Re: IPSEC + Via Padlock + racoon + Windows

2007-12-03 Thread Michael Proto
Dewayne Geraghty wrote: > My apologies for the confusion, yes, the C7 only helps with AES. > > The configuration detail is: between branch offices I use FreeBSD ipsec > (AES), and within the branches Windows boxes access the firewall boxes. The > "firewalls" run samba inside a jail. Due to sens

RE: IPSEC + Via Padlock + racoon + Windows

2007-12-03 Thread Dewayne Geraghty
My apologies for the confusion, yes, the C7 only helps with AES. The configuration detail is: between branch offices I use FreeBSD ipsec (AES), and within the branches Windows boxes access the firewall boxes. The "firewalls" run samba inside a jail. Due to sensitive information (see your local

Re: IPSEC + Via Padlock + racoon + Windows

2007-12-03 Thread Vivek Khera
On Dec 3, 2007, at 9:39 AM, Michael Proto wrote: Not that this solves your problem, but doesn't the padlock crypto engine only provide acceleration for AES symmetric encryption? From the man page: The boot messages on my C7 based system shows this: PadLock: HW support loaded for AES-CBC,S

Re: IPSEC + Via Padlock + racoon + Windows

2007-12-03 Thread Michael Proto
Dewayne Geraghty wrote: > We're looking to deploy FreeBSD on our main firewall. The firewall config > is a VIA C7 (padlock), racoon(ipsec-tools-0.7), IPSec. We're testing racoon > with a windows box, however the firewall doesn't function correctly when > net.inet.ipsec.crypto_support=1 is set. W