Re: [gentoo-user] Networkmanager VPNC key timeout

2015-03-03 Thread Petric Frank
software like strongswan (it has a networkmanager plugin) or even ipsec-tools instead of vpnc, to see if you're getting the same problem? I think that they should work with Cisco VPN gateways, although it may be fiddly to set them up. i can find only ebuilds of (networkmanager-)openswan

Re: [gentoo-user] (Free|Open|Strong)Swan and Gentoo as a client

2016-02-19 Thread Mick
On Friday 19 Feb 2016 15:36:20 Mick wrote: > On Friday 19 Feb 2016 14:51:40 Daniel Quinn wrote: > > Hello all, I’ve been asked to connect my Gentoo box to a StrongSwan VPN > > and was offered a .mobileconfig file as means to connect. Unfortunately, > > this appears to be

Re: [gentoo-user] (Free|Open|Strong)Swan and Gentoo as a client

2016-02-19 Thread Mick
On Friday 19 Feb 2016 16:23:22 Daniel Quinn wrote: > The problem is that the names of the fields on iThings are different > from the fields I see in NetworkManager, so I don’t know what correlates > to what. > > I have just uninstalled libreswan and installed strongswan, but

Re: [gentoo-user] (Free|Open|Strong)Swan and Gentoo as a client

2016-02-19 Thread Mick
On Friday 19 Feb 2016 14:51:40 Daniel Quinn wrote: > Hello all, I’ve been asked to connect my Gentoo box to a StrongSwan VPN > and was offered a .mobileconfig file as means to connect. Unfortunately, > this appears to be a special-Apple-only-format and I can’t make heads or > tails of

Re: [gentoo-user] (Free|Open|Strong)Swan and Gentoo as a client

2016-02-19 Thread Daniel Quinn
The problem is that the names of the fields on iThings are different from the fields I see in NetworkManager, so I don’t know what correlates to what. I have just uninstalled libreswan and installed strongswan, but I can’t find evidence of a networkmanager plugin for strongswan in Portage. |eix

Re: [gentoo-user] GRE link state detection

2013-09-09 Thread Mick
another. DPD timeouts are 30seconds minimum, which is too long. i'll keep you posted if the bird recommendations works better You can tune dpd_delay and dpd_retry in racoon.conf (if you are using ipsec- tools) or the equivalent in open/strongswan. I think strongswan sends keepalives every 20

Re: [gentoo-user] Networkmanager VPNC key timeout

2015-03-03 Thread Mick
? maybe. BTW, have you tried more actively developed VPN software like strongswan (it has a networkmanager plugin) or even ipsec-tools instead of vpnc, to see if you're getting the same problem? I think that they should work with Cisco VPN gateways, although it may be fiddly

Re: [gentoo-user] Traffic Intensive IPSec Tunnel

2013-05-12 Thread Adam Carter
You can read a comparison between the *Swans here, but things have moved on since; e.g. StrongSwan supports IKEv1 in Aggressive Mode, Aggressive mode with pre-shared keys is vulnerable to offline dictionary attack so you might as well use main mode. If for some reason you have to use

[gentoo-user] IPsec

2021-04-04 Thread Grant Taylor
Hi, Does anyone have any experience with IPsec? Preferably on Gentoo or Linux in general? I'd like to discuss some things (probably off list) while wading into the IPsec pool. E.g.: - ip xfrm ... - strongSwan - Libraswan - X.509 certificate based authentication, preferably /mutual

[gentoo-user] (Free|Open|Strong)Swan and Gentoo as a client

2016-02-19 Thread Daniel Quinn
Hello all, I’ve been asked to connect my Gentoo box to a StrongSwan VPN and was offered a .mobileconfig file as means to connect. Unfortunately, this appears to be a special-Apple-only-format and I can’t make heads or tails of the contents. I understand that the server is Ubuntu running StrongSwan

[gentoo-user] Which IPSEC to go?

2010-01-24 Thread Konstantinos Agouros
Hi, since I am a while out of the game of doing ipsec with Linux: What's the way to go? Strongswan/Openswan or ipsec-tools for kame/racoon. Emerge -p gave me some ~ for ipsec-tools while openswan goes without. Any input welcome. I need this for a road warrior setup. Regards, Konstantin

Re: [gentoo-user] Networkmanager VPNC key timeout

2015-03-02 Thread Mick
actively developed VPN software like strongswan (it has a networkmanager plugin) or even ipsec-tools instead of vpnc, to see if you're getting the same problem? I think that they should work with Cisco VPN gateways, although it may be fiddly to set them up. i can find only ebuilds

Re: [gentoo-user] Which IPSEC to go?

2010-01-26 Thread Eray Aslan
On 24.01.2010 23:38, Konstantinos Agouros wrote: since I am a while out of the game of doing ipsec with Linux: What's the way to go? Strongswan/Openswan or ipsec-tools for kame/racoon. Emerge -p gave me some ~ for ipsec-tools while openswan goes without. Any input welcome. I need

Re: [gentoo-user] Which IPSEC to go?

2010-01-27 Thread kashani
On 1/24/2010 1:38 PM, Konstantinos Agouros wrote: Hi, since I am a while out of the game of doing ipsec with Linux: What's the way to go? Strongswan/Openswan or ipsec-tools for kame/racoon. Emerge -p gave me some ~ for ipsec-tools while openswan goes without. Any input welcome. I need

Re: [gentoo-user] Which IPSEC to go?

2010-01-27 Thread Amit Dor-Shifer
kashani wrote: On 1/24/2010 1:38 PM, Konstantinos Agouros wrote: Hi, since I am a while out of the game of doing ipsec with Linux: What's the way to go? Strongswan/Openswan or ipsec-tools for kame/racoon. Emerge -p gave me some ~ for ipsec-tools while openswan goes without. Any input

Re: [gentoo-user] IPsec

2021-04-06 Thread J. Roeleveld
On Monday, April 5, 2021 3:46:37 AM CEST Grant Taylor wrote: > Hi, > > Does anyone have any experience with IPsec? Preferably on Gentoo or > Linux in general? > > I'd like to discuss some things (probably off list) while wading into > the IPsec pool. E.g.: > > - i

Re: [gentoo-user] Which IPSEC to go?

2010-01-28 Thread Konstantinos Agouros
In 4b612f2e.1070...@badapple.net kashani-l...@badapple.net (kashani) writes: On 1/24/2010 1:38 PM, Konstantinos Agouros wrote: Hi, since I am a while out of the game of doing ipsec with Linux: What's the way to go? Strongswan/Openswan or ipsec-tools for kame/racoon. Emerge -p gave me some

Re: [gentoo-user] Traffic Intensive IPSec Tunnel

2013-05-12 Thread Mick
On Monday 13 May 2013 03:13:27 Adam Carter wrote: You can read a comparison between the *Swans here, but things have moved on since; e.g. StrongSwan supports IKEv1 in Aggressive Mode, Aggressive mode with pre-shared keys is vulnerable to offline dictionary attack so you might as well use

Re: [gentoo-user] problem with l2tp-isec

2013-12-19 Thread Mick
' to get some useful information until you get it going. However, if you are using Windows =7 then it may be better to install and run StrongSwan with IKEv2 on Linux, which MSWindows can now support natively and do away with L2TP all together. Openswan also supports IKEv2. -- Regards, Mick

Re: [gentoo-user] Traffic Intensive IPSec Tunnel

2013-05-12 Thread Mick
with ifconfig and ip. Apparently they work if you use xauth, according to this thread: http://forums.gentoo.org/viewtopic-p-6977674.html Instead, I opted for using StrongSwan, which is *much* better documented, supports additional ciphers, RADIUS, etc. and allocation of IKEv1 pools using

Re: [gentoo-user] Heartbleed fix - question re: replacing self-signed certs with real ones

2014-04-19 Thread Mick
certificates with strongswan, so I think I will be limited to: prime256v1 secp384r1 secp521r1 http://wiki.strongswan.org/projects/strongswan/wiki/EcDsaSecret -- Regards, Mick signature.asc Description: This is a digitally signed message part.

Re: [gentoo-user] Which IPSEC to go?

2010-01-24 Thread Mick
On Sunday 24 January 2010 21:38:23 Konstantinos Agouros wrote: Hi, since I am a while out of the game of doing ipsec with Linux: What's the way to go? Strongswan/Openswan or ipsec-tools for kame/racoon. Openswan is simpler to configure, although I have not tried it yet. I have however

Re: [gentoo-user] VPN connection from gentoo to OSX server?

2013-06-17 Thread Mick
L2TP. Has anyone else done this successfully? Thanks for any clues. I haven't used L2TP to comment on specifics, but have you emerged and set up xl2tp which I understand will set up the L2TP tunnel? L2TP will be encapsulated within IPSec, which you should set up using racoon, strongswan

Re: [gentoo-user] /etc/passwd entry query

2013-10-21 Thread Mick
-lite:/var/run/pcscd:/sbin/nologin ipsec:x:110:998:added by portage for strongswan:/dev/null:/sbin/nologin polkitd:x:111:997:added by portage for polkit:/var/lib/polkit-1:/sbin/nologin -- Regards, Mick signature.asc Description: This is a digitally signed message part.

Re: [gentoo-user] problem with l2tp-isec

2013-12-19 Thread covici
to install and run StrongSwan with IKEv2 on Linux, which MSWindows can now support natively and do away with L2TP all together. Openswan also supports IKEv2. -- Regards, Mick -- Your life is like a penny. You're going to lose it. The question is: How do you spend it? John Covici

Re: [gentoo-user] Enable "regular" network traffic when using VPN

2018-06-19 Thread Mick
Gentoo (without dnsmasq) I have found the remote peer's nameservers are written in resolv.conf by the VPN client Up script, but only for full tunnels. I've noticed with strongswan when setting up split tunnels it errors out as it tries to set a nameserver for the tunnel side and ends up wit

Re: [gentoo-user] [OT] What is the best open-source VPN server for Linux?

2018-04-06 Thread Grant Taylor
configuring IPSec policies via a GPEdit snapin. It was extremly low level and obtuse to configure. OpenSWAN was forked into LibreSWAN and FreeSWAN is now called StrongSWAN. Anyway, part of the IKEv2 standard is to offer support for mobile and multihomed users (MOBIKE). Hum. I've not payed

Re: [gentoo-user] [OT] What is the best open-source VPN server for Linux?

2018-04-06 Thread Mick
AN was forked into LibreSWAN and FreeSWAN is now called StrongSWAN. Anyway, part of the IKEv2 standard is to offer support for mobile and multihomed users (MOBIKE). Although IKE operates in userspace, the IPSec stack is in kernelspace and its performance superior to userspace VPN technologies. A

Re: [gentoo-user] openvpn rc script dependencies

2018-04-10 Thread Mick
> > init scripts themselves. > > Unfortunately I can't test this anymore, but looking at the > documentation this _should_ work. > > Thanks! > > -- > Regards, > Christoph I recall noticing a somewhat similar behaviour with the ipsec service of strongswan. In pa

Re: [gentoo-user] Networkmanager VPNC key timeout

2015-03-02 Thread Petric Frank
for 0.5.2: Fix Phase 2 rekeying, by various authors I don't know whether this is along your statement above. So it seems not to be completely fixed. The homepage is not updated the last 7 years. BTW, have you tried more actively developed VPN software like strongswan (it has a networkmanager

Re: [gentoo-user] Re: replacement for ftp?

2017-05-15 Thread Mick
implementations of IKE/IPSec VPNs. For the latter I recommend StrongSwan which has extensive documentation and example configurations. Saying all this, I would still stick with ftps/filezilla and get the users trained. When things don't work troubleshooting ought to be simpler. ;-) -- Regards

Re: [gentoo-user] Proxy server problem

2013-08-24 Thread Mick
consider using a different tunnel method. A network layer VPN, like IPSec (you can use StrongSwan which also offers IKEv2 and MOBIKE for your laptop, or ipsec-tools with racoon for IKEv1 only) should work without such problems. You will be tunnelling tcp in udp packets. If you tunnel to your

Re: [gentoo-user] Proxy server problem

2013-08-25 Thread Grant
consider using a different tunnel method. A network layer VPN, like IPSec (you can use StrongSwan which also offers IKEv2 and MOBIKE for your laptop, or ipsec-tools with racoon for IKEv1 only) should work without such problems. You will be tunnelling tcp in udp packets. If you tunnel to your

Re: [gentoo-user] Networkmanager VPNC key timeout

2015-03-02 Thread Mick
, but I don't know if this includes any necessary patches. You could check the changelog. BTW, have you tried more actively developed VPN software like strongswan (it has a networkmanager plugin) or even ipsec-tools instead of vpnc, to see if you're getting the same problem? I think

Re: [gentoo-user] IPsec

2021-04-06 Thread Grant Taylor
$ADST proto esp reqid $AID mode transport # d in policy -->8-- This is working and does enable IPsec /transport/ /mode/ between $LeftHost and $RightHost. But it's completely manual at the moment. I'm curious if you have any comments on "ip xfrm". - strongSwan / Libraswan /

Re: [gentoo-user] Enable "regular" network traffic when using VPN

2018-06-18 Thread Mick
VPN IP allocated by the remote VPN gateway, e.g. $SOME_COMPANY_IP_1, via the VPN tunnel (tun0) to the remote company's LAN. 2. Route for all other connections, outside the VPN tunnel: A second route is typically the default route of the PC for all other connections and it is used to route datagr

Re: [gentoo-user] Enable "regular" network traffic when using VPN

2018-06-18 Thread Grant Taylor
lco is wanting to do. Some VPN clients add a new routing policy rule table (e.g. strongswan), but others (e.g. racoon) add routes for the VPN tunnel in the main routing policy rule table. I was not aware that any VPNs used alternate routing tables and rules to use them. But that does m

[gentoo-user] Can't get racoon IPSec going on the client machine

2011-11-20 Thread Mick
there like strongswan, but would really like to learn to do it using the vanilla racoon and kernel set up first rather than apply another layer of software to it. Could some kind soul give me a nudge in troubleshooting this? On the home router I have: public IP: 123.456.78.9 LAN: 10.10.10.0/24

[gentoo-user] Re: Can't get racoon IPSec going on the client machine

2011-11-21 Thread Mick
configuration of racoon is not working.  There are other apps out there like strongswan, but would really like to learn to do it using the vanilla racoon and kernel set up first rather than apply another layer of software to it. Could some kind soul give me a nudge in troubleshooting