isakmpd and x509

2006-02-07 Thread Vincent Bernat
Hi ! By reading carefully isakmpd(8), isakmpd.conf(5) and isakmpd.policy(5) but I don't fully understand how to setup correctly isakmpd to work with X509 certificates. In isakmpd(8), it is said that client certificates must be put in /etc/isakmpd/certs. Why would isakmpd need those

Re: IPsec performance

2005-11-08 Thread Vincent Bernat
OoO En cette fin de matinie radieuse du mardi 08 novembre 2005, vers 11:05, Otto Moerbeek [EMAIL PROTECTED] disait: OpenBSD is running on a Celeron 2.4 GHz and openssl speed aes gives 70 MB/s and des-ede3 gives 15 MB/s. With 40 Mb/s (megabits/s) of traffic, the processor is used at 100%.

IPsec performance

2005-11-07 Thread Vincent Bernat
Hi ! I have several questions about IPsec performance in OpenBSD. I am using IPsec to maintain more than 60 tunnels and it performs well when those tunnels are idle. Tunnels are either using 3DES or AES. 3DES is due to the fact that clients are using Windows where AES is not