[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Freeswan in Debian, or: Why I am such a bad maintainer

On Mon, 28 Jun 2004, Wichert Akkerman wrote:

> Previously Lupe Christoph wrote:
> > Such as having virtual interfaces to hang firewall rules from,
> > preferably one per tunnel?
> You should be able to do that using dummy interfaces. Just keep in
> mind that ipsec is no longer done through an interface but via a
> route transform, which is a very different and more flexible approach.

Wichert, would you care to produce even just an outline of an example of
how to do it, or point me to an howto which provides it? Indeed the one
thing I love of KLIPS with respect to the native Linux IPSec is just
having virtual interfaces, which ease quite a lot writing and maintaining
complex firewalling and/or traffic control rules.



Giacomo Mulas <gmulas@ca.astro.it>

Str. 54, Loc. Poggio dei Pini * 09012 Capoterra (CA)

Tel. (OAC): +39 070 71180 248     Fax : +39 070 71180 222
Tel. (UNICA): +39 070 675 4916

"When the storms are raging around you, stay right where you are"
                         (Freddy Mercury)

Reply to: