Re: Site-to-site IPSec VPN using if_ipsec and racoon

2018-05-17 Thread Andreas Scherrer
Dear Andrey Thank you for your reply. I was able to find a configuration that establishes the IPSec tunnel now! It was a bit of a trial and error and I have tried/changed several things; so I am not 100% sure what the minimum set of changes required would have been, but I think I understand that

Re: Site-to-site IPSec VPN using if_ipsec and racoon

2018-05-12 Thread Andrey V. Elsukov
On 13.05.2018 02:37, Andreas Scherrer wrote: > My interpretation of [2]'s statement: > > "If no security association is found, the packet is put on hold and the > IKE daemon is asked to negotiate an appropriate one." > > is that it should somehow be automagic. But in my current configuration, > t

Site-to-site IPSec VPN using if_ipsec and racoon

2018-05-12 Thread Andreas Scherrer
Hi I am trying to configure a site to site VPN using the (new?) if_ipsec interfaces [1]. One endpoint is FreeBSD 11.1-RELEASE whereas the other will be a RPi (Raspbian 9.4 stretch running libreswan). The public IPs involved are all IPv6 and the goal is to tunnel IPv4 traffic. Currently I am