FreeBSD 7.2 racoon and NAT-T

2009-07-16 Thread Gergely CZUCZY
Hello, I'd like to ask for the state of that NAT-T support in 7.2. I've seen a note in ipsec-tools's OPTIONS for a required kernel patch for 6.x in order to have NAT-T working. Is this also required for 7.2? If a kernel patch is needed, is a recent patch available for 7.2? Does racoon needs to be

Re: FreeBSD 7.2 racoon and NAT-T

2009-07-16 Thread VANHULLEBUS Yvan
On Thu, Jul 16, 2009 at 02:32:48PM +0200, Gergely CZUCZY wrote: > Hello, Hi. > I'd like to ask for the state of that NAT-T support in 7.2. I've seen a > note in ipsec-tools's OPTIONS for a required kernel patch for 6.x in > order to have NAT-T working. Is this also required for 7.2? > If a kerne

Re: FreeBSD 7.2 racoon and NAT-T

2009-07-16 Thread Gergely CZUCZY
On Thu, 16 Jul 2009 14:38:36 +0200 VANHULLEBUS Yvan wrote: > On Thu, Jul 16, 2009 at 02:32:48PM +0200, Gergely CZUCZY wrote: > > Hello, > > Hi. > > > > I'd like to ask for the state of that NAT-T support in 7.2. I've > > seen a note in ipsec-tools's OPTIONS for a required kernel patch > > for

Re: FreeBSD 7.2 racoon and NAT-T

2009-07-16 Thread VANHULLEBUS Yvan
On Thu, Jul 16, 2009 at 02:57:59PM +0200, Gergely CZUCZY wrote: [...] > Thank you very much. > > Would it be possible that this could be integrated? > Might be with racoon, that would also be very nice. So far this is the > only thing I've found in FreeBSD that needs a feature in the base > instal

Re: FreeBSD 7.2 racoon and NAT-T

2009-07-16 Thread Julian Elischer
Gergely CZUCZY wrote: On Thu, 16 Jul 2009 14:38:36 +0200 VANHULLEBUS Yvan wrote: On Thu, Jul 16, 2009 at 02:32:48PM +0200, Gergely CZUCZY wrote: Hello, Hi. I'd like to ask for the state of that NAT-T support in 7.2. I've seen a note in ipsec-tools's OPTIONS for a required kernel patch for

GRE tunnel limitations

2009-07-16 Thread Jacobs, Brian
Does anyone have some realistic data on the number of GRE/ipip tunnels FreeBSD 7.x can reasonably terminate? Assume no IPsec, just standard encapsulation. I have an ad-hoc need to terminate about 1,4000 static GRE tunnels (as Cisco 7206's are backordered until September). J Thanks in advance

Re: GRE tunnel limitations

2009-07-16 Thread Julian Elischer
Jacobs, Brian wrote: Does anyone have some realistic data on the number of GRE/ipip tunnels FreeBSD 7.x can reasonably terminate? Assume no IPsec, just standard encapsulation. I have an ad-hoc need to terminate about 1,4000 static GRE tunnels (as Cisco 7206's are backordered until September).

RE: GRE tunnel limitations

2009-07-16 Thread Jacobs, Brian
IP unnumbered between the two boxen. I've built some scripts to automatically generate config files, and then other scripts to automagically create the GRE interfaces and inject appropriate routes. GRE numbers are assigned sequentially based on config file lines (and are of no consequence): gre4

Re: kern/136836: [ath] atheros card stops functioning after about 12 hours uptime

2009-07-16 Thread linimon
Old Synopsis: atheros card stops functioning after about 12 hours uptime New Synopsis: [ath] atheros card stops functioning after about 12 hours uptime Responsible-Changed-From-To: freebsd-bugs->freebsd-net Responsible-Changed-By: linimon Responsible-Changed-When: Fri Jul 17 04:09:22 UTC 2009 Resp

Re: kern/136803: [sctp] [panic] Kernel panic and hanging on using SCTP

2009-07-16 Thread linimon
Old Synopsis: Kernel panic and hanging on using SCTP New Synopsis: [sctp] [panic] Kernel panic and hanging on using SCTP Responsible-Changed-From-To: freebsd-bugs->freebsd-net Responsible-Changed-By: linimon Responsible-Changed-When: Fri Jul 17 04:15:38 UTC 2009 Responsible-Changed-Why: Over to m

Re: question regarding IPSEC Setup

2009-07-16 Thread David DeSimone
rascal wrote: > > If I could ask one more favor; what does your cisco config look like > that would match one of these? I have got mine configed based on > someone else's tunnel specs and while I am sure they are comparable I > wanted to make sure I wasn't missing anything. Here's an example con