Connect to Cisco VPN server from FreeBSD?

From: Scott Mitchell (scott+lists.freebsd_at_fishballoon.org)
Date: 04/10/05

  • Next message: Jay O'Brien: "Re: [PATCH TO TEST] VESA [1024x768] mode support for FreeBSD-CURRENT"
    Date: Sun, 10 Apr 2005 16:38:34 +0100
    To: freebsd-questions@freebsd.org
    
    

    Hi all,

    As in the subject - has anyone managed to get a FreeBSD machine to connect
    to a Cisco VPN server, using IPSec and 2-factor authentication (password +
    SecurID card)? My employer has been acquired by another company, and this
    will soon be the only remote-access method available. Linux client
    software exists, but given that it relies on a kernel module I'm not
    holding out much hope of it working. The security/vpnc port looks like it
    might be useful. No idea if racoon + FreeBSD native IPSec can be persuaded
    to do the SecurID authentication.

    I would try all these things myself, except I don't have any account
    details for the server yet. I really don't want to keep a Linux or Windows
    machine around just to connect to the office...

    Many thanks in advance,

            Scott

    -- 
    ===========================================================================
    Scott Mitchell           | PGP Key ID | "Eagles may soar, but weasels
    Cambridge, England       | 0x54B171B9 |  don't get sucked into jet engines"
    scott at fishballoon.org | 0xAA775B8B |      -- Anon
    _______________________________________________
    freebsd-questions@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-questions
    To unsubscribe, send any mail to "freebsd-questions-unsubscribe@freebsd.org"
    

  • Next message: Jay O'Brien: "Re: [PATCH TO TEST] VESA [1024x768] mode support for FreeBSD-CURRENT"

    Relevant Pages

    • Re: MSFT Bans insecure hashes - was"Passwords with Lan Manager (LM) under Windows"
      ... After I pointed out that "IPsec based auth" is not a basic netlogon ... authentication protocol like Kerberos, LM, NTLM and NTLMv2, you said I was ... based auth" to authenticate the request as opposed to LM, NTLM, or NTLMv2. ... Up to 75% of cyber attacks are launched on shopping carts, forms, ...
      (Pen-Test)
    • RE: Passwords with Lan Manager (LM) under Windows
      ... A device's security associations are contained in its Security Association Database ... Internet Protocol Security (IPSec) provides application-transparent encryption services for IP network traffic as well as other network access protections for the Windows 2000 operating system. ... As for "article you reference does indeed use the phrase "IPSec Authentication," but as any who reads it ...
      (Pen-Test)
    • Re: Kerberos machine authentication - apparent authentication fail
      ... as the case may be) which will delay authentication until ... I also have an Intel network adapter and WAP that does not have this> problem and even works well with 802.1X EAP-TLS for domain logon. ... In> most cases [ipsec a possible exception] kerberos authentication is not> needed to access domain resources as long as the client and server use a> common authentication method for lm/ntlm/ntlmv2. ... The main issue is to> NEVER include an ISP dns server in the preferred server list in the tcp/ip> properties or DHCP scope of any domain computer or any computer you want to> join to the domain in which case your computers may be trying to locate the> domain _srv records on the ISP dns server and fail. ...
      (microsoft.public.windows.server.security)
    • Re: IPsec - restrict communcation
      ... IPsec can use three different methods to initially authenticate machines: ... permit, block, or negotiate security, as well as authentication methods ... you don't need the communications to be private. ...
      (microsoft.public.security)
    • Re: Attacks on IPsec
      ... The real problem seems to be not the IPSec protocol, ... RFC 2406 says that encryption without authentication ... This cipher can be used in an ESP ...
      (sci.crypt)