Le (On) Fri, Sep 21, 2001 at 09:47:03AM +0100, Brian Somers ecrivit (wrote):
> 
>   spdadd 1.2.3.4/32 5.6.7.8/32 ip4 -P in ipsec esp/transport//require;
>   spdadd 5.6.7.8/32 1.2.3.4/32 ip4 -P out ipsec esp/transport//require;
> 
> This is your setkey input.  The ``ip4'' bit tells ipsec to only touch 
> IP-in-IP traffic, so comms going from an internal LAN to an external 
> gateway address (1.2.3.4 or 5.6.7.8) won't be encrypted (but may be 
> NAT'd).  Only the gif-encapsulated traffic is encrypted.

Hum, looks great, but the man page for setkey says:

«     spdadd src_range dst_range upperspec policy ;

     upperspec
             Upper-layer protocol to be used.  Currently tcp, udp and any can
             be specified.  any stands for ``any protocol''. »

And when I use 'ip4' instead of any/icmp/tcp/udp, it says: 
line #[where ip4]: Syntax error at [i].

(Funny error location, by the way).

Is it a « new feature » with 4.4's shipped KAME's setkey ?

-- 
Sameh

To Unsubscribe: send mail to [EMAIL PROTECTED]
with "unsubscribe freebsd-net" in the body of the message

Reply via email to