IPSEC documentation

Brian Candler B.Candler at pobox.com
Wed Dec 28 11:12:42 PST 2005


On Wed, Dec 28, 2005 at 05:43:39PM +0100, VANHULLEBUS Yvan wrote:
> > Also excellent would be "bump in the wire" bridging, where the gateway
> > negotiates transport-mode security on behalf of clients without their being
> > aware of it, but as far as I know only OpenBSD supports that.
> 
> What is the benefit of transport mode for that, instead of just using
> an IPSec tunnel between the gates ???

"Opportunistic" encryption and gradual deployment.
http://www.thought.net/jason/bridgepaper/node9.html
(an interesting paper, read through to at least "Transparent Policy
Enforcement")

One use would be if you decided to roll out transport mode IPSEC across your
network; you could put all the legacy hosts behind such a gateway as a
transition measure until you had managed to upgrade them.

Regards,

Brian.


More information about the freebsd-net mailing list