Custom Wireless Solution
Charles Sprickman
spork at inch.com
Thu Apr 26 03:17:40 UTC 2001
On Wed, 25 Apr 2001, John Kristoff wrote:
> Mike Schoenecker wrote:
> > if one is prone to be paranoia, using both [1] and [2] probably makes sense.
>
> Except that it is currently impractical for many sites since it requires
> an entirely Cisco end-to-end shop including the Cisco (or Microsoft's)
> RADIUS server.
Since all these products are bridges, wouldn't it make sense to just have
an Open/FreeBSD box at either end with two nics? Both os's can do IPSEC
tunnels, and both end nodes will only be bridging a single MAC address.
You end up with a "clean" network design (since you've got an actual
endpoint or 'router') and you can encrypt your traffic with a bit more
confidence than with the WEP stuff...
Charles
> John
>
More information about the NANOG
mailing list