[KLUG Hardware] Difference between Gold & Silver

Adam Tauno Williams hardware@kalamazoolinux.org
17 Apr 2003 07:37:55 -0400


> >>>Since either can be easily broken, I didn't see the point in buying 
> >>>a gold.  Besides, the higher encryption you go, the slower the link.  
> >>>Much better to run a VPN of some kind if you need security (IMO).
> >What is people preferred VPN solution for over wireless? 
> I used to use IPSEC in RH 8.0.  I read that the IPSEC kernel patches
> will not apply to a RH9 kernel (although I haven't actually tried it),
> so I'm looking for something different myself.
> One question:  Does PPTP require a kernel patch?  Recompiling my laptop
> kernel every other week when RH comes out with a new kernel is a PITA.

The PPTP client minus encryption will run without any kernel mods.  To
get 128 bit stateless compression you have to install a "tainted" kernel
module.  But no recompiling is required.  You do have to upgrade to a
special ppp (with M$ CHAP v2 and MPPE enabled).  They are pretty
studious about releasing RPMs every time there is a kernel update

> I already have my WAP isolated on it's on NIC (DMZ) on my firewall.
> Now I need to limit who can get to the internet from there.

Right thats what I intend to do.

> > Has anyone tried the VPN support built into RH9?