|
|||||||||||
|
[Users] Newbie question: NATed & Preshared keys (& XP ???)
From: Paolo <iw6dak(at)bib.uniurb.it>
Date: Fri Oct 10 2003 - 06:47:45 EDT Hello all, I'm new to the list and to FreeSwan too... Well, I recently set up FreeSwan and it was mainly OK but there is an apparently easy question I was not able to answer myself, after a lot of documentation browsing as well. The question is ... can a NATed client connect to a Free/Swan gateway using PSK ??? This is because with Linux it's easy to setup "authby=rsasig" and go on but will be nice to offer also XP connection and I'd avoid to fight with certificates if possible. Here some details. Linux hosts are RedHat 8 with kernel 2.4.20-20.8.1.99.8.2foo, idest Super Frees/WAN 1.99.8, XP are XP Home :-) The NATting device is at now a Linux box but I'm going to test at home with a Netgear DM602 ADSL router ... This configuration DO WORK vith NAT.
# Gateway configuration ===========================
interfaces=%defaultroute
klipsdebug=none
plutodebug=none
plutoload=%search
plutostart=%search
conn %default
keyingtries=0
disablearrivalcheck=no
conn road
right=193.205.x.y
rightid=@blabla.bib.uniurb.it
rightsubnet=10.1.1.0/24
rightnexthop=193.205.x.z
left=193.205.a.b
leftsubnet=192.168.200.2/32 #or leftsubnetwithin ...
leftid=@portatile.at1839.it
leftnexthop=193.205.a.a
authby=rsasig
rightrsasigkey=0sAQOAZnYM2.....
leftrsasigkey=gjyrf ....
auto=add
pfs=yes
If I switch to authby=secret and get rid of left and right rsasigkey the connection stuck on STATE_MAIN_I1: initiate ... :-( The ipsec.secrets file contains @blabla.bib.uniurb.it @portatile.at1839.it: PSK "sdfghjk ... lkjhg" Well, I will send the barfs and so on IF the PSK way can be ... of course I suppose it's better to solve the problem with Linux before to try with XP :-) Thanks for any help and forget my spaghetti English. Paolo Cecchini. FreeS/WAN Users mailing list users@lists.freeswan.org https://mj2.freeswan.org/cgi-bin/mj_wwwusr Received on Fri Oct 10 06:58:09 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:02:04 EDT |
||||||||||
|
|||||||||||