Linux Netfilter discussions
 help / color / mirror / Atom feed
* Can I have DES / 3 DES VPN with IPtables Kernal kernel version 2. 4.20 with IPSEC installed
@ 2003-12-18 12:58 Laxmi_Narsaiah
  2003-12-18 14:54 ` John A. Sullivan III
  0 siblings, 1 reply; 5+ messages in thread
From: Laxmi_Narsaiah @ 2003-12-18 12:58 UTC (permalink / raw)
  To: 'netfilter@lists.netfilter.org'

[-- Attachment #1: Type: text/plain, Size: 771 bytes --]

Hi,

Can I have DES / 3 DES VPN with IPtables Kernal kernel version 2.4.20 with
IPSEC installed, please let me know.

Thanks in advance.

Laxmi Narsaiah.


************************************************************************** 
This email (including any attachments) is intended for the sole use of the
intended recipient/s and may contain material that is CONFIDENTIAL AND
PRIVATE COMPANY INFORMATION. Any review or reliance by others or copying or
distribution or forwarding of any or all of the contents in this message is
STRICTLY PROHIBITED. If you are not the intended recipient, please contact
the sender by email and delete all copies; your cooperation in this regard
is appreciated.
**************************************************************************

[-- Attachment #2: Type: text/html, Size: 1435 bytes --]

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: Can I have DES / 3 DES VPN with IPtables Kernal kernel version 2. 4.20 with IPSEC installed
  2003-12-18 12:58 Can I have DES / 3 DES VPN with IPtables Kernal kernel version 2. 4.20 with IPSEC installed Laxmi_Narsaiah
@ 2003-12-18 14:54 ` John A. Sullivan III
  2003-12-18 15:11   ` Michael Gale
  0 siblings, 1 reply; 5+ messages in thread
From: John A. Sullivan III @ 2003-12-18 14:54 UTC (permalink / raw)
  To: Laxmi_Narsaiah; +Cc: 'netfilter@lists.netfilter.org'

On Thu, 2003-12-18 at 07:58, Laxmi_Narsaiah wrote:
> Hi,
> 
> Can I have DES / 3 DES VPN with IPtables Kernal kernel version 2.4.20
> with IPSEC installed, please let me know.
> 
<snip>
	We do this all the time with FreeS/WAN.  In fact, we are developing a
GUI front end to managed combined firewall and VPN security for large,
complex implementations.  You can find training slide shows on using
iptables, FreeS/WAN, iproute2 and DHCP at http://iscs.sourceforge.net -
Good luck
-- 
John A. Sullivan III
Chief Technology Officer
Nexus Management
+1 207-985-7880
john.sullivan@nexusmgmt.com
---
If you are interested in helping to develop a GPL enterprise class
VPN/Firewall/Security device management console, please visit
http://iscs.sourceforge.net 



^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: Can I have DES / 3 DES VPN with IPtables Kernal kernel version 2. 4.20 with IPSEC installed
  2003-12-18 14:54 ` John A. Sullivan III
@ 2003-12-18 15:11   ` Michael Gale
  2003-12-18 15:17     ` Michael Gale
  2003-12-18 16:15     ` Michael H. Warfield
  0 siblings, 2 replies; 5+ messages in thread
From: Michael Gale @ 2003-12-18 15:11 UTC (permalink / raw)
  To: netfilter

Hello,

	You should seriously consider Super FreeS/Wan ... it supports more then DES and 3DES which are out dated and I believe it has been proven. 

Michael.



On Thu, 18 Dec 2003 09:54:32 -0500
"John A. Sullivan III" <john.sullivan@nexusmgmt.com> wrote:

> On Thu, 2003-12-18 at 07:58, Laxmi_Narsaiah wrote:
> > Hi,
> > 
> > Can I have DES / 3 DES VPN with IPtables Kernal kernel version 2.4.20
> > with IPSEC installed, please let me know.
> > 
> <snip>
> 	We do this all the time with FreeS/WAN.  In fact, we are developing a
> GUI front end to managed combined firewall and VPN security for large,
> complex implementations.  You can find training slide shows on using
> iptables, FreeS/WAN, iproute2 and DHCP at http://iscs.sourceforge.net -
> Good luck
> -- 
> John A. Sullivan III
> Chief Technology Officer
> Nexus Management
> +1 207-985-7880
> john.sullivan@nexusmgmt.com
> ---
> If you are interested in helping to develop a GPL enterprise class
> VPN/Firewall/Security device management console, please visit
> http://iscs.sourceforge.net 
> 
> 


-- 
Michael Gale
Network Administrator
Utilitran Corporation


^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: Can I have DES / 3 DES VPN with IPtables Kernal kernel version 2. 4.20 with IPSEC installed
  2003-12-18 15:11   ` Michael Gale
@ 2003-12-18 15:17     ` Michael Gale
  2003-12-18 16:15     ` Michael H. Warfield
  1 sibling, 0 replies; 5+ messages in thread
From: Michael Gale @ 2003-12-18 15:17 UTC (permalink / raw)
  To: netfilter


Sorry my mistake only DES has been proven to be crackable. At this moment no one has officially cracked 3DES.

Michael.


On Thu, 18 Dec 2003 08:11:26 -0700
Michael Gale <mgale@utilitran.com> wrote:

> Hello,
> 
> 	You should seriously consider Super FreeS/Wan ... it supports more then DES and 3DES which are out dated and I believe it has been proven. 
> 
> Michael.
> 
> 
> 
> On Thu, 18 Dec 2003 09:54:32 -0500
> "John A. Sullivan III" <john.sullivan@nexusmgmt.com> wrote:
> 
> > On Thu, 2003-12-18 at 07:58, Laxmi_Narsaiah wrote:
> > > Hi,
> > > 
> > > Can I have DES / 3 DES VPN with IPtables Kernal kernel version 2.4.20
> > > with IPSEC installed, please let me know.
> > > 
> > <snip>
> > 	We do this all the time with FreeS/WAN.  In fact, we are developing a
> > GUI front end to managed combined firewall and VPN security for large,
> > complex implementations.  You can find training slide shows on using
> > iptables, FreeS/WAN, iproute2 and DHCP at http://iscs.sourceforge.net -
> > Good luck
> > -- 
> > John A. Sullivan III
> > Chief Technology Officer
> > Nexus Management
> > +1 207-985-7880
> > john.sullivan@nexusmgmt.com
> > ---
> > If you are interested in helping to develop a GPL enterprise class
> > VPN/Firewall/Security device management console, please visit
> > http://iscs.sourceforge.net 
> > 
> > 
> 
> 
> -- 
> Michael Gale
> Network Administrator
> Utilitran Corporation
> 


-- 
Michael Gale
Network Administrator
Utilitran Corporation


^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: Can I have DES / 3 DES VPN with IPtables Kernal kernel version 2. 4.20 with IPSEC installed
  2003-12-18 15:11   ` Michael Gale
  2003-12-18 15:17     ` Michael Gale
@ 2003-12-18 16:15     ` Michael H. Warfield
  1 sibling, 0 replies; 5+ messages in thread
From: Michael H. Warfield @ 2003-12-18 16:15 UTC (permalink / raw)
  To: Michael Gale; +Cc: netfilter

[-- Attachment #1: Type: text/plain, Size: 2373 bytes --]

On Thu, Dec 18, 2003 at 08:11:26AM -0700, Michael Gale wrote:
> Hello,

> 	You should seriously consider Super FreeS/Wan ... it supports more then DES and 3DES which are out dated and I believe it has been proven. 

	FreeSWAN doesn't support DES because it's considered weak.
Single DES hasn't been "cracked" per se, it's just that it's keyspace
(56 bits) is now considered too small to resist concerted brute force
attacks.  If it's used for persistent storage of data, you could have a
real problem.  If it's used with ephemeral keys in a communications
channel with frequent auto-rekeying and perfect forward secrecy (supported
by IKE/pluto) it's not so much a problem since brute forcing would take
longer than the life expectancy of the ephemeral key.  If you used it
for long term "shared secret" keys and sessions with no rekeying, you
could have a problem.  So if you want to be really REALLY sure, you
avoid single DES and so unpatched FreeSWAN doesn't support it.

> Michael.


> On Thu, 18 Dec 2003 09:54:32 -0500
> "John A. Sullivan III" <john.sullivan@nexusmgmt.com> wrote:
> 
> > On Thu, 2003-12-18 at 07:58, Laxmi_Narsaiah wrote:
> > > Hi,
> > > 
> > > Can I have DES / 3 DES VPN with IPtables Kernal kernel version 2.4.20
> > > with IPSEC installed, please let me know.
> > > 
> > <snip>
> > 	We do this all the time with FreeS/WAN.  In fact, we are developing a
> > GUI front end to managed combined firewall and VPN security for large,
> > complex implementations.  You can find training slide shows on using
> > iptables, FreeS/WAN, iproute2 and DHCP at http://iscs.sourceforge.net -
> > Good luck
> > -- 
> > John A. Sullivan III
> > Chief Technology Officer
> > Nexus Management
> > +1 207-985-7880
> > john.sullivan@nexusmgmt.com
> > ---
> > If you are interested in helping to develop a GPL enterprise class
> > VPN/Firewall/Security device management console, please visit
> > http://iscs.sourceforge.net 
> > 
> > 
> 
> 
> -- 
> Michael Gale
> Network Administrator
> Utilitran Corporation

	Mike
-- 
 Michael H. Warfield    |  (770) 985-6132   |  mhw@WittsEnd.com
  /\/\|=mhw=|\/\/       |  (678) 463-0932   |  http://www.wittsend.com/mhw/
  NIC whois:  MHW9      |  An optimist believes we live in the best of all
 PGP Key: 0xDF1DD471    |  possible worlds.  A pessimist is sure of it!

[-- Attachment #2: Type: application/pgp-signature, Size: 307 bytes --]

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2003-12-18 16:15 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-12-18 12:58 Can I have DES / 3 DES VPN with IPtables Kernal kernel version 2. 4.20 with IPSEC installed Laxmi_Narsaiah
2003-12-18 14:54 ` John A. Sullivan III
2003-12-18 15:11   ` Michael Gale
2003-12-18 15:17     ` Michael Gale
2003-12-18 16:15     ` Michael H. Warfield

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox