Improving and Stabilizing the Racoon2 IKE Daemon in NetBSD(blog.netbsd.org) |
Improving and Stabilizing the Racoon2 IKE Daemon in NetBSD(blog.netbsd.org) |
> racoon2 is a system to exchange and install security parameters for IPsec. It consists of an IKEv1/IKEv2 key exchange daemon, a security policy management daemon, and a Kerberos-based key exchange daemon.
When would you use this over wireguard? There's a hint in
> for built-in Windows, iOS and Android VPN clients.
where I can see value if you want to provide a VPN without needing to install anything on the client, but that doesn't seem like a big thing to me. Or maybe legacy ipsec setups?
IPsec is standardized, Wireguard isn't. This is a two-edged sword; the standardization process has hurt IPsec quite a lot (to the suspicion of active sabotage) but at the same time it's much easier to get an IPsec setup certified for government use.
(Also, cf. down in the thread, you don't have to deal with the Wireguard people showing up and complaining that you implemented it.)
The killer feature for us is to be able to push routes to clients (unfortunately macos screwed this up royally in recent releases, so i had to build a custom client)
> When would you use a standalone program for NetBSD that is written in C, over a Linux kernel module with a GPL licence, or a standalone program written in one of two languages neither of which comes in NetBSD base, or a perpetually unfinished kernel module that isn't being worked on that is for the wrong BSD anyway?
> IPv6 support fixed and enabled by default
Oof. Bad sign to see either of these, though for opposite reasons. Broken IPv6 points to way insufficient testing & use. IKEv1 meanwhile is deprecated and rather ought to be removed entirely.
* https://mail-index.netbsd.org/tech-net/2020/08/25/msg007861....