Re: [gentoo-user] Traffic Intensive IPSec Tunnel

2013-05-12 Thread Mick
On Sunday 12 May 2013 03:37:48 Nick Khamis wrote: Thanks yet again Michael! Enjoy your weekend. N. On 5/11/13, Michael Mol mike...@gmail.com wrote: On 05/11/2013 03:13 PM, Nick Khamis wrote: Hello Everyone, Our service provider requires all connections between us be done through

Re: [gentoo-user] Traffic Intensive IPSec Tunnel

2013-05-12 Thread Adam Carter
You can read a comparison between the *Swans here, but things have moved on since; e.g. StrongSwan supports IKEv1 in Aggressive Mode, Aggressive mode with pre-shared keys is vulnerable to offline dictionary attack so you might as well use main mode. If for some reason you have to use

Re: [gentoo-user] Traffic Intensive IPSec Tunnel

2013-05-12 Thread Mick
On Monday 13 May 2013 03:13:27 Adam Carter wrote: You can read a comparison between the *Swans here, but things have moved on since; e.g. StrongSwan supports IKEv1 in Aggressive Mode, Aggressive mode with pre-shared keys is vulnerable to offline dictionary attack so you might as well use

[gentoo-user] Traffic Intensive IPSec Tunnel

2013-05-11 Thread Nick Khamis
Hello Everyone, Our service provider requires all connections between us be done through IPSec IKE. From the little bit of research, I found that this is achieved using a system with IPSec kernel modules enabled, along with cryptography modules. On the application level, I saw ipsec tool,

Re: [gentoo-user] Traffic Intensive IPSec Tunnel

2013-05-11 Thread Michael Mol
On 05/11/2013 03:13 PM, Nick Khamis wrote: Hello Everyone, Our service provider requires all connections between us be done through IPSec IKE. From the little bit of research, I found that this is achieved using a system with IPSec kernel modules enabled, along with cryptography modules. On

Re: [gentoo-user] Traffic Intensive IPSec Tunnel

2013-05-11 Thread Nick Khamis
Thanks yet again Michael! Enjoy your weekend. N. On 5/11/13, Michael Mol mike...@gmail.com wrote: On 05/11/2013 03:13 PM, Nick Khamis wrote: Hello Everyone, Our service provider requires all connections between us be done through IPSec IKE. From the little bit of research, I found that this