Re: VPN site to site with ipsec

2007-07-24 Thread sonjaya
yhx have been working now , my notebook antivirus blocking ping request . but how i can make the server vpn in host(a) can accepy any connection from dynamic ip , and mobile user . thx On 7/23/07, John Jackson [EMAIL PROTECTED] wrote: Have you tried tcpdumping on the enc0 interface on both

VPN site to site with ipsec

2007-07-23 Thread sonjaya
Dear all i have network lite this pc(b)host(b)---internet-host(a)-pc(a) i follow tutorial from this link : http://www.openbsdsupport.org/vpn-ipsec.html then i try test : 1. Ping from host(b) to host(a) or host(a) to host(b) working ( reply ) . 2. Ping from pc(b) to host (a)

Re: VPN site to site with ipsec

2007-07-23 Thread Daniel Ouellet
sonjaya wrote: http://www.openbsdsupport.org/vpn-ipsec.html This is almost 3 years old and there is so many changes, please don't follow this on 4.1! I most likely will remove it if we can get an updated version. Consider this: http://www.serverwatch.com/tutorials/article.php/3659686 or

Re: VPN site to site with ipsec

2007-07-23 Thread Daniel Ouellet
sonjaya wrote: http://www.openbsdsupport.org/vpn-ipsec.html May be you could also have a look at this nice presentation that show many changes done on OpenBSD. You can start here to see some OpenBSD suggestions, but you can look it all as well as it's nice. (;

Re: VPN site to site with ipsec

2007-07-23 Thread sonjaya
thx daniel , i have follow the link and still get ping reply from pc(a) to pc(b) , below my ipsec.conf and pf.conf in host(a) # cat /etc/ipsec.conf ike esp from 192.168.0.0/24 to 192.168.2.0/24 peer host(b) ike esp from host(a) to 192.168.2.0/24 peer host(b) ike esp from host(a) to host(b) # #

Re: VPN site to site with ipsec

2007-07-23 Thread John Jackson
Have you tried tcpdumping on the enc0 interface on both gateways to see what happens on when pinging? tcpdump -n -s 1600 -i enc0 Is there a firewall enabled on the non-responsive end hosts? I've seen recent versions of Windows block or drop icmp echo requests, maybe some recent service pack