[strongSwan] how to create a ACL-like system based on certificates?

2010-05-13 Thread Andreas Schuldei
In order to have fine grained control over the IPsec traffic in our distributed network of host-to-host ipsec connections we would like to create a ACLs-like system. For example all servers should be able to talk to infrastructure hosts (like DNS or backup servers). Only the other storage

Re: [strongSwan] how to create a ACL-like system based on certificates?

2010-05-13 Thread John A. Sullivan III
On Thu, 2010-05-13 at 01:02 +0200, Andreas Schuldei wrote: In order to have fine grained control over the IPsec traffic in our distributed network of host-to-host ipsec connections we would like to create a ACLs-like system. For example all servers should be able to talk to infrastructure