Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

[Users] Newbie question: NATed & Preshared keys (& XP ???)

From: Paolo <iw6dak(at)bib.uniurb.it>
Date: Fri Oct 10 2003 - 06:47:45 EDT

Hello all, I'm new to the list and to FreeSwan too...

Well, I recently set up FreeSwan and it was mainly OK but there is an apparently easy question I was not able to answer myself, after a lot of documentation browsing as well.

The question is ... can a NATed client connect to a Free/Swan gateway using PSK ??? This is because with Linux it's easy to setup "authby=rsasig" and go on but will be nice to offer also XP connection and I'd avoid to fight with certificates if possible.

Here some details. Linux hosts are RedHat 8 with kernel 2.4.20-20.8.1.99.8.2foo, idest Super Frees/WAN 1.99.8, XP are XP Home :-)

The NATting device is at now a Linux box but I'm going to test at home with a Netgear DM602 ADSL router ...

This configuration DO WORK vith NAT.

# Gateway configuration ===========================
config setup

        interfaces=%defaultroute
        klipsdebug=none
        plutodebug=none
        plutoload=%search
        plutostart=%search
conn %default
        keyingtries=0
        disablearrivalcheck=no
conn road
        right=193.205.x.y
        rightid=@blabla.bib.uniurb.it
        rightsubnet=10.1.1.0/24
        rightnexthop=193.205.x.z
        left=193.205.a.b
        leftsubnet=192.168.200.2/32   #or leftsubnetwithin ...
        leftid=@portatile.at1839.it
        leftnexthop=193.205.a.a
        authby=rsasig
        rightrsasigkey=0sAQOAZnYM2.....
        leftrsasigkey=gjyrf ....
        auto=add
        pfs=yes

# Linux Client configuration ===========================
conn road right=193.205.x.y rightid=@blabla.bib.uniurb.it rightsubnet=10.1.1.0/24 rightnexthop=193.205.x.z left=%defaultroute leftid=@portatile.at1839.it leftnexthop= authby=rsasig rightrsasigkey=0sAQOAZnYM2..... leftrsasigkey=gjyrf .... auto=add pfs=yes
Do you need help?X

If I switch to authby=secret and get rid of left and right rsasigkey the connection stuck on STATE_MAIN_I1: initiate ... :-(

The ipsec.secrets file contains

@blabla.bib.uniurb.it @portatile.at1839.it: PSK "sdfghjk ... lkjhg"

Well, I will send the barfs and so on IF the PSK way can be ... of course I suppose it's better to solve the problem with Linux before to try with XP :-)

Thanks for any help and forget my spaghetti English.

Paolo Cecchini.



FreeS/WAN Users mailing list
users@lists.freeswan.org
https://mj2.freeswan.org/cgi-bin/mj_wwwusr Received on Fri Oct 10 06:58:09 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:02:04 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library