From owner-freebsd-net@FreeBSD.ORG Sun Sep 17 12:55:42 2006 Return-Path: X-Original-To: freebsd-net@freebsd.org Delivered-To: freebsd-net@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 546CD16A416 for ; Sun, 17 Sep 2006 12:55:42 +0000 (UTC) (envelope-from vanhu@zeninc.net) Received: from leia.fdn.fr (ns0.fdn.org [80.67.169.12]) by mx1.FreeBSD.org (Postfix) with ESMTP id 0426443D58 for ; Sun, 17 Sep 2006 12:55:39 +0000 (GMT) (envelope-from vanhu@zeninc.net) Received: from smtp.zeninc.net (reverse-25.fdn.fr [80.67.176.25]) by leia.fdn.fr (8.13.3/8.13.3/FDN) with ESMTP id k8HCta2R025595 for ; Sun, 17 Sep 2006 14:55:37 +0200 Received: from jayce.zen.inc (jayce.zen.inc [192.168.1.7]) by smtp.zeninc.net (smtpd) with ESMTP id 0337F3F17 for ; Sun, 17 Sep 2006 14:55:30 +0200 (CEST) Received: by jayce.zen.inc (Postfix, from userid 1000) id CDD302E1FD; Sun, 17 Sep 2006 14:55:31 +0200 (CEST) Date: Sun, 17 Sep 2006 14:55:31 +0200 From: VANHULLEBUS Yvan To: freebsd-net@freebsd.org Message-ID: <20060917125531.GA1611@jayce.zen.inc> References: <20060914093034.A83805@gta.com> <20060915091430.A45488@gta.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: User-Agent: All mail clients suck. This one just sucks less. Subject: Re: FAST_IPSEC NAT-T support X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 17 Sep 2006 12:55:42 -0000 On Fri, Sep 15, 2006 at 12:07:58PM -0400, Scott Ullrich wrote: [....] > Next problem that I have encountered (with FAST_IPSEC) is: > > # /sbin/setkey -D > Invalid extension type > Invalid extension type > Invalid extension type > Invalid extension type > Invalid extension type > Invalid extension type > Invalid extension type > Invalid extension type > Invalid extension type > Invalid extension type > Invalid extension type > Invalid extension type > Invalid extension type > Invalid extension type > > Let me know if I can do any further testing, still waiting for status > reports from a few of the pfSense users, but IPSEC seems to work okay > even with this small cosmetic setkey issue. Make sure your ipsec-tools port have been recompiled after your system has been patched / compiled / upgraded, and use /usr/local/sbin/setkey. FreeBSD's setkey does not (yet ?) support NAT-T extensions at all. Yvan. -- NETASQ http://www.netasq.com