From owner-freebsd-current@FreeBSD.ORG Fri Jan 25 04:47:34 2008 Return-Path: Delivered-To: freebsd-current@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 773A316A418 for ; Fri, 25 Jan 2008 04:47:34 +0000 (UTC) (envelope-from matheusber@gmail.com) Received: from wa-out-1112.google.com (wa-out-1112.google.com [209.85.146.178]) by mx1.freebsd.org (Postfix) with ESMTP id 47E6F13C4DB for ; Fri, 25 Jan 2008 04:47:34 +0000 (UTC) (envelope-from matheusber@gmail.com) Received: by wa-out-1112.google.com with SMTP id k17so827734waf.3 for ; Thu, 24 Jan 2008 20:47:33 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:received:received:message-id:date:from:to:subject:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; bh=LyTu5SvtkwD7FjeZIQPQom4xUyIVj0+OTm5OvJOtraM=; b=juwKFIQwVyqZaTQt1FH7K02LwNL2yQm2BCetZXSp25HHaP4dzNQg42+8/dCzm6QBhEBwn2z5pEcRHlnDGSy2fC5G+6ZS1FwTkjU0FqqYxwMDlzhiJUG8IZEUZFS0ZAXQXsRWP8V6rH64tQ8vlXMvwUMc+7hPgiGU4Hv/gGwLr2Q= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=message-id:date:from:to:subject:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=cdiuXQZ9/BFq8kxvyp7RdeZkEx+VjmhF0W9yZNBkQS0fqylC1/NOesVpmPbFQJrrpVXZZT1PmQ2RBasBEVlJuM2Us5N/EkUG3yCy2yZe5n8/oplgpzN6RrcQUeumzPnma6AZkAO5tV1EGYKFVUUJgEGopRLd03Oa9JMyy+UohDo= Received: by 10.114.178.1 with SMTP id a1mr1727204waf.135.1201234809013; Thu, 24 Jan 2008 20:20:09 -0800 (PST) Received: by 10.115.16.7 with HTTP; Thu, 24 Jan 2008 20:20:08 -0800 (PST) Message-ID: <4956a5e50801242020j41fea759v84720c62a246db63@mail.gmail.com> Date: Fri, 25 Jan 2008 01:20:08 -0300 From: Nenhum_de_Nos To: freebsd-current@freebsd.org In-Reply-To: <4956a5e50801242019m37675b90t7fbbb72d4d917960@mail.gmail.com> MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Content-Disposition: inline References: <012101c85cbe$3d93fef0$292d280a@friedman.net> <4795B6ED.8020902@beardz.net> <003901c85d02$96a78d60$292d280a@friedman.net> <4956a5e50801242019m37675b90t7fbbb72d4d917960@mail.gmail.com> X-Mailman-Approved-At: Fri, 25 Jan 2008 12:15:48 +0000 Subject: IPSEC on 7.0-PRERELEASE X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 25 Jan 2008 04:47:34 -0000 ---------- Forwarded message ---------- From: Nenhum_de_Nos Date: Jan 25, 2008 1:19 AM Subject: Re: IPSEC on 7.0-PRERELEASE To: "Dr. Aharon Friedman" On Jan 22, 2008 11:25 AM, Dr. Aharon Friedman wrote: > This looks like the solution. It did pass compile. I have not run it yet, > but I am sure it will work. Here is the configuration part for IPSEC: > > > > options IPSEC #IP security (requires device crypto) > > options IPSEC_FILTERTUNNEL #filter ipsec packets from a > tunnel > > device enc #IPsec interface > > device crypto # core crypto support > > device cryptodev # /dev/crypto for access to h/w > > > > Aharon I have a IPSec tunnel over gif ifaces and all ok. was I supposed to change anything ? thanks, matheus -- We will call you cygnus, The God of balance you shall be -- We will call you cygnus, The God of balance you shall be