Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 26 Jan 2008 22:33:59 +0800
From:      gnn@freebsd.org
To:        Nenhum_de_Nos <matheusber@gmail.com>
Cc:        freebsd-current@freebsd.org
Subject:   Re: IPSEC on 7.0-PRERELEASE
Message-ID:  <m2wspwoduw.wl%gnn@neville-neil.com>
In-Reply-To: <4956a5e50801242020j41fea759v84720c62a246db63@mail.gmail.com>
References:  <012101c85cbe$3d93fef0$292d280a@friedman.net> <4795B6ED.8020902@beardz.net> <003901c85d02$96a78d60$292d280a@friedman.net> <4956a5e50801242019m37675b90t7fbbb72d4d917960@mail.gmail.com> <4956a5e50801242020j41fea759v84720c62a246db63@mail.gmail.com>

index | next in thread | previous in thread | raw e-mail

At Fri, 25 Jan 2008 01:20:08 -0300,
Nenhum_de_Nos wrote:
> 
> ---------- Forwarded message ----------
> From: Nenhum_de_Nos <matheusber@gmail.com>
> Date: Jan 25, 2008 1:19 AM
> Subject: Re: IPSEC on 7.0-PRERELEASE
> To: "Dr. Aharon Friedman" <AFriedman@drsns.com>
> 
> 
> On Jan 22, 2008 11:25 AM, Dr. Aharon Friedman <AFriedman@drsns.com> wrote:
> > This looks like the solution.  It did pass compile.  I have not run it yet,
> > but I am sure it will work.  Here is the configuration part for IPSEC:
> >
> >
> >
> > options     IPSEC             #IP security (requires device crypto)
> >
> > options           IPSEC_FILTERTUNNEL      #filter ipsec packets from a
> > tunnel
> >
> > device            enc               #IPsec interface
> >
> > device            crypto            # core crypto support
> >
> > device            cryptodev   # /dev/crypto for access to h/w
> >
> >
> >
> > Aharon
> 
> I have a IPSec tunnel over gif ifaces and all ok. was I supposed to
> change anything ?
> 

Sorry to reply so late, I'm traveling at the moment.  In 7.0 we have
moved to a single IPsec stack, that stack requires the "device crypto"
line whether you're using software or hardware cryptography.  I think
it's time for a documentation update but that will have to wait until
I clear away some other $dayjob related work.  If someone is up for
updating our IPsec docs I'd be able to help with that, just not do it
completely on my own.

Best,
George


home | help

Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?m2wspwoduw.wl%gnn>