Re: l2tp and openbsd 6.1

2017-10-06 Thread Sterling Archer
save/reload then uncomment, I can connect just fine. > > > > > -Original Message- > From: owner-m...@openbsd.org [mailto:owner-m...@openbsd.org] On Behalf Of > Charles Amstutz > Sent: Friday, October 6, 2017 10:04 AM > To: 'misc@openbsd.org' > Subje

Re: l2tp and openbsd 6.1

2017-10-06 Thread Charles Amstutz
to:owner-m...@openbsd.org] On Behalf Of Charles Amstutz Sent: Friday, October 6, 2017 10:04 AM To: 'misc@openbsd.org' Subject: Re: l2tp and openbsd 6.1 Hello Noth, "Try pppx instead of pppx0, it'll work in pf.conf, including as a macro." I did!! I found another article

Re: l2tp and openbsd 6.1

2017-10-06 Thread Charles Amstutz
Hello Noth, "Try pppx instead of pppx0, it'll work in pf.conf, including as a macro." I did!! I found another article that talked about the group. After reading this: http://frankgroeneveld.nl/2015/08/16/configuring-l2tp-over-ipsec-on-openbsd-for-mac-os-x-clients/ However, I still get this

Re: l2tp and openbsd 6.1

2017-10-05 Thread Noth
pppx0 to a variable doesn't work either. Neither does setting it to be dynamic. -Original Message- From: owner-m...@openbsd.org [mailto:owner-m...@openbsd.org] On Behalf Of Charles Amstutz Sent: Thursday, October 5, 2017 10:44 AM To: 'misc@openbsd.org' Subject: Re: l2tp a

Re: l2tp and openbsd 6.1

2017-10-05 Thread Noth
quot;self signed certificates". Again, I do not understand a thing. Sorry for the noise. Please excuse my brevity. Sent from my handphone.   Original Message From: Vijay Sankar Sent: Wednesday 4 October 2017 23:42 To: misc@openbsd.org Subject: Re: l2tp and openbsd 6.1 Quoting Charles Ams

Re: l2tp and openbsd 6.1

2017-10-05 Thread Charles Amstutz
m: owner-m...@openbsd.org [mailto:owner-m...@openbsd.org] On Behalf Of Charles Amstutz Sent: Thursday, October 5, 2017 10:44 AM To: 'misc@openbsd.org' Subject: Re: l2tp and openbsd 6.1 Here is a related but new question, If pppx0 only exists when someone is vpn'ed in. How do peopl

Re: l2tp and openbsd 6.1

2017-10-05 Thread Charles Amstutz
Here is a related but new question, If pppx0 only exists when someone is vpn'ed in. How do people handle this in pf? If you don't define rules, packets get blocked on it. But if there is no connect, pf complains about pppx0 not having a firewall. The only thing that seems to work is set ski

Re: l2tp and openbsd 6.1

2017-10-05 Thread Vijay Sankar
Quoting lilit-aibolit : On 05/10/17 09:17, lilit-aibolit wrote: Hi, I've just try your suggestion and IPhone could connect but Windows gives new errors in log: ##here is Windows attempt Oct  5 09:08:16 gw isakmpd[19354]: message_parse_payloads: invalid next payload type in payload of type

Re: l2tp and openbsd 6.1

2017-10-05 Thread lilit-aibolit
On 05/10/17 09:17, lilit-aibolit wrote: Hi, I've just try your suggestion and IPhone could connect but Windows gives new errors in log: ##here is Windows attempt Oct  5 09:08:16 gw isakmpd[19354]: message_parse_payloads: invalid next payload type in payload of type 5 Oct  5 09:08:16 gw isakm

Re: l2tp and openbsd 6.1

2017-10-04 Thread lilit-aibolit
Hi, I've just try your suggestion and IPhone could connect but Windows gives new errors in log: Oct  5 09:05:44 gw isakmpd[19354]: attribute_unacceptable: GROUP_DESCRIPTION: got MODP_1024, expected MODP_2048 Oct  5 09:05:46 gw npppd[10826]: l2tpd ctrl=6 logtype=Started RecvSCCRQ from=37.73.214.

Re: l2tp and openbsd 6.1

2017-10-04 Thread Vivek Vinod
iour. It may or may not be related to "self signed certificates". Again, I do not understand a thing. Sorry for the noise. Please excuse my brevity. Sent from my handphone.   Original Message   From: Vijay Sankar Sent: Wednesday 4 October 2017 23:42 To: misc@openbsd.org Subject:

Re: l2tp and openbsd 6.1

2017-10-04 Thread Vijay Sankar
al Message- From: owner-m...@openbsd.org [mailto:owner-m...@openbsd.org] On Behalf Of lilit-aibolit Sent: Wednesday, October 4, 2017 2:46 AM To: misc@openbsd.org Cc: Charles Amstutz ; yasu...@yasuoka.net Subject: Re: l2tp and openbsd 6.1 Hi, with l2tp I have situation when iOS  and Android dev

Re: l2tp and openbsd 6.1

2017-10-04 Thread Charles Amstutz
penbsd.org [mailto:owner-m...@openbsd.org] On Behalf Of lilit-aibolit Sent: Wednesday, October 4, 2017 2:46 AM To: misc@openbsd.org Cc: Charles Amstutz ; yasu...@yasuoka.net Subject: Re: l2tp and openbsd 6.1 Hi, with l2tp I have situation when iOS  and Android devices could connect but Windows 7 and

Re: l2tp and openbsd 6.1

2017-10-04 Thread lilit-aibolit
Hi, with l2tp I have situation when iOS  and Android devices could connect but Windows 7 and Windows 10 couldn't. Is it possible to adjust ipsec.conf somehow so it could accept connection from Windows clients too? Or is there a way to adjust some settings in Windows so it will work with current i

Re: l2tp and openbsd 6.1

2017-10-03 Thread Noth
ssages is just from npppd. Unless I'm reading it wrong, there doesn't appear to be any errors. -Original Message- From: Sterling Archer [mailto:deb...@gmail.com] Sent: Monday, October 2, 2017 5:35 PM To: Charles Amstutz Cc: misc@openbsd.org Subject: Re: l2tp and openbsd 6.1 On M

Re: l2tp and openbsd 6.1

2017-10-02 Thread Vijay Sankar
Quoting Stuart Henderson : On 2017-10-02, Charles Amstutz wrote: Hello Sterling, Thanks for the response. I changed it to ike passive esp transport \ proto udp from $public_ip to any port 1701 \ main auth "hmac-sha1" enc "aes-256" group modp1024\ quick auth "hmac-sha1" enc "aes-256

Re: l2tp and openbsd 6.1

2017-10-02 Thread Stuart Henderson
On 2017-10-02, Charles Amstutz wrote: > Hello Sterling, > > Thanks for the response. I changed it to > > ike passive esp transport \ >proto udp from $public_ip to any port 1701 \ >main auth "hmac-sha1" enc "aes-256" group modp1024\ >quick auth "hmac-sha1" enc "aes-256" \ >PSK "PSK

Re: l2tp and openbsd 6.1

2017-10-02 Thread Charles Amstutz
Original Message- From: Sterling Archer [mailto:deb...@gmail.com] Sent: Monday, October 2, 2017 5:35 PM To: Charles Amstutz Cc: misc@openbsd.org Subject: Re: l2tp and openbsd 6.1 On Mon, Oct 2, 2017 at 10:03 PM, Charles Amstutz wrote: > Hello everyone, > > I'm new to this

Re: l2tp and openbsd 6.1

2017-10-02 Thread Sterling Archer
On Mon, Oct 2, 2017 at 10:03 PM, Charles Amstutz wrote: > Hello everyone, > > I'm new to this list and l2tp/openbsd (but do have working UNIX/Linux > knowledge). After searching the previous forum posts (and the internet) I > have found a lot of information on l2tp ipsec.conf connection strings

l2tp and openbsd 6.1

2017-10-02 Thread Charles Amstutz
Hello everyone, I'm new to this list and l2tp/openbsd (but do have working UNIX/Linux knowledge). After searching the previous forum posts (and the internet) I have found a lot of information on l2tp ipsec.conf connection strings. However, I can't get android to connect. I keep getting IKE neg