| Wichert Akkerman 2004-06-28, 9:14 am |
| Previously Marc Haber wrote:
> Linux 2.6 ipsec sucks, because it makes packet filtering much harder
> and more complicated, and debugging nearly impossible because you
> don't see the unencrypted packet with tcpdump.
As was already mentioned it isn't perfect yet; netfilter hooks are
definitely one such area. It does however have a nice modern design
and has the benefit of being the officialy blessed implementation on
which all future development will be based, so expect things to improve
rapidly.
Wichert.
--
Wichert Akkerman <wichert@wiggy.net> It is simple to make things.
http://www.wiggy.net/ It is hard to make things simple.
--
To UNSUBSCRIBE, email to debian-devel-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
|