From: Arif Hossain <aftnix@gmail.com>
To: Jan Engelhardt <jengelh@inai.de>
Cc: netfilter-devel <netfilter-devel@vger.kernel.org>,
nefilter@vger.kernel.org
Subject: Re: CRYPT target patch for newer kernel ?
Date: Wed, 08 Aug 2012 20:15:26 +0600 [thread overview]
Message-ID: <1344435326.4763.36.camel@localhost> (raw)
In-Reply-To: <alpine.LNX.2.01.1208081613060.1203@frira.zrqbmnf.qr>
On Wed, 2012-08-08 at 16:15 +0200, Jan Engelhardt wrote:
<snip>
> You can probably even use IPsec without StrongSWAN, if you manage to
> knit together the pieces using `ip xfrm state` and `ip xfrm policy`.
>
I guess i'm not clarifying my issue transparently. The client device is
far from linux or POSIX etc. Its ip stack does not have IPSEC either.
And its a vendor locked thing. We can install userland stuff. nothing
else. And to if i'm not wrong ,to enable IPSEC, we need to first port it
to the client machine. And its not possible and not feasible. We just
want to encrypt the UDP traffic.
>
> >Just for an example, we used tls for only the initial session
> >establishment, not the original data, and it proved very inefficient so
> >we had to abandon the thing completely.
>
> So perhaps you did something really wrong?
Not actually, we did standard stuff. But the the poor and brain dead
processor could not handle it. The speed is ok if you want to surf web,
but its inadequate for real time data. Again i'm talking about a retard
processor with retard amount of memory.
--
Cheers
aft
aftnix@gmail.com
next prev parent reply other threads:[~2012-08-08 14:26 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-08-08 12:25 CRYPT target patch for newer kernel ? Arif Hossain
2012-08-08 13:41 ` Jan Engelhardt
2012-08-08 13:53 ` Arif Hossain
2012-08-08 14:15 ` Jan Engelhardt
2012-08-08 14:15 ` Arif Hossain [this message]
2012-08-08 15:34 ` Jan Engelhardt
2012-08-08 15:41 ` Arif Hossain
2012-08-08 16:06 ` Jan Engelhardt
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1344435326.4763.36.camel@localhost \
--to=aftnix@gmail.com \
--cc=jengelh@inai.de \
--cc=nefilter@vger.kernel.org \
--cc=netfilter-devel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.