Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 28 Aug 2006 00:20:51 +0200
From:      =?ISO-8859-1?Q?Erik_N=F8rgaard?= <norgaard@locolomo.org>
To:        Jim Stapleton <stapleton.41@gmail.com>
Cc:        freebsd-questions@freebsd.org
Subject:   Re: IPSEC, am I missing something?
Message-ID:  <44F21AC3.2080908@locolomo.org>
In-Reply-To: <80f4f2b20608271358l32b84ed6m5c6e5819d38c5c01@mail.gmail.com>
References:  <80f4f2b20608271358l32b84ed6m5c6e5819d38c5c01@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
Jim Stapleton wrote:

> What I found and added:
> #ipsec: Required for VPN
> options        IPSEC        #IP security
> options        IPSEC_ESP    #IP security (crypto; define w/ IPSEC)
> #ipsec optimsations
> options        FAST_IPSEC   # new IPsec (cannot define w/ IPSEC)
> options        IPSEC_FILTERGIF  #filter ipsec packets from a tunnel
> 
> before adding these, I just had the default 6.1 generic kernel file
> with a few things commented and a couple uncommented.

Just start with the first two options, then add the others if needed.
But before you start, check if this actually solves the problem. There
is a well known problem with IPSec across NAT-firewalls: Authenticated
Headers don't work.

Not all kernel options are in the GENERIC file, look for the NOTES file,
platform specific NOTES are where you find the GENERIC for your
platform, but there is also a general NOTES.

Cheers, Erik
-- 
Ph: +34.666334818                      web: http://www.locolomo.org
X.509 Certificate: http://www.locolomo.org/crt/8D03551FFCE04F0C.crt
Key ID: 69:79:B8:2C:E3:8F:E7:BE:5D:C3:C3:B1:74:62:B8:3F:9F:1F:69:B9

[-- Attachment #2 --]
0	*H
010	+0	*H
00נ	UO0
	*H
010	UES10U
Daemon Security10UCertificate Authority10UCertificate Authority1$0"	*H
	ca@daemonsecurity.com1
0U00
060420131650Z
070420131650Z0b10	UES10U
LocoLomo.Org10U
Erik Norgaard1$0"	*H
	norgaard@locolomo.org0"0
	*H
0
>NPLGMK	$^ha~	Xם-`Y^P
oœtƥ*\.e_!2\j]m)B>v+z2VfDѝR}Tc&E/#_.9DŽ9÷(3	?ԝWu%)vŅͯTr)FA+(R6ƶw
{9zP_Q^zpk/jXMYn0j0U00U0Uiy,]ñtb?i0U#0Àa&WtЕna=⥡010	UES10U
Daemon Security10UCertificate Authority10UCertificate Authority1$0"	*H
	ca@daemonsecurity.com1
0U0	UO0 U0norgaard@locolomo.org08U10/0-+)'http://www.daemonsecurity.com/ca/ds.crl0
	*H
ǟ@&<mWc4LS@G4['s5\\VN^`I
&>"@>"[xq89`@sG;LP]ƜTT|sGٶ2Ҋctx?'ҭ$0r;2#ba"%$B
p%rԆU
ì>!73ȁg6_I.2Ġ!AaAmF
G'bךuf>-dxqq09#XOSk+FuyTvr+p!!}n.6NH'5+9`CVĩ;7RߔRKIpv&S@P`;%eƓxCuiL	Cb
Y,)x:3ѓGjRe
EtPҰk<
c\;9pT9/K̩ LHzMMuʔ(dkskj<ds08PxZ
NWC00נ	UO0
	*H
010	UES10U
Daemon Security10UCertificate Authority10UCertificate Authority1$0"	*H
	ca@daemonsecurity.com1
0U00
060420131650Z
070420131650Z0b10	UES10U
LocoLomo.Org10U
Erik Norgaard1$0"	*H
	norgaard@locolomo.org0"0
	*H
0
>NPLGMK	$^ha~	Xם-`Y^P
oœtƥ*\.e_!2\j]m)B>v+z2VfDѝR}Tc&E/#_.9DŽ9÷(3	?ԝWu%)vŅͯTr)FA+(R6ƶw
{9zP_Q^zpk/jXMYn0j0U00U0Uiy,]ñtb?i0U#0Àa&WtЕna=⥡010	UES10U
Daemon Security10UCertificate Authority10UCertificate Authority1$0"	*H
	ca@daemonsecurity.com1
0U0	UO0 U0norgaard@locolomo.org08U10/0-+)'http://www.daemonsecurity.com/ca/ds.crl0
	*H
ǟ@&<mWc4LS@G4['s5\\VN^`I
&>"@>"[xq89`@sG;LP]ƜTT|sGٶ2Ҋctx?'ҭ$0r;2#ba"%$B
p%rԆU
ì>!73ȁg6_I.2Ġ!AaAmF
G'bךuf>-dxqq09#XOSk+FuyTvr+p!!}n.6NH'5+9`CVĩ;7RߔRKIpv&S@P`;%eƓxCuiL	Cb
Y,)x:3ѓGjRe
EtPҰk<
c\;9pT9/K̩ LHzMMuʔ(dkskj<ds08PxZ
NWC100010	UES10U
Daemon Security10UCertificate Authority10UCertificate Authority1$0"	*H
	ca@daemonsecurity.com1
0U0	UO0	+)0	*H
	1	*H
0	*H
	1
060827222051Z0#	*H
	1`u3r0Q?+HT0R	*H
	1E0C0
*H
0*H
0
*H
@0+0
*H
(0	+710010	UES10U
Daemon Security10UCertificate Authority10UCertificate Authority1$0"	*H
	ca@daemonsecurity.com1
0U0	UO0*H
	1010	UES10U
Daemon Security10UCertificate Authority10UCertificate Authority1$0"	*H
	ca@daemonsecurity.com1
0U0	UO0
	*H
n-{*n]&^#tIX)+Uip.

Pz;#@(j3ʄt"VğZޕ䂋6yߟ-
#<O%iyY<cœBnRu}UGO!tfTWȓ3:ExTw
/RE}逌73r@5xzOPhpqClǯQ#ę:1DKi]AFupJ)8Wc/0

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?44F21AC3.2080908>