[hipl-users] Re: Trying to understand OpenVPN instructions

  • From: Robert Moskowitz <rgm@xxxxxxxxxxxxxxx>
  • To: hipl-users@xxxxxxxxxxxxx
  • Date: Tue, 31 Mar 2009 07:45:52 -0400

Miika Komu wrote:
Robert Moskowitz wrote:

Hi,

I am reading http://infrahip.hiit.fi/hipl/manual/ch16s07.html

Is this suppose to be running openVPN over HIP? If so why the text:

it's about OpenVPN compatibility. The section is not written very clearly. I made some changes that will be available when merge again.

:)


A HIP and OpenVPN tunnel have roughly the same througput. It is even possible run HIP inside the OpenVPN tunnel, even though this seems to halve the throughput at least without any optimizations.

What is a HIP tunnel?

BEET SA.

So this is not a well worded comparison. BEET packets are smaller than OpenVPN packets? In congested networks this may make a difference?

Also a BEET tunnel cannot get you to other systems beyond the tunnel edge, which is something I sometimes want.


Can you configure OpenVPN to use LSIs?

I think the OpenVPN experiments were done using HITs.

Oh? I have never seen any documentation that OpenVPN supports IPv6. Can it do 6 over 6? 4 over 6? I have only seen 4 over 4.


Are you talking about plugging HIP over VPN or vice versa?

I need classic VPN capablity over HIP in limited cases. Either I am on the road and need to access non-HIP systems within my home network (IPv6 or v4, I currently use SSH and want to use HIP instead), or I want to reach external non-HIP systems via a HIP mid-box and hide my internal address (use an address on the mid-box).


LSIs are implemented using raw sockets and iptables. I can imagine that there could be problems, but you never know for sure until you try.

I just thought LSIs for mobility if the VPN only supports IPv4 for the outter addressing.



Other related posts: