Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: Behaviour of IPsec when there are two flow-pairs between same gateways?

From: Markus Friedl <markus(at)openbsd.org>
Date: Fri Jan 24 2003 - 04:37:19 EST

i don't see this problem with openbsd 3.2.

however, i'm setting up the flows/SPD with ipsecadm.

e.g.

ipsecadm flow -addr 11.0.0.0/8 192.168.40.0/24 -src 10.0.0.1 -dst 192.168.0.1 -proto esp -out -require
ipsecadm flow -addr 192.168.40.0/24 11.0.0.0/8 -src 10.0.0.1 -dst 192.168.0.1 -proto esp -in -require
ipsecadm flow -addr 12.0.0.0/8 192.168.40.0/24 -src 10.0.0.1 -dst 192.168.0.1 -proto esp -out -require
ipsecadm flow -addr 192.168.40.0/24 12.0.0.0/8 -src 10.0.0.1 -dst 192.168.0.1 -proto esp -in -require

isakmpd is just used for negotiation the SAs.

all you need for authentication is

/etc/isakmpd/private/local.key
/etc/isakmpd/pubkeys/ipv4/192.168.0.1

-markus Received on Fri Jan 24 04:39:17 2003

Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:48:29 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library