Re: IKEv2/IPSEC Road Warrior VPN Tunneling?

2013-05-13 Thread VANHULLEBUS Yvan
On Wed, Apr 17, 2013 at 11:57:19AM +0200, Willy Offermans wrote: Hello Karl and FreeBSD friends, Hi all. I recall having read about racoon and roadwarrior. Have a look to /usr/local/share/examples/ipsec-tools/, if you have installed it. I'm also planning to install this on my server. However

Re: ipsec kernel panic

2012-06-25 Thread VANHULLEBUS Yvan
User-Agent: All mail clients suck. This one just sucks less. On Mon, Jun 25, 2012 at 07:34:25AM +0300, mbsd wrote: Hi stable users. Hi. Like this good guy: http://www.freebsd.org/cgi/query-pr.cgi?pr=159629cat= I'm bad guy also have kernel panic. 1;2802;0c Maybe it's doesn't matter good or

Re: Support for IPSec NAT-T in transoprt mode

2012-04-16 Thread VANHULLEBUS Yvan
Hi. On Sun, Apr 15, 2012 at 04:40:03PM +0300, Zmiter wrote: 14.04.2012 19:59, Bjoern A. Zeeb ??: On 13. Apr 2012, at 04:28 , Zmiter wrote: Hello. Does FreeBSD 8.[0-4] support IPSec NAT-T in transport mode? Or it's still in broken state? It's not broken; it was never

Re: Enabling IPSec panics stable/9 (runs OK on stable/8)

2012-01-05 Thread VANHULLEBUS Yvan
On Thu, Jan 05, 2012 at 11:20:48AM +0100, Attila Nagy wrote: On 01/04/12 17:31, VANHULLEBUS Yvan wrote: [] Could you check that you are running a correct debug kernel ? The kernel config is GENERIC, plus some, so it contains DEBUG=-g makeoptions. Ok. [] (kgdb) frame 7 #7

Re: Enabling IPSec panics stable/9 (runs OK on stable/8)

2012-01-04 Thread VANHULLEBUS Yvan
On Wed, Jan 04, 2012 at 01:46:03PM +0100, Attila Nagy wrote: Hi, Hi. I've just upgraded a 8-STABLE box to 9-STABLE (well, just few commits before it has been tagged as STABLE), which runs from NFS (pxebooted). It has some IPSec config in ipsec.conf, like this for several boxes:

Re: Enabling IPSec panics stable/9 (runs OK on stable/8)

2012-01-04 Thread VANHULLEBUS Yvan
On Wed, Jan 04, 2012 at 04:17:41PM +0100, Attila Nagy wrote: [] #7 0x809bf779 in ipsec_process_done (m=0xfe000c7c7a00, isr=0xfe001bf54380) at /data/usr/src/sys/netipsec/ipsec_output.c:170 Here seems to be the problem Can you do the following (in this

Re: SPD

2011-03-26 Thread VANHULLEBUS Yvan
On Fri, Mar 25, 2011 at 12:28:53PM -0400, Stephen Clark wrote: Hi, Hi. If one has multiple entries in the SPD some representing more specific network addresses not to be encrypted and sent over an ipsec tunnel vs more general networks that would be encrypted would this work? In other

Re: IPSec NAT-T in transport mode

2010-01-22 Thread VANHULLEBUS Yvan
Hi. On Thu, Jan 21, 2010 at 04:36:12PM +, David Murray wrote: [...] On 2010-01-20 Wed 1:22 pm, Crest wrote: Yes the NAT-T Patch has been integrated into FreeBSD 8.0. Just rebuild your kernel with this options: device crypto # IPsec depends on this options IPSEC options IPSEC_DEBUG

Re: IPSec NAT-T in transport mode

2010-01-20 Thread VANHULLEBUS Yvan
On Wed, Jan 20, 2010 at 03:16:02PM +0600, Rabidinov M.A. wrote: Hello, Freebsd-stable. Hi. Does FreeBSD 8.0 support IPSec NAT-T in transport mode? I want to create a L2TP/IPSec server. My VPN clients are NATed. L2TP server (MPD5.x) makes tunnel, so I need working IPSec NAT-T in transport

Re: ifconfig won't allow me to change ether address and inet address in the same command

2008-10-21 Thread VANHULLEBUS Yvan
On Tue, Oct 21, 2008 at 04:48:50PM -0200, Eduardo Meyer wrote: Hello :) Hi. Please, follow: # ifconfig rl0 ether 00:02:4f:0a:ce:f3 inet 192.168.2.12 netmask 255.255.255.0 ifconfig: can't set link-level netmask or broadcast # ifconfig rl0 inet 192.168.2.12 netmask 255.255.255.0 ether