Re: OpenBSD + isakmpd + VPN concentrator 3060

2008-09-27 Thread Claer
On Fri, Sep 26 2008 at 03:19, Christoph Leser wrote: > This is interesting. We suffer from spurious connection losses since we > started with OBSD ipsec. > Do you have any details what caused your problem, and why setting > DPD-check-interval helped? The problem was the following : Tunnels were e

Re: OpenBSD + isakmpd + VPN concentrator 3060

2008-09-26 Thread Christoph Leser
This is interesting. We suffer from spurious connection losses since we started with OBSD ipsec. Do you have any details what caused your problem, and why setting DPD-check-interval helped? > In our environnement (we manage openbsd tunnels to cisco 3030 > which is out of our scope) we debugged a

Re: OpenBSD + isakmpd + VPN concentrator 3060

2008-09-26 Thread [EMAIL PROTECTED]
Claer wrote: On Fri, Sep 26 2008 at 45:07, Mariusz Makowski wrote: I finally was able to setup vpn connection. Other side was configured in wrong way and sum of all my ipsec.conf look in this way: -- ipsec.conf -- other_peer = "c.c.c.c_public_ip" ike esp tunnel from a.a.a.a_net to d.d.d.d_n

Re: OpenBSD + isakmpd + VPN concentrator 3060

2008-09-26 Thread Claer
On Fri, Sep 26 2008 at 45:07, Mariusz Makowski wrote: > I finally was able to setup vpn connection. > Other side was configured in wrong way and sum of all my ipsec.conf look in > this way: > > -- ipsec.conf -- > other_peer = "c.c.c.c_public_ip" > > > ike esp tunnel from a.a.a.a_net to d.d.d.d_net

Re: OpenBSD + isakmpd + VPN concentrator 3060

2008-09-25 Thread Mariusz Makowski
I finally was able to setup vpn connection. Other side was configured in wrong way and sum of all my ipsec.conf look in this way: -- ipsec.conf -- other_peer = "c.c.c.c_public_ip" ike esp tunnel from a.a.a.a_net to d.d.d.d_net peer $other_peer \ main auth hmac-sha1 enc 3des group modp1024 \

Re: OpenBSD + isakmpd + VPN concentrator 3060

2008-09-23 Thread Toni Mueller
Hi, On Sun, 21.09.2008 at 16:04:11 +0200, Mariusz Makowski <[EMAIL PROTECTED]> wrote: > a.a.a.a_net b.b.b.b_public_ip --- c.c.c.c_public_ip d.d.d.d_net > > What i wan't to achiev is: - comunication from a.a.a.a_net to d.d.d.d_net > -- isakmpd.conf -- > [General] > Listen-on= b.

Re: OpenBSD + isakmpd + VPN concentrator 3060

2008-09-21 Thread Mariusz Makowski
Mariusz Makowski wrote: Hello, Firstly i want to mention that it's my begining with ipsec/isakmpd tunneling. My problem is about making connection from OpenBSD 4.3 to Cisco VPN concentrator 3060. Cisco concentrator is out of my range so i can't check log there and i only wish that configura

OpenBSD + isakmpd + VPN concentrator 3060

2008-09-21 Thread Mariusz Makowski
Hello, Firstly i want to mention that it's my begining with ipsec/isakmpd tunneling. My problem is about making connection from OpenBSD 4.3 to Cisco VPN concentrator 3060. Cisco concentrator is out of my range so i can't check log there and i only wish that configuration there is done well. H