"Darrell May" <[EMAIL PROTECTED]> said:

> Coloring outside the lines are we ;->

I think the more diverse the testing, the more useful our IPSec RPM / Blade
will be  ;-) I'm happy to do lots of testing on this, I have pppoe over ADSL
and a dynamic cable IP to test going into a static head office IP. I could
even test with a dial-up dynamic IP if required.

I'll test with the SnapGear and also with home based SME if you like.

> I'm just new to this but I believe there are two types of authentication
> that FreeS/WAN supports, PSK and RSA.  PSK is a shared secret.  RSA is a
> shared key.  Are you saying you need PSK?
>

The SnapGear boxen allow either PSK or RSA.
>From my reading RSA is preferred (although for ease of use the SnapGear
recommends PSK)
I had set up my SnapGear to require RSA, and had copied the Public Key both
ways.
As I said earlier, and KLIPS debug = all reported this, my setup was not
working as the SME was sending out its Authentication Identifier as @[IP
Addr], and I had set my SnapGear up to be looking for head@work from my
headoffice so the connection was being dumped before the RSA public keys
were checked. This is why something to report the current Authentication ID,
and / or set it to your preferred ID would be worthwhile.

In the end I want to be able to set up multiple IPSec based VPNs from (in my
case 3) home users with cheaper dynamically assigned IPs to my head office
with its static IP.

If we want to take this to the ultimate IPSec RPM, we should allow dynamic
at both ends (hopefully tied into dyndns).

One other small comment: The naming convention in the server-manager is
currently "Virtual private networks". I think that should change to "IPSec
setup", as PPTP VPNs are already available through the Remote Access page.

So further down this development path we will need to make room for
additional /etc/e-smith/templates/etc/ipsec.conf/30Connections and / or a
complicated script in there to read from multiple entries in
/home/e-smith/configuration. Likewise
/etc/e-smith/templates/etc/ipsec.secrets/10RSAKey will need to be modified
to allow multiple secrets.

There is also the latest freeswan stuff to do with opportunistic encryption
...... but that is in 1.91  <G>

I'm sorry guys, I am a user not a programmer. I am a sales guy, but in this
small office also IT guy, so I am at the limit of my capabilities in testing
and throwing in my 2 cents worth  .....   ;o)

Thanks for coming back Andy your work so far has given us a very good
starting point, and thanks for all your work Darrell.

Hugh Fox
Sales Director
www.drcauto.com

drcauto now hosts support newsgroups:
news://news.drcauto.com/drcauto.lt_toolkit
news://news.drcauto.com/drcauto.smart_architect
news://news.drcauto.com/drcauto.accurender_lt
The same groups are accessible via your browser, go to:
http://discussion.drcauto.com



--
Please report bugs to [EMAIL PROTECTED]
Please mail [EMAIL PROTECTED] (only) to discuss security issues
Support for registered customers and partners to [EMAIL PROTECTED]
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]
Archives by mail and http://www.mail-archive.com/devinfo%40lists.e-smith.org

Reply via email to