Re: IPSEC Compression

From: Eric Anderson (anderson@centtech.com)
Date: 01/25/02


Date: Thu, 24 Jan 2002 17:05:30 -0600
From: Eric Anderson <anderson@centtech.com>
To: Nate Williams <nate@yogotech.com>

Well, racoon does it, I think, or else things like:
compression_algorithm deflate
wouldn't be in the config files. So I suppose my question should have been:

How do I turn on compression with racoon for an IPSEC tunnel?

Eric

Nate Williams wrote:
>
> > How do I turn on compression with an IPSEC tunnel?
>
> I think you're confusing IPSEC with SSH. The former doesn't have a
> standard way of pre-compressing packets, while the latter does b/c it's
> done in userland.
>
> Nate

-- 
------------------------------------------------------------------
Eric Anderson	 anderson@centtech.com    Centaur Technology
If at first you don't succeed, sky diving is probably not for you.
------------------------------------------------------------------
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • Racoon Problem & Cisco Tunnel
    ... I have several remote FreeBSD users who want to connect their home LANs ... to my trusted network over an IPSec tunnel via a DSL connection. ... But I don't think the racoon is ... Happens with the config files I've written and the stock ...
    (FreeBSD-Security)
  • Re: Racoon without compression
    ... > I'm trying to set up a VPN connection to a NetScreen VPN using racoon. ... compression is not needed for IPSec. ... The settings in /etc/ipsec.conf are what tell ...
    (freebsd-questions)
  • Connecting IPSec from Behind a gateway
    ... I am trying to connect 2 FreeBSD 5.4 boxes with an IPSec tunnel using ... racoon. ... The gateway router is a commercial box with "IPSEC Passthrough" ...
    (freebsd-questions)
  • IPSEC Compression
    ... How do I turn on compression with an IPSEC tunnel? ... If at first you don't succeed, sky diving is probably not for you. ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • Re: KAME IPsec on low-end hardware
    ... > compression can be disabled? ... > isakmpd supports dymamic client IP addresses, but that seems to be the ... > only major difference. ... racoon can do too. ...
    (FreeBSD-Security)