Wednesday, May 31, 2023

Re: Route based IPsec

> On 31 May 2023, at 18:33, Claudio Jeker <cjeker@diehard.n-r-g.com> wrote:
>
> On Wed, May 31, 2023 at 08:35:45AM +1000, David Gwynne wrote:
>>
>>
>>> On 27 May 2023, at 21:40, Stuart Henderson <stu.lists@spacehopper.org> wrote:
>>>
>>> On 2023-05-27, Valdrin MUJA <valdrin_muja@outlook.com> wrote:
>>>> Does OpenBSD have routed based IPsec support?
>>>
>>> Not yet.
>>
>> while you wait, it might be possible to configure a gif tunnel protected
>> by ipsec transport mode.
>>
>
> The annoying bit with gif tunnels in transport mode is the need for static
> IPs on both sides of the tunnel. I ended up tunneling gif in tunnel mode
> because of that.

that's an annoying thing about gif, even without ipsec in the mix.

should i make it possible to specify an interface as the source of local addresses on tunnels?

No comments:

Post a Comment