Re: IPSec VPNs: to gif or not to gif

From: Eric Anderson (anderson_at_centtech.com)
Date: 10/22/03

  • Next message: Mark Murray: "Re: hardware crypto and SSL?"
    Date: Wed, 22 Oct 2003 07:34:30 -0500
    To: Jim Hatfield <subscriber@insignia.com>
    
    

    Jim Hatfield wrote:

    >I will shortly be replacing a couple of proprietary VPN boxes
    >with a FreeBSD solution. Section 10.10 of the Handbook has a
    >detailed description of how to do this.
    >
    >However I remember a lot of discussion about a year ago about
    >whether the gif interface was necessary to set up VPNs like
    >this or whether it was just a convenience, for "getting the
    >routing right". A number of people said that gif was not
    >needed but I've never found a step-by-step description of how
    >to set up a lan-to-lan VPN without using it.
    >

    I use gif interfaces for my VPN's, and it works extremely well. The
    only other solution I think I would even try, is mpd, but that uses a
    much weaker protocol from what I know (PPTP).

    It's so easy to use gif, I'm not sure why you wouldn't.

    Eric

    -- 
    ------------------------------------------------------------------
    Eric Anderson	   Systems Administrator      Centaur Technology
    All generalizations are false, including this one.
    ------------------------------------------------------------------
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Mark Murray: "Re: hardware crypto and SSL?"

    Relevant Pages

    • Re: IPSec VPNs: to gif or not to gif
      ... > whether the gif interface was necessary to set up VPNs like ... > Is the Handbook the current received wisdom on how to set this ... do a gif tunnel over the transport ipsec you have dynamic vpn based ... I however just do tunnel mode ipsec with no gif tunnel and packet filter ...
      (FreeBSD-Security)
    • Re: IPSec VPNs: to gif or not to gif
      ... JH> whether the gif interface was necessary to set up VPNs like ... JH> to set up a lan-to-lan VPN without using it. ... because i can not see packets that pass through gif interface. ... JH> Is the Handbook the current received wisdom on how to set this ...
      (FreeBSD-Security)
    • Re: IPSec VPNs: to gif or not to gif
      ... On Wed, 22 Oct 2003, Jim Hatfield wrote: ... > whether the gif interface was necessary to set up VPNs like ... (vice versa on the other host's setkey config) ...
      (FreeBSD-Security)
    • Re: IPSec VPNs: to gif or not to gif
      ... On Wed, 22 Oct 2003, Jim Hatfield wrote: ... > whether the gif interface was necessary to set up VPNs like ... I use VPN with gif device. ... Create and set tunnel. ...
      (FreeBSD-Security)
    • IPSec VPNs: to gif or not to gif
      ... I will shortly be replacing a couple of proprietary VPN boxes ... whether the gif interface was necessary to set up VPNs like ... Is the Handbook the current received wisdom on how to set this ... that a new interface esp0 be created so that ipfw could work ...
      (FreeBSD-Security)