ipsec ain’t easy
September 7, 2004 | Filed Under General |29 degrees. Amazing, so cycled to uni again. Lunch was also a lot better than last Thurday.
We had another scheduled demonstration for our university wlan project. After we’ve solved the firewall issues last week, we ran into another problem. Some sites were not reachable via http. We think that it has something to do with the mtu size since experiments with a mtu size of 1300 were successful. Also ran into more stability problems which are quite bizarre. Sometimes a client could not establish a secured connection. After a restart of the software on the gateway everything was working again. But this is not really a practical solution for a system that is supposed to serve quite a lot of clients simulteanously.
The presentation of the client was quite a desaster. Did not surprise me, because in my opinion it is difficult if not even impossible to create a simple, cheap and secure ipsec solution that supports the major clients (windows, linux, macos) at the moment.
The idea of switching to openvpn came up again. This would mean losing most of the gateway work from the past 3 months but in the end it might be easier and less painful to deploy.
Went for pancakes at the “Cafe Blau”, two Andexer at the Pendel - where we finally saw Nora again - and a Korean soup at the NetzLaden. Even managed to sell 4 geekladen shirts.