From mboxrd@z Thu Jan 1 00:00:00 1970 From: Nick Drage Subject: Re: vpn Date: Tue, 14 Sep 2004 17:07:35 +0100 Sender: netfilter-bounces@lists.netfilter.org Message-ID: <20040914160735.GP26823@metastasis.org.uk> References: <012a01c49a61$340e8ad0$49caa8c0@caris.priv> <1095172947.2055.33.camel@localhost> Reply-To: Netfilter Mailing List Mime-Version: 1.0 Return-path: Content-Disposition: inline In-Reply-To: <1095172947.2055.33.camel@localhost> List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: netfilter-bounces@lists.netfilter.org Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: netfilter@lists.netfilter.org On Tue, Sep 14, 2004 at 10:42:27AM -0400, John A. Sullivan III wrote: > On Tue, 2004-09-14 at 09:46, Peter Marshall wrote: > I would suggest an IPSec VPN using either the native IPSec stack in the > latest Linux or either StrongSWAN (www.strongswan.org) or OpenSWAN > (www.openswan.org) and placing access control and VPN on the same > device. That is how we design most devices for use in the ISCS project > (http://iscs.sourceforge.net). Reading "Network Security Hacks" recently I liked the look of VTun. Any thoughts on that? How does it interface with IPTables? -- mors omnia vincit