|
From: Oliver J. <oli...@mo...> - 2004-03-03 06:30:19
|
> One of the big advantages I found with FreeS/wan is the documentation and in > particular the interoperability guides - they've helped me out in many cases. to make it clear, i'm not fixed on kame or freeswan.... i personally prefer a solution compatible with the kernel instead of patching the kernel. i read something about freeswan compatibility with 2.6 in version 2.06.. so if you have some free time :-) please contribute !!!!!!! a lot of freeswan users will be happy to migrate to 2.6 without changeing the vpn configuration. i will concentrate my work on kame/ipsec-tools, because it looks like the perfered solution for the kernel developers involved in this area. > I'm unfamiliar with Kame, but in my brief reading it appears to be easier to > configure, but is not as well tested as FreeS/wan. ask the bsd people for test results !! they use racoon long time... > There may still be some > issues with x509 certs and nat traversal, but I'm sure these will be solved > in time... > nat traversal is prepared for merge (in cvs).... x509 certs looks working for me... > So, I would add my voice to the concensus and recommend DL sticks to FreeS/wan > for kernel 2.4 and see where 2.6 goes. there should be no disussion if freeswan or kame is or should be the one and only solution... for 2.4 freeswan is the one and only maintained solution. so its the best solution... and 2.4 is in maintained mode, so its dead for new features now. (and backports). Oliver |