Re: iked.conf question - muplitple clients with certs.

2012-08-16 Thread Paulm
I'm not sure if it's relevant for your situation, but do you know that, according to the iked(8) manpage, iked is 'not finished' and not recommended for production networks? (See the last section - 'caveats') It might be better to use isakmpd(8) with ipsec(4)/ipsecctl(8)/ipsec.conf(5) if your

iked.conf question - muplitple clients with certs.

2012-08-15 Thread Bentley, Dain
Hello Misc, I'm having a small issue with my iked.conf on my openbsd 4.9 firewall. I have the following config and it works fine: Ikev2 laptop passive esp \ From 192.168.10.0/24 to 1.1.1.0/24 local any peer any \ srcid xxx.xxx.xxx.xxx \ config