Re: port based filtering and IPsec 2.6

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Sunday 18 January 2004 9:14 am, Marc Haber wrote:

> On Sat, 17 Jan 2004 18:29:56 +0000, Antony Stone wrote:
>
> > What do you think is wrong with FreeS/WAN?
>
> FreeS/WAN is - as somebody else said very nicely - at war with the
> kernel routing machinery.
>
> FreeS/WAN is a kernel patch with a very strange applying mechanism
>
> The latest FreeS/WAN version I have successfully used is 1.99.
>
> The FreeS/WAN-Users mailing list is flooded with spam
>
> I hope that I made my point clear.

Indeed, thanks.   I understand now why you dislike it.

I guess I've just been lucky that I prefer compiling my own kernels anyway, I 
don't mind a strange patching mechanism so long as it works, and I've not 
joined the mailing list because I've found the info I need in the 
documentation or in the list archives.

I agree with the point made earlier however that it's a very poor situation if 
the 2.6 kernel IPsec won't allow filtering unencrypted packets.

Antony.

-- 
In science, one tries to tell people
in such a way as to be understood by everyone
something that no-one ever knew before.

In poetry, it is the exact opposite.

 - Paul Dirac

                                                     Please reply to the list;
                                                           please don't CC me.



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux