Re: IPSEC + Via Padlock + racoon + Windows

2007-12-03 Thread Michael Proto
Dewayne Geraghty wrote: > My apologies for the confusion, yes, the C7 only helps with AES. > > The configuration detail is: between branch offices I use FreeBSD ipsec > (AES), and within the branches Windows boxes access the firewall boxes. The > "firewalls" run samba inside a jail. Due to sens

RE: IPSEC + Via Padlock + racoon + Windows

2007-12-03 Thread Dewayne Geraghty
My apologies for the confusion, yes, the C7 only helps with AES. The configuration detail is: between branch offices I use FreeBSD ipsec (AES), and within the branches Windows boxes access the firewall boxes. The "firewalls" run samba inside a jail. Due to sensitive information (see your local

Re: IPSEC + Via Padlock + racoon + Windows

2007-12-03 Thread Vivek Khera
On Dec 3, 2007, at 9:39 AM, Michael Proto wrote: Not that this solves your problem, but doesn't the padlock crypto engine only provide acceleration for AES symmetric encryption? From the man page: The boot messages on my C7 based system shows this: PadLock: HW support loaded for AES-CBC,S

Re: IPSEC + Via Padlock + racoon + Windows

2007-12-03 Thread Michael Proto
Dewayne Geraghty wrote: > We're looking to deploy FreeBSD on our main firewall. The firewall config > is a VIA C7 (padlock), racoon(ipsec-tools-0.7), IPSec. We're testing racoon > with a windows box, however the firewall doesn't function correctly when > net.inet.ipsec.crypto_support=1 is set. W

IPSEC + Via Padlock + racoon + Windows

2007-12-02 Thread Dewayne Geraghty
We're looking to deploy FreeBSD on our main firewall. The firewall config is a VIA C7 (padlock), racoon(ipsec-tools-0.7), IPSec. We're testing racoon with a windows box, however the firewall doesn't function correctly when net.inet.ipsec.crypto_support=1 is set. With a net.inet.ipsec.crypto_supp

Re: Via padlock

2007-09-12 Thread Daniel O'Connor
On Wed, 12 Sep 2007, Oliver Fromme wrote: > padlock_load="YES" > > So there's no need to modify your kernel. I just realised that I checked and amd64 6.2 machine and an i386 -current machine, hence my confusion :) -- Daniel O'Connor software and network engineer for Genesis Software - http://ww

Re: Via padlock

2007-09-12 Thread Oliver Fromme
Daniel O'Connor wrote: > On Wed, 12 Sep 2007, Minseok Choi wrote: > > I found out from googling that VIA Padlock would be supported in > > FreeBSD 6.2. > > > > But I don't know how to activate it. > > Is there any kernel configuration or specific

Re: Via padlock

2007-09-12 Thread Daniel O'Connor
On Wed, 12 Sep 2007, Minseok Choi wrote: > I found out from googling that VIA Padlock would be supported in > FreeBSD 6.2. > > But I don't know how to activate it. > Is there any kernel configuration or specific application for the > Padlock? > > If you have any idea

Via padlock

2007-09-12 Thread Minseok Choi
I found out from googling that VIA Padlock would be supported in FreeBSD 6.2. But I don't know how to activate it. Is there any kernel configuration or specific application for the Padlock? If you have any idea about this issue, let me know. Currently I am using VIA Epia SP13000, whic