Re: IPsec IKEv1 accepts non-matching phase 2 parameters

2016-01-02 Thread Julian Hsiao
ts the wrong traffic - 0.0.0.0/0 is an obvious example but rather unsubtle. I'm not sure I completely follow. Do you mean that the client has "from any to $SERVER_IP" instead of "from $CLIENT_IP to $SERVER_IP", resulting the client routing all its traffic to the server? Incidentally, do you know if iked(8) (IKEv2) suffers from similar gotchas? Thanks. Julian Hsiao

Re: IPsec IKEv1 accepts non-matching phase 2 parameters

2015-12-31 Thread Julian Hsiao
31.12.2015 06:56 schrieb Julian Hsiao: How do I configure isakmpd such that phase 2 parameters must also match on both ends in order to establish security associations? Just a guess, but do: echo r > /var/run/isakmpd.fifo and look into the /var/run/isakmpd.report My bet is, that you had a h

IPsec IKEv1 accepts non-matching phase 2 parameters

2015-12-30 Thread Julian Hsiao
0x6cf20561 auth hmac-md5 enc blowfish How do I configure isakmpd such that phase 2 parameters must also match on both ends in order to establish security associations? Thanks. Julian Hsiao

Re: stable tree

2013-03-22 Thread Julian Hsiao
I'm also curious why patch 002 is not in OPENBSD_5_2 branch, especially since patch 003 is. Is patch 002 intentionally skipped over? Julian Hsiao On 2013-03-17 07:23:23 +, Maurice Janssen said: The latest patches on the errata-page for 5.2 and 5.3 are not yet in the stable tree