Re: [fbsd] Re: IPSEC documentation

2006-01-09 Thread Phil Regnauld
Jeremie Le Hen (jeremie) writes: > > I personally find the gif(4)/transport mode setup neater than the > single tunnel mode - though I am not aware of initial constrains > when IPSec RFCs were written - especially because one can look after the > traffic going through the VPN link in a very natura

Re: [fbsd] Re: [fbsd] Re: IPSEC documentation

2006-01-09 Thread Jeremie Le Hen
Hi Phil, > > I personally find the gif(4)/transport mode setup neater than the > > single tunnel mode - though I am not aware of initial constrains > > when IPSec RFCs were written - especially because one can look after the > > traffic going through the VPN link in a very natural way. I forgot t

Re: [fbsd] Re: IPSEC documentation

2006-01-09 Thread Jeremie Le Hen
Hi, Brian, Eric, > I still think that gif + IPSEC tunnel mode (as currently documented) is not > a good approach, especially if it's the *only* mode of operation to be > documented and hence implicitly recommended as the 'right' way to do it. AFAIK, using both gif(4) and IPSec tunnel mode is actu