Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 21 Jul 2002 15:27:31 +0200
From:      Bernd Walter <ticso@cicely5.cicely.de>
To:        chris scott <chris.scott@uk.tiscali.com>
Cc:        freebsd-questions@FreeBSD.ORG, freebsd-security@FreeBSD.ORG
Subject:   Re: roaming ipsec policies and racoon
Message-ID:  <20020721132730.GB83916@cicely5.cicely.de>
In-Reply-To: <008501c2304c$59fbd800$a4102c0a@viper>
References:  <008501c2304c$59fbd800$a4102c0a@viper>

next in thread | previous in thread | raw e-mail | index | archive | help
On Sun, Jul 21, 2002 at 01:16:18AM +0100, chris scott wrote:
> Hi,
> 
> I am currently trying playing with IPSEC and racoon to provide a secure services for my users. They all use either freebsd or windows 2k/XP clients. They unfortunately all have dynamic ips 8(. I have successfully configured the ipsec policies and have got round the dynamic IP problem with the freebsd clients by using  racoons peer and my identifier  features to initiate the shared key communication. This all works fine. However I don't know how to do the same thing with windows 2000/XP. I can setup the ipsec policies on the clients easily enough, as I can the preshared key. I have no idea how to set the identifiers though. Without this racoon doesn't match a key on the psk.txt file as it uses the hosts ip rather than whatever@this.com and hence fails the key exchange. Has anyone got any clues to point me in the correct direction?

With Windows you have to either use PPTP or L2TP/IPSec-tranport mode.
Windows native implementation of IPSec-tunnel mode only works with
fixed IPs.
You still have the option to use a different implementation than that
of  Microsoft.

-- 
B.Walter              COSMO-Project         http://www.cosmo-project.de
ticso@cicely.de         Usergroup           info@cosmo-project.de


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20020721132730.GB83916>