[Users] Re: [Design] Restriction of 4 virtual ipsec interfaces

From: Michael Richardson (mcr_at_sandelman.ottawa.on.ca)
Date: Mon Oct 28 2002 - 15:32:48 CET


-----BEGIN PGP SIGNED MESSAGE-----

The 4 IPSEC virtual interfaces restrict you to sending/receiving IPsec
packets on 4 physical interfaces.

I can't parse what you mean by "4 different ipsec SGs from a host". We
regularly have dozens or more tunnels open.

You can trivially increase the number of virtual interfaces in 1.98 and
upwards.

] ON HUMILITY: to err is human. To moo, bovine. | firewalls [
] Michael Richardson, Sandelman Software Works, Ottawa, ON |net architect[
] mcr_at_sandelman.ottawa.on.ca http://www.sandelman.ottawa.on.ca/ |device driver[
] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)
Comment: Finger me for keys

iQCVAwUBPb1KjoqHRg3pndX9AQFbHgQAsFADXEzGcf5yUadrhTvvgHXw6uw3qmvF
vB0uF72uA2AY0SFBHQXVJIaxLGftn95P8bK+ltZDVhssyeRR/ESRVxWaLBvqCbua
Gtw7euKdovtTC/J0JOMuQYro6fGO959qzh6mZ2suV5DbRHSSUZ5SjM/Dj3JPPU3T
6QVxZKyU7JY=
=D7zm
-----END PGP SIGNATURE-----
_______________________________________________
Users mailing list
Users_at_lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users



This archive was generated by hypermail 2.1.5 : Wed Oct 30 2002 - 05:20:34 CET