|
From: <hzu...@ra...> - 2004-03-02 16:30:52
|
On 03/02/2004 10:02:43 AM Bruce Smith wrote: >> > According to slashdot, "KAME" was selected as the standard Linux >IPSEC >> > implementation. Does anyone have any experience with KAME? (I've >never >> > even heard of it myself) Maybe we should think about switching DL >to >> > include KAME instead of FreeS/WAN? >> >> KAME/racoon is already in the tree but working >> only witha a 2.6 kernel... >> >> there exists a backport of the ipsec-infrastructure for 2.4, if you >> look in the redhat kernels, but i never tried to patch a vanilla 2.4 >> >> i would rather suggest >> >> 2.4 = freeswan (until a maintained 2.6 ipsec backport is available) >> 2.6 = KAME/racoon DL v1.2 will be a "2.4 only" release. The 2.6 support is only for testing and folks who really need it (and they need to compile it themselves). I think after that all the patches and other programs should be working under 2.6 and then we can get ready for a 2.0 release of DL with Kernel 2.6. >I guess it also depends if the next stable release will be 2.6 only, or >a choice of 2.4/2.6. > >> i've only played with racoon, but its easy to configure and there >exists >> a good how-to on the web for it. >> >> http://www.ipsec-howto.org/ > >An IPSEC implementation that is easy to configure? >Isn't that an oxymoron? ;-) LOL Heiko |