Re: fbsd amd64 and fast_ipsec



On Wed, 14 Mar 2007, rms_zaphod wrote:

Hi <real name of:rms_zaphod>,

OK, I have used these ken mods for my file server/nat/router/firewall servers
for years. (kern ops then question)

options FAST_IPSEC
device crypto

With 6.2, with latest (3.13.07) cvsup -L 2 -h `(fastest_cvsup -q -c us )`
/root/stable-supfile

make buildworld etc...I STILL cannot get setkey nor racoon to function. I
keep getting a pfkey error, and cannot establish a VPN tunnel. I can if I
use:

can you be more specific about which "racoon"?
Which "setkey" and what errors when doing what?

I'll be happy to fix more amd64/(fast)ipsec bugs but I need details so
I can try to reproduce them.

--
Bjoern A. Zeeb bzeeb at Zabbadoz dot NeT
_______________________________________________
freebsd-net@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-net
To unsubscribe, send any mail to "freebsd-net-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: [PATCH] fbsd amd64 and fast_ipsec
    ... make buildworld etc...I STILL cannot get setkey nor racoon to function. ... testor# setkey -D ... and I recieved the same error message. ...
    (freebsd-net)
  • Re: Tov?bb?t?s: [Ipsec-tools-users] freebsd & linux setup question
    ... I've recompiled racoon with NATT, but as you've said, only pure Internet is between A and B without NAT, and thus it did not solve my problem. ... I can confirm, that setkey -D and -DP's output were full, so only the two entries existed for the SA's and policices. ... I've a working tunnel setup between two linux hosts. ...
    (freebsd-net)
  • Re: Re: Racoon to Cisco ASA 5505
    ... If I want to clean up my racoon configuration file, ... crypto ipsec security-association lifetime kilobytes 4608000 ... setkey -FP ...
    (freebsd-questions)
  • RELENG_5 and FAST_IPSEC limits
    ... We are running into a case where there are too many SAs, and doing a setkey ... This also seems to send racoon into a hung state that we then need ... #define RAWSNDQ 8192 ... #define RAWRCVQ 8192 ...
    (freebsd-stable)