Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

[Users] freeswan 2.0, default route, policy groups

From: <setzer(at)corvina.placemark.com>
Date: Fri Feb 28 2003 - 17:12:53 EST


I just installed 2.0 (rc2) today and ran into an unexpected problem. In 2.0, opportunistic encryption is enabled by default. It's part of the new Policy Groups feature. As a result, freeswan will add an extra default route making it impossible for machines behind your freeswan gateway to get out.

To disable OE and avoid the issue with the default route, read these instructions:

http://www.freeswan.ca/docs/freeswan-Snapshot/doc/policygroups.html

To disable policy groups, cut and paste the following lines to /etc/ipsec.conf:

conn block

    auto=ignore

conn private

    auto=ignore

Do you need help?X

conn private-or-clear

    auto=ignore

conn clear-or-private

    auto=ignore

conn clear

    auto=ignore

Restart FreeS/WAN

    ipsec setup restart



Users mailing list
Users@lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users Received on Fri Feb 28 19:27:47 2003
Do you need more help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:00:26 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library