Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For me it's just easier to get my head around having a new network interface presented rather than this pile of security associations and transform configurations. I can just re-use my firewalling and routing knowledge and do not have to put my mind into IPsec mode to manage this. That aside, I think it's still quite a lot easier to use IPsec tooling when you want something that plays along with certificate based multi-level trust models.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: