Date: Mon, 28 Aug 2006 00:20:51 +0200 From: =?ISO-8859-1?Q?Erik_N=F8rgaard?= <norgaard@locolomo.org> To: Jim Stapleton <stapleton.41@gmail.com> Cc: freebsd-questions@freebsd.org Subject: Re: IPSEC, am I missing something? Message-ID: <44F21AC3.2080908@locolomo.org> In-Reply-To: <80f4f2b20608271358l32b84ed6m5c6e5819d38c5c01@mail.gmail.com> References: <80f4f2b20608271358l32b84ed6m5c6e5819d38c5c01@mail.gmail.com>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --] Jim Stapleton wrote: > What I found and added: > #ipsec: Required for VPN > options IPSEC #IP security > options IPSEC_ESP #IP security (crypto; define w/ IPSEC) > #ipsec optimsations > options FAST_IPSEC # new IPsec (cannot define w/ IPSEC) > options IPSEC_FILTERGIF #filter ipsec packets from a tunnel > > before adding these, I just had the default 6.1 generic kernel file > with a few things commented and a couple uncommented. Just start with the first two options, then add the others if needed. But before you start, check if this actually solves the problem. There is a well known problem with IPSec across NAT-firewalls: Authenticated Headers don't work. Not all kernel options are in the GENERIC file, look for the NOTES file, platform specific NOTES are where you find the GENERIC for your platform, but there is also a general NOTES. Cheers, Erik -- Ph: +34.666334818 web: http://www.locolomo.org X.509 Certificate: http://www.locolomo.org/crt/8D03551FFCE04F0C.crt Key ID: 69:79:B8:2C:E3:8F:E7:BE:5D:C3:C3:B1:74:62:B8:3F:9F:1F:69:B9 [-- Attachment #2 --] 0 *H 010 + 0 *H 00נ UO0 *H 010 UES10U Daemon Security10UCertificate Authority10UCertificate Authority1$0" *H ca@daemonsecurity.com1 0U00 060420131650Z 070420131650Z0b10 UES10U LocoLomo.Org10U Erik Norgaard1$0" *H norgaard@locolomo.org0"0 *H 0 >NPLGMK $^ha~ Xם-`Y^P oœtƥ*\.e_!2\j]m)B>v+z2VfDѝR}Tc&E/#_.9DŽ9÷(3 ?ԝWu%)vŅͯTr)FA+(R6ƶw {9zP_Q^zpk/jXMY n0j0U0 0U0Uiy,]ñtb?i0U#0Àa&WtЕna=⥡010 UES10U Daemon Security10UCertificate Authority10UCertificate Authority1$0" *H ca@daemonsecurity.com1 0U0 UO0 U0norgaard@locolomo.org08U10/0-+)'http://www.daemonsecurity.com/ca/ds.crl0 *H ǟ@&<mWc4LS@G4['s5\\VN^`I &>"@>"[xq89`@sG;LP]ƜTT|sGٶ2 Ҋctx?'ҭ$0r;2#ba"%$B p%rԆU ì>!73ȁg6_I.2Ġ!AaAmF G'bךuf>-dxqq09#XOSk+FuyTvr+p!!}n.6NH'5+9`CVĩ;7RߔRKIpv&S@P`;%eƓxCuiL Cb Y,)x:3ѓGjRe EtPҰk< c\;9pT9/K̩ LHzMMuʔ(dkskj <ds08PxZ NWC00נ UO0 *H 010 UES10U Daemon Security10UCertificate Authority10UCertificate Authority1$0" *H ca@daemonsecurity.com1 0U00 060420131650Z 070420131650Z0b10 UES10U LocoLomo.Org10U Erik Norgaard1$0" *H norgaard@locolomo.org0"0 *H 0 >NPLGMK $^ha~ Xם-`Y^P oœtƥ*\.e_!2\j]m)B>v+z2VfDѝR}Tc&E/#_.9DŽ9÷(3 ?ԝWu%)vŅͯTr)FA+(R6ƶw {9zP_Q^zpk/jXMY n0j0U0 0U0Uiy,]ñtb?i0U#0Àa&WtЕna=⥡010 UES10U Daemon Security10UCertificate Authority10UCertificate Authority1$0" *H ca@daemonsecurity.com1 0U0 UO0 U0norgaard@locolomo.org08U10/0-+)'http://www.daemonsecurity.com/ca/ds.crl0 *H ǟ@&<mWc4LS@G4['s5\\VN^`I &>"@>"[xq89`@sG;LP]ƜTT|sGٶ2 Ҋctx?'ҭ$0r;2#ba"%$B p%rԆU ì>!73ȁg6_I.2Ġ!AaAmF G'bךuf>-dxqq09#XOSk+FuyTvr+p!!}n.6NH'5+9`CVĩ;7RߔRKIpv&S@P`;%eƓxCuiL Cb Y,)x:3ѓGjRe EtPҰk< c\;9pT9/K̩ LHzMMuʔ(dkskj <ds08PxZ NWC100010 UES10U Daemon Security10UCertificate Authority10UCertificate Authority1$0" *H ca@daemonsecurity.com1 0U0 UO0 + )0 *H 1 *H 0 *H 1 060827222051Z0# *H 1`u3r0Q?+HT0R *H 1E0C0 *H 0*H 0 *H @0+0 *H (0 +710010 UES10U Daemon Security10UCertificate Authority10UCertificate Authority1$0" *H ca@daemonsecurity.com1 0U0 UO0*H 1010 UES10U Daemon Security10UCertificate Authority10UCertificate Authority1$0" *H ca@daemonsecurity.com1 0U0 UO0 *H n-{*n]&^#tIX)+Uip. Pz;#@(j3ʄt"VğZޕ䂋6yߟ- #<O%iyY <cœBnRu}UGO!tfTWȓ3:ExTw /RE}逌73r@5xzOPhpqClǯQ#ę:1DKi]AFupJ)8Wc/0
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?44F21AC3.2080908>
