Re: [Users] Re: Help

From: Alan Vasques (atv_at_amazon.com.br)
Date: Mon Nov 25 2002 - 22:55:05 CET


Hi, Andreas,

Thanks for your help, but I still have a doubt.

You said in your example that AES is the prefered cipher, but 3DES is still acceptable. Well, what I really want is that IKE and ESP choose the cipher randomly. I mean, I want it changes the ciphers used everytime a connection is done and/or at periods of time, like every week. Understand?

Do you have any sugestion?

Thanks.

Alan Tamer Vasques

--------- Mensagem Original --------
De: "Andreas Steffen" <andreas.steffen@strongsec.net>
Para: "Alan Tamer Vasques" <atv@amazon.com.br>
Cópia: "FreeS/WAN Users" <users@lists.freeswan.org>, "Ken Bantoft" <ken@freeswan.ca>
Assunto: [Users] Re: Help
Data: 25/11/02 13:41


You can define the ike and esp options on a connection basis. I have set

ike=aes128,3des
esp=aes128,3des

for all connections which means that I prefer aes128 but that I accept
also 3des. You can find all possible options in the README on JuanJo's site.

Regards

Andreas

WAlan Tamer Vasques wrote:
> Hi, Folks..
>
> I'd like to use all ciphers available in Juanjo's site (3DES, AES, CAST,
> Serpent, Blowfish and Twofish) in my FreeS/WAN VPN and I want FreeS/WAN
> choose the best cipher in each situation. My question is:
>
> - How IKE and ESP will do this? Randomly or it's not possible to use all
> ciphers?
>
> I'd appreciate if you could send me sample configurations of this.
>
> Thanks in advance.
>
> []s
>
> Alan Tamer Vasques
>

======================================================================
Andreas Steffen e-mail: andreas.steffen@strongsec.com
strongSec GmbH phone: +41 76 340 25 56
Alter Zürichweg 20 home: http://www.strongsec.com
CH-8952 Schlieren (Switzerland)
==========================================[strong internet security]==


_______________________________________________
Users mailing list
Users@lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users






________________________________________________
Mensagem enviada usando Amazon Corporation Webmail 2.7 _______________________________________________ Users mailing list Users@lists.freeswan.org http://lists.freeswan.org/mailman/listinfo/users

This archive was generated by hypermail 2.1.5 : Tue Nov 26 2002 - 05:20:48 CET