Linux Netfilter discussions
 help / color / mirror / Atom feed
From: "Michael H. Warfield" <mhw@wittsend.com>
To: Michael Gale <mgale@utilitran.com>
Cc: netfilter@lists.netfilter.org
Subject: Re: Can I have DES / 3 DES VPN with IPtables Kernal kernel version 2. 4.20 with IPSEC installed
Date: Thu, 18 Dec 2003 11:15:52 -0500	[thread overview]
Message-ID: <20031218161552.GA19518@alcove.wittsend.com> (raw)
In-Reply-To: <20031218081126.7719e90c.mgale@utilitran.com>

[-- Attachment #1: Type: text/plain, Size: 2373 bytes --]

On Thu, Dec 18, 2003 at 08:11:26AM -0700, Michael Gale wrote:
> Hello,

> 	You should seriously consider Super FreeS/Wan ... it supports more then DES and 3DES which are out dated and I believe it has been proven. 

	FreeSWAN doesn't support DES because it's considered weak.
Single DES hasn't been "cracked" per se, it's just that it's keyspace
(56 bits) is now considered too small to resist concerted brute force
attacks.  If it's used for persistent storage of data, you could have a
real problem.  If it's used with ephemeral keys in a communications
channel with frequent auto-rekeying and perfect forward secrecy (supported
by IKE/pluto) it's not so much a problem since brute forcing would take
longer than the life expectancy of the ephemeral key.  If you used it
for long term "shared secret" keys and sessions with no rekeying, you
could have a problem.  So if you want to be really REALLY sure, you
avoid single DES and so unpatched FreeSWAN doesn't support it.

> Michael.


> On Thu, 18 Dec 2003 09:54:32 -0500
> "John A. Sullivan III" <john.sullivan@nexusmgmt.com> wrote:
> 
> > On Thu, 2003-12-18 at 07:58, Laxmi_Narsaiah wrote:
> > > Hi,
> > > 
> > > Can I have DES / 3 DES VPN with IPtables Kernal kernel version 2.4.20
> > > with IPSEC installed, please let me know.
> > > 
> > <snip>
> > 	We do this all the time with FreeS/WAN.  In fact, we are developing a
> > GUI front end to managed combined firewall and VPN security for large,
> > complex implementations.  You can find training slide shows on using
> > iptables, FreeS/WAN, iproute2 and DHCP at http://iscs.sourceforge.net -
> > Good luck
> > -- 
> > John A. Sullivan III
> > Chief Technology Officer
> > Nexus Management
> > +1 207-985-7880
> > john.sullivan@nexusmgmt.com
> > ---
> > If you are interested in helping to develop a GPL enterprise class
> > VPN/Firewall/Security device management console, please visit
> > http://iscs.sourceforge.net 
> > 
> > 
> 
> 
> -- 
> Michael Gale
> Network Administrator
> Utilitran Corporation

	Mike
-- 
 Michael H. Warfield    |  (770) 985-6132   |  mhw@WittsEnd.com
  /\/\|=mhw=|\/\/       |  (678) 463-0932   |  http://www.wittsend.com/mhw/
  NIC whois:  MHW9      |  An optimist believes we live in the best of all
 PGP Key: 0xDF1DD471    |  possible worlds.  A pessimist is sure of it!

[-- Attachment #2: Type: application/pgp-signature, Size: 307 bytes --]

      parent reply	other threads:[~2003-12-18 16:15 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-12-18 12:58 Can I have DES / 3 DES VPN with IPtables Kernal kernel version 2. 4.20 with IPSEC installed Laxmi_Narsaiah
2003-12-18 14:54 ` John A. Sullivan III
2003-12-18 15:11   ` Michael Gale
2003-12-18 15:17     ` Michael Gale
2003-12-18 16:15     ` Michael H. Warfield [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20031218161552.GA19518@alcove.wittsend.com \
    --to=mhw@wittsend.com \
    --cc=mgale@utilitran.com \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox