Re: IPsec: odd behaviour with policies

2004-03-11 Thread Nick Slager
Thus spake Helge Oldach ([EMAIL PROTECTED]): > Nick Slager: > >I have a newly created VPN between a 4.8 box and a Cisco VPN 3000 > >Concentrator. > > [ ... ] > Try using "unique" instead of "require". > > (This is my standard answer on the subject. :-)) Thanks, it works great. After re-readin

Re: IPsec: odd behaviour with policies

2004-03-11 Thread Helge Oldach
Nick Slager: >I have a newly created VPN between a 4.8 box and a Cisco VPN 3000 >Concentrator. > >/etc/ipsec.conf: > >flush; >spdflush; >spdadd 192.168.1.1/32 1.2.3.4/32 any -P out ipsec >esp/tunnel/203.1.1.1-203.2.2.2/require; >spdadd 1.2.3.4/32 192.168.1.1/32 any -P in ipsec >esp/tunnel/203.2.2.2

IPsec: odd behaviour with policies

2004-03-09 Thread Nick Slager
This is perhaps the wrong forum for this question, however, posting on -questions has drawn a blank. I have a newly created VPN between a 4.8 box and a Cisco VPN 3000 Concentrator. The concentrator is not under my control, being owned by an associated company. The policies are extremely restrict