Hi Christian,
Our Goal for now is to implement the IPsec with the minimum setting and options and i will consider the next:
- We will focus on IP v4
- All the policy configurations (ipsec.confg, policy
files , ISAKMP files ) will be configured a head .
- We are looking for implementing Authentication Header (AH) only
and in the next stage we will add Encapsulating
Security Payload (ESP).
- We are looking for implementing the Transport Mode
- The ISAKMP
should be able to recognize the KEYNOTE, so we will use the OpenBSD
implantation for the ISAKMP
- In the current stage we will use static IPs to simplify the negotiate process
- The main object now
to implement the Security Associations (SA) and the packet
filter options .
I am Open for suggestions and prior experiences. In the same time i am welcoming any one would like to participate .
Best
Mohammad