1 comments

  • yjftsjthsd-h 54 minutes ago
    I suspect I'm in a bubble, so perhaps someone might tell me what I'm missing...

    > racoon2 is a system to exchange and install security parameters for IPsec. It consists of an IKEv1/IKEv2 key exchange daemon, a security policy management daemon, and a Kerberos-based key exchange daemon.

    When would you use this over wireguard? There's a hint in

    > for built-in Windows, iOS and Android VPN clients.

    where I can see value if you want to provide a VPN without needing to install anything on the client, but that doesn't seem like a big thing to me. Or maybe legacy ipsec setups?

    • wmf 10 minutes ago
      There is a lot of legacy IPSec out there. For example AWS Site-to-Site VPN seems to still be IPSec.