netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* ?completeness of IPsec feature-set
@ 2003-03-27 11:13 John S. Denker
  2003-03-27 13:36 ` bert hubert
  0 siblings, 1 reply; 8+ messages in thread
From: John S. Denker @ 2003-03-27 11:13 UTC (permalink / raw)
  To: netdev

Hi --

I've been unable to find much discussion of what IPsec
features should be built into 2.5 / 2.6 to ensure a
reasonable level of usability and scalability.

For example, consider the challenge of establishing an
ordinary VPN where N-1 of the gateways have changeable
wild-side IP addresses.  AFAICT nobody knows how to get
racoon to do this.

People were hoping that the new IPsec implementation
would be a step forward.  If it can't support road
warriors it might be considered a step backwards.

Mr. Atkins recently offered to look into the road-warrior
issue in particular ...
http://lists.freeswan.org/pipermail/design/2003-March/004575.html

... but the overall question remains:  What has been
done to ensure completeness and coherence of the
design in general?

Is there a document somewhere listing the set of
desirable features and the status thereof?  If not,
it's high time to create one.

If you want to know what sort of features I'm talking
about, please see
http://www.monmouth.com/~jsd/vpn/ipsec+routing/feature-list.htm

Some of the listed features are obvious and already implemented
or at least promised.  But others may be less obvious and their
status is not clear.

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2003-03-28 10:19 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-03-27 11:13 ?completeness of IPsec feature-set John S. Denker
2003-03-27 13:36 ` bert hubert
2003-03-27 21:48   ` John S. Denker
2003-03-27 21:58     ` bert hubert
2003-03-27 22:58       ` John S. Denker
2003-03-27 23:21       ` James Morris
2003-03-28  6:32       ` Pekka Savola
2003-03-28 10:19         ` bert hubert

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).