Re: IPSec Provisioning Tools

Ricky Charlet <rcharlet@redcreek.com> Mon, 19 March 2001 19:55 UTC

Received: from lists.tislabs.com (portal.gw.tislabs.com [192.94.214.101]) by above.proper.com (8.9.3/8.9.3) with ESMTP id LAA02763; Mon, 19 Mar 2001 11:55:34 -0800 (PST)
Received: by lists.tislabs.com (8.9.1/8.9.1) id NAA01898 Mon, 19 Mar 2001 13:06:10 -0500 (EST)
Message-ID: <3AB63E91.F89A07F@redcreek.com>
Date: Mon, 19 Mar 2001 10:14:57 -0700
From: Ricky Charlet <rcharlet@redcreek.com>
Organization: Redcreek Communications
X-Mailer: Mozilla 4.75 [en] (X11; U; Linux 2.2.16-22 i686)
X-Accept-Language: en
MIME-Version: 1.0
To: Dirk Rosler <dirk@unicircuits.com>
CC: "Yap, Alister" <AYap@colt-telecom.com>, IPSec <ipsec@lists.tislabs.com>
Subject: Re: IPSec Provisioning Tools
References: <B6DBBE89.22F6%dirk@unicircuits.com>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Sender: owner-ipsec@lists.tislabs.com
Precedence: bulk

Dirk Rosler wrote:
> 
> > Does anyone know/recommend any tools for provisioning IPSec VPN tunnels?
> 
> Hi Alister,
> 
> I am looking into the same things, tools for carrier-scale VPN provisioning.
> 
> I haven't really gotten into the matter deeply yet, but I have superficially
> looked at two interesting, vendor-independent products. 1) Solsoft
> [solsoft.com](at the moment no IPSec support, but due shortly; neat router,
> firewall etc. policy tool that when extended to IPSec should become very
> interesting) 2) TBD Networks [tbdnetworks.com] a what appears to be very
> scalable solution, manageable via a browser interface.
> 
> Most other management tools I have looked at yet were more or less
> vendor-specific, which in the case of a heterogeneous network environment
> that telcos have is unsuitable.
> 
> I'd be very interested in your opinion and/or other solutions you -or anyone
> else for that matter- come across, so please let me know!
> 
> Regards
> 
> Dirk

Howdy,

	Work on standardized configuration of IPsec devices is just in its
infancy. You can follow the development of
draft-ietf-ipsp-ipsecpib-02.txt and
draft-ietf-ipsp-ipsec-conf-mib-00.txt.  The real trick of it will be
getting muitiple vendors to believe in the need for interoperable
configuration of IPsec devices. Therefore I appreciate your note asking
for it. And I encourage you to solicite the "IPsec Policy" working group
for further updates on the progress of inter-vendor configurability. The
"IPsec Policy" WG email list can be found at:

General Discussion:ipsec-policy@vpnc.org 
To Subscribe: ipsec-policy-request@vpnc.org 
In Body: subscribe 
Archive: http://www.vpnc.org/ipsec-policy/ 


-- 
  Ricky Charlet   : Redcreek Communications   : usa (510) 795-6903