configure ipsec to accept roaming users?

2002-11-07 Thread Vincent Chen
Hi, all I already done some test on ipsec transport and tunnel test successfully. Now, I try to figure out how to deal with roaming users. Here is the situation: internal <---> freebsd <---> roaming user freebsd's external NIC has a public, to accept incoming ipsec from roaming user. freebsd's

racoon questions?

2002-11-07 Thread Vincent Chen
Hi, all I have a ipsec tunnel with 2 freebsd in each end. It just came to me recently, how safe if racoon accept anonymous connection? Is it possible that somebody just create a fake certificate and feed it to racoon, then got access? BTW: I didn't check peer's identifier at this time. Will it be

IPSec tunnel status?

2002-04-29 Thread Vincent Chen
Dear all, I have a freebsd act as VPN gateway which support PPTP and IPSec. I am trying to monitor those incoming connections. For PPTP, I can use snmp to get ngx status and statics. Is there any to monitor IPsec tunnel like those PPTP connection? Thanks, Vincent Chen

why prefer old SA in KAME's IPSec?

2002-04-20 Thread Vincent Chen
net.key.prefered_oldsa=0 will solve that problem. But why prefer old one? Thanks, Vincent Chen __ Do You Yahoo!? Yahoo! Games - play chess, backgammon, pool and more http://games.yahoo.com/ To Unsubscribe: send mail to [EMAIL PROTECTED] with

IPSec for roaming user?

2002-03-20 Thread Vincent Chen
CA didn't appear in the list. Is there any special requirement to generate certificate for IPsec? Thanks for your help, Vincent Chen __ Do You Yahoo!? Yahoo! Sports - live college hoops coverage http://sports.yahoo.com/ To Unsubscribe: send

pptp problem?

2002-03-11 Thread Vincent Chen
Dear all, I am trying to establish PPTP link between a windows 2000 pro and freebsd 4.5 running mpd 3.6. I must disable encryption or link will failed. Please help! here is the log: [pptp] up: 1 link, total bandwidth 64000 bps [pptp] IPCP: Up event [pptp] IPCP: state change Starting --> Req-Se