1 Oct 2008 09:36
[Openswan dev] IPsec over IPv6 including 6to4 ... some success, and some documentation opportunities
John Denker <jsd <at> av8n.com>
2008-10-01 07:36:15 GMT
2008-10-01 07:36:15 GMT
Hi Folks -- I recently brought up IPsec over IPv6. I'm happy to report it was mostly uneventful. For me, this is important. It means I don't need to fool with NAPT traversal ever again. Of course this is using pluto with kernel IPsec via netkey, not using klips. For the next level of detail on all of this, see http://www.av8n.com/computer/htm/ipv6-howto.htm especially http://www.av8n.com/computer/htm/ipv6-howto.htm#sec-ipsec Some suggestions: 1) There ought to be more documentation about using kernel IPsec instead of klips. The documentation is very sketchy on this topic, and soon degenerates into unhelpful whining about ancient political issues. Also this part of the documentation contains some broken links. 2) Similarly, there ought to be more documentation of using openswan over IPv6. I talked to some people who weren't even sure it would work. There is not a single mention of "connaddrfamily" in the /doc directory, unless my grep is missing something (although it is mentioned properly on the ipsec.conf manpage). Some examples would be nice.(Continue reading)
RSS Feed