CIPE

An IP encryption package

Version 1.5

February 2001

Olaf Titz


(1)

As CIPE is an IP routing application, this manual talks only about IP-based networks.

(2)

For Linux 2.2, this has been merged into the ipip module, but the functionality is the same.

(3)

GSSAPI/Kerberos authentication is not supported because (a) I don't have the environment to test it, and (b) it can specify that UDP packets be encrypted with its own method, which is unnecessary and causes only additional load here, and (c) it makes the implementation much more complicated.

(4)

Use 127.0.0.1:9, the discard UDP port on the local host

(5)

Note the similarity to the @command{ssh

(6)

It is also possible, but less convenient, to configure this statically: The carrier address of the `2' end should be the special dummy 127.0.0.1:9, and the ip-up script in `2' should have the ping statement as in the sample. See also `1-3'.

(7)

Static configuration like `1-2' is also possible.

(8)

Dynamic DNS is easiest to handle because it does not need any external scripts or special software for CIPE, only the dynamic DNS client. There are some services which provide dynamic DNS free of charge.


This document was generated on 12 February 2002 using texi2html 1.56k.