Re: IPSec troubles

From: Crist J. Clark (cristjc_at_comcast.net)
Date: 03/29/04

  • Next message: Ruslan Ermilov: "Re: Disabling VLAN_HWTAGGING"
    Date: Mon, 29 Mar 2004 13:40:58 -0800
    To: Cyrill R?ttimann <ruettimac@mac.com>
    
    

    On Mon, Mar 29, 2004 at 12:06:21AM +0200, Cyrill R?ttimann wrote:
    > Hello,
    >
    > I have troubles setting up an IPSec Host-to-Host connection between
    > FreeBSD 5.2.1 and MacOS X 10.3.3:

    Last I knew, 5.2.1 still had broken IPsec. Specifically, the system
    tries to apply the IPsec policy to the IKE traffic giving us a chicken
    and egg problem. The Mac end timing out waiting to hear from the
    FreeBSD system is consistent with this. Run 'tcpdump -n port 500' on
    the FreeBSD system and watch for outgoing traffic, and have a look at
    'netstat -sp ipsec' and see if the 'outbound packets with no SA
    available' count is increasing.

    The workaround was to not use IPSEC in the kernel, but FAST_IPSEC.

    -- 
    Crist J. Clark                     |     cjclark@alum.mit.edu
                                       |     cjclark@jhu.edu
    http://people.freebsd.org/~cjc/    |     cjc@freebsd.org
    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"
    

  • Next message: Ruslan Ermilov: "Re: Disabling VLAN_HWTAGGING"

    Relevant Pages

    • Re: Win2K Security & Firewall - long post
      ... >> look at implementing an IPSec policy on Win2K for extra security. ... >> Today I went a stage further and did a fresh installation of Win2K, ...
      (comp.security.firewalls)
    • Re: IPSec: Network sooo slooooow
      ... but to secure all other traffic. ... > configure an ipsec policy in the domain you must exempt domain controllers ... > from ipsec negotiation. ...
      (microsoft.public.windows.server.networking)
    • Re: OU GPO Corrupts 2003 Servers only??
      ... have impact on the Servers OU. ... then you are looking at the effect of the default behaviors of IPsec ... In W2k3 the IPsec Policy Agent will block inbound during the boot ... inbound and outbound TCP/IP network traffic that is not permitted by ...
      (microsoft.public.windows.group_policy)
    • Win2K Security & Firewall - long post
      ... No security measures were taken except to install an IPSec ... I wanted the installation to ... Why have MS not urged people to implement an IPSec policy as a defence ...
      (comp.security.firewalls)
    • Re: Firewall für 2003 IIS Webserver
      ... aber in generellen Firewall Newsgroups kann man sich ... Server mach Linux drauf" etc. ... das durch die dort beschriebene IPSec Policy alle ...
      (microsoft.public.de.inetserver.iis)