Re: [vpp-dev] RFC: IPSec Tunnel remodel

2019-05-29 Thread Matthew Smith via Lists.Fd.Io
data required to programme > VPP, so it can replay should VPP crash, so having download the full update > each time is fine IMO. > > Does that sound reasonable? > > > > Regards, > > neale > > > > *De : *Matthew Smith > *Date : *mercredi 22 mai 2019 à

Re: [vpp-dev] RFC: IPSec Tunnel remodel

2019-05-27 Thread Neale Ranns via Lists.Fd.Io
replay should VPP crash, so having download the full update each time is fine IMO. Does that sound reasonable? Regards, neale De : Matthew Smith Date : mercredi 22 mai 2019 à 17:50 À : "Neale Ranns (nranns)" Cc : "vpp-dev@lists.fd.io" Objet : Re: [vpp-dev] RFC: IPSec Tunnel re

Re: [vpp-dev] RFC: IPSec Tunnel remodel

2019-05-22 Thread Matthew Smith via Lists.Fd.Io
Hi Neale, We (Netgate/TNSR) use strongswan for IKE with a module that connects to the VPP binary API to manage IPsec tunnel interfaces. The API changes mostly look fine from my perspective. It won't be that much different than what we do now. Currently we create an IPsec tunnel interface before a

Re: [vpp-dev] RFC: IPSec Tunnel remodel

2019-05-22 Thread Ole Troan
Hi Neale, > Thanks for taking the time to examine the proposal. Lots of comments inline > >> Answering as a non VPP-IPsec'er. More like an anti-IPsec'er if anything. ;-) > >> Eecutive summary: Not a fan. > >> This tastes too much of the dreams of the IPsec'ers of the past. Where IPsec >> was a

Re: [vpp-dev] RFC: IPSec Tunnel remodel

2019-05-21 Thread Jim Thompson via Lists.Fd.Io
> On May 21, 2019, at 9:43 AM, Neale Ranns via Lists.Fd.Io > wrote: > > In the initial patch I removed the ipsec-gre code, for two reasons: > 1) I know no-one is using it, since it didn't work until a few weeks ago Given the presence of routed IPsec in VPP, there wasn’t a use-case for ipsec-

Re: [vpp-dev] RFC: IPSec Tunnel remodel

2019-05-21 Thread Neale Ranns via Lists.Fd.Io
Hi Ole, Thanks for taking the time to examine the proposal. Lots of comments inline > Answering as a non VPP-IPsec'er. More like an anti-IPsec'er if anything. ;-) > Eecutive summary: Not a fan. > This tastes too much of the dreams of the IPsec'ers of the past. Where IPsec

Re: [vpp-dev] RFC: IPSec Tunnel remodel

2019-05-20 Thread Ole Troan
Hi Neale, > Hi VPP-IPSec-ers, > > I'd like to gauge comments on this article: > https://wiki.fd.io/view/VPP/IPSec > and the proposal for the IPSec tunnel re-model. > The associated patch is: > https://gerrit.fd.io/r/#/c/18956/ Answering as a non VPP-IPsec'er. More like an anti-IPsec'er if any

[vpp-dev] RFC: IPSec Tunnel remodel

2019-05-20 Thread Neale Ranns via Lists.Fd.Io
Hi VPP-IPSec-ers, I'd like to gauge comments on this article: https://wiki.fd.io/view/VPP/IPSec and the proposal for the IPSec tunnel re-model. The associated patch is: https://gerrit.fd.io/r/#/c/18956/ thanks, Neale -=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this gro