Re: doubt about IPSEC - Freebsd 7



Hi.


On Sat, Nov 24, 2007 at 03:11:05PM +0100, Giulio Ferro wrote:
I've noticed that in the kernel configuration IPSEC_ESP disappeared
from the options. It says that you just need device crypto and IPSEC.

Does this mean that with crypto and IPSEC I have all I need to treat
ESP like the old IPSEC_ESP option?


IPSEC_ESP was a needed option for KAME's IPSec implementation, which
is no longer in FreeBSD's kernel.

IPSEC now enables FAST_IPSEC stack, which just needs IPSEC and device
crypto.


I'm having some problems right now setting up a vpn to complete phase 2,
(the error is no proposal chosen).
Since ipsec-tools uses the facilities in the kernel, I want to make sure
that the
kernel provides everything racoon needs...

That really sounds like a configuration issue (racoon.conf, or perhaps
your SPD entries), racoon's debug on responder should give you more
informations on the problem.



Yvan.

--
NETASQ
http://www.netasq.com
_______________________________________________
freebsd-hackers@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-hackers
To unsubscribe, send any mail to "freebsd-hackers-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: hardware encryption under freebsd
    ... > interface to hardware and software implementations of cryptographic ... > "A FAST_IPSEC kernel option now allows the IPsec implementation to use the ... In general I see 100% utilization of the crypto h/w under IPsec ...
    (FreeBSD-Security)
  • cisco 2801, ipsec problem with onboard accelerator
    ... I need to connect two 2801 over fast ethernet with ipsec encryption. ... crypto isakmp key hryakwesdxc address 192.168.200.241 ... tunnel source FastEthernet0/1 ... I guess that compression is done on CPU. ...
    (comp.dcom.sys.cisco)
  • Re: doubt about IPSEC - Freebsd 7
    ... It says that you just need device crypto and IPSEC. ... Since ipsec-tools uses the facilities in the kernel, ... kernel provides everything racoon needs... ...
    (freebsd-hackers)
  • doubt about IPSEC - Freebsd 7
    ... I've noticed that in the kernel configuration IPSEC_ESP disappeared ... It says that you just need device crypto and IPSEC. ... Since ipsec-tools uses the facilities in the kernel, I want to make sure that the ...
    (freebsd-hackers)
  • Re: 877 VPN problem to 837
    ... But strange thing is on either routers it does not show any debugging for ... debug crypto isakmp ... debug crypto ipsec ... crypto isakmp policy 140 ...
    (comp.dcom.sys.cisco)