IPv6 readyNote: This archive passes through spamassassin. Every mail marked with the subject "*****SPAM*****" has exceed a certain threshold of spam-like behaviour.

Re: [Users] Why freeswan instead of cisco/nortel

From: Ken Bantoft (ken_at_networkoverlord.com)
Date: Tue Jul 16 2002 - 19:24:56 CEST


On Tue, 16 Jul 2002, Jon Molin wrote:

> > Normal argument "We don't know anything else, so use what we know". After
> > using FreeS/Wan for a few weeks, you can set it up in 15 minutes too.
> > FreeS/Wan -> Nortel is iffy... It worked at one point using the older code
> > (both on Contivity head end and FreeS/Wan) but I don't know about recent.
> > I'm using Netlock's Contivity client for Linux remote users, but it's not
> > designed to run as a remote office. I've been debating on testing more
> > recent stuff, but it's low on my priority list, as I don't ever plan to do
> > it for any reason other than "see if it works". If someone was really
> > keen on this, I can do the contivity side easily enough, but I'm not setup
> > to do the FreeS/Wan side.
> >
>
> Do I understand right that FreeS/Wan -> Nortel is big trouble. Becouse
> that's exactly what I need to do...My biggest problem is time, if
> there'll be loads of hassle and it'll take alot of time my boss won't be
> with me as 'time is money'(tm).

It might well be. I haven't seen any recent postings of people getting it
working - only people trying. Nortel used to support FreeS/Wan as a
branch office tunnel back in the FS 1.1 or 1.3 days, and Nortel code < 4.0

> > remote sites. The Cisco's are used for business partners with the same
> > attitude as yours... "Cisco or nothing", so I jam them into a little 1720
> > and then run all the traffic through a firewall.
> >
>
> I trust you on that one. I'm no fan of cisco and their 'you need a
> license for every little function you might wanna use' attitude.

Yea. Needed 3 DES code... $upgrade. Oh wait.. that won't fit on your
flash card, $upgrade. And you'll need more RAM too... $upgrade.

> > You've got the main ones... if *you* are stuck supporting it, you'd want
> > something you know, and don't wanna spend additional $, since you have the
> > equipment in place already.
> >
>
> A big problem is initial time and lack of long term thinking (ever heard
> that before?). They don't include maintainance they just count from
> start untill one is up and running. Unfortenately if the initial time is
> huge the chance I'll have my boss's support is pretty low.
>
> /Jon

Unless you've got the gear to pre-test with, and you know both
products, it's totally hit + miss. Since it looks like you're dealing
with a 3rd party of sorts... it could be you know your gear, but the
person on the other side is clueless :(

-- 
Ken Bantoft			One Unix to rule them all, One Resolver to find them,
ken_at_networkoverlord.com		One IP to bring them all, and in the zone, bind them.

_______________________________________________ Users mailing list Users_at_lists.freeswan.org http://lists.freeswan.org/mailman/listinfo/users



This archive was generated by hypermail 2.1.3 : Mon Jul 29 2002 - 05:20:23 CEST