Re: IPSec and Racoon between 5.4 and 4.11

2005-05-18 Thread Daren Russell
Daren Russell wrote: > Hi, > > We have a VPN between two FBSD machines using IPSEC and Racoon. I > managed to put this together a couple of years back with (getting) old > hardware, although I am certainly no expert. One of the machines is > about to be replaced as it is occasionally conking out

Re: IPSec and Racoon between 5.4 and 4.11

2005-05-17 Thread Daren Russell
Mike Tancsa wrote: > On Tue, 17 May 2005 09:33:40 +0100, in sentex.lists.freebsd.questions > you wrote: > >>A basic tunnel (without any encryption) works fine. As soon as >>ipsec_enable is set in rc.conf, it fails. >> >>setkey -D shows No SAD entries. > > >>If I start a ping from 192.168.1.254

Re: IPSec and Racoon between 5.4 and 4.11

2005-05-17 Thread Mike Tancsa
On Tue, 17 May 2005 09:33:40 +0100, in sentex.lists.freebsd.questions you wrote: >A basic tunnel (without any encryption) works fine. As soon as >ipsec_enable is set in rc.conf, it fails. > >setkey -D shows No SAD entries. > >If I start a ping from 192.168.1.254 -> 192.168.0.254, the receiving >m

Re: IPSec and Racoon between 5.4 and 4.11

2005-05-17 Thread Daren Russell
Mike Tancsa wrote: > On Mon, 16 May 2005 12:51:50 +0100, in sentex.lists.freebsd.questions > you wrote: > > >>Hi, >> >>Has anybody got 5.4 <-> 4.11 talking in this config, or does anybody >>know of any pitfalls because of kernel changes? > > > There should not be any issues as I have 90+ RELENG

Re: IPSec and Racoon between 5.4 and 4.11

2005-05-16 Thread Mike Tancsa
On Mon, 16 May 2005 12:51:50 +0100, in sentex.lists.freebsd.questions you wrote: >Hi, > >Has anybody got 5.4 <-> 4.11 talking in this config, or does anybody >know of any pitfalls because of kernel changes? There should not be any issues as I have 90+ RELENG4 boxes deployed talking to a 5.4 serve

IPSec and Racoon between 5.4 and 4.11

2005-05-16 Thread Daren Russell
Hi, We have a VPN between two FBSD machines using IPSEC and Racoon. I managed to put this together a couple of years back with (getting) old hardware, although I am certainly no expert. One of the machines is about to be replaced as it is occasionally conking out, and I though I would try the 5.