Re: Site-to-site IPSec VPN using if_ipsec and racoon

2018-05-12 Thread Andrey V. Elsukov
On 13.05.2018 02:37, Andreas Scherrer wrote: > My interpretation of [2]'s statement: > > "If no security association is found, the packet is put on hold and the > IKE daemon is asked to negotiate an appropriate one." > > is that it should somehow be automagic. But in my current configuration, > t

Site-to-site IPSec VPN using if_ipsec and racoon

2018-05-12 Thread Andreas Scherrer
Hi I am trying to configure a site to site VPN using the (new?) if_ipsec interfaces [1]. One endpoint is FreeBSD 11.1-RELEASE whereas the other will be a RPi (Raspbian 9.4 stretch running libreswan). The public IPs involved are all IPv6 and the goal is to tunnel IPv4 traffic. Currently I am

[Bug 228163] ipfw & tunnel interfaces - strange tags are keeped after packet processing in kernel

2018-05-12 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=228163 Eugene Grosbein changed: What|Removed |Added CC||eu...@freebsd.org St

[Bug 228163] ipfw & tunnel interfaces - strange tags are keeped after packet processing in kernel

2018-05-12 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=228163 Mark Linimon changed: What|Removed |Added Assignee|b...@freebsd.org|n...@freebsd.org -- You are receiv

[Bug 228202] em/igb regression: after r333345 Intel I120 ethernet card is not initialized correctly

2018-05-12 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=228202 Mark Linimon changed: What|Removed |Added Keywords||IntelNetworking, regression

[Bug 195197] [netinet6] ipv6 prefix not renewed when managed by userspace daemon with pltime and vltime

2018-05-12 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=195197 --- Comment #8 from guy...@gmail.com --- I created phabricator D15406 as my attempt to port the NetBSD changes to 12.0-CURRENT. Fix for 194485 is needed first. My attempts for fixes to that bug are D15404 and D15405. -- You are receiving

[Bug 194485] Userland cannot add IPv6 prefix routes

2018-05-12 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=194485 guy...@gmail.com changed: What|Removed |Added CC||guy...@gmail.com --- Comment #4

[Bug 209581] igb vf driver does not correctly handle vlan tag

2018-05-12 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=209581 Dieter changed: What|Removed |Added CC||dknuep...@online.de --- Comment #7 from D