Hi,
> I think it might be simpler if we did things as named policies and left
> it up to people whether to integrate these named policies into
> default/inner-tunnel or to generate their own virtual servers.
you want this stuff to work and be adopted, right? there seem to be only
about a dozen people (well, based on the FR mailing lists) that are able
to configure a FR server with any complexity in it. my proposal would deal
with the other 99.90% of FR admins - some of who are going to have this
software forced onto them and dont know any unix 101 :\
alan
|