iked: how to request a virtual IP when running as a road warrior

2018-01-30 Thread Peter Müller
uest a virtual IP? Any help is highly appreciated, since I am flying blind here. Thanks and best regards, Peter Müller

Re: iked: how to request a virtual IP when running as a road warrior

2018-02-04 Thread Peter Müller
Hello, thanks for the reply. > Hello > > On 01/30/18 22:00, Peter Müller wrote: > > Hello *, > > > > I am trying to set up an IPsec connection between OpenBSD 6.2 > > and an IPFire firewall, while the OpenBSD is a road warrior. > > There, I use "iked

Re: Blocking "shodan.io" - What are my options?

2019-01-03 Thread Peter Müller
ate limits, I doubt maintaining an IP list makes sense. Querying RBLs or lists of known networks hosting malware (i.e. Spamhaus DROP) probably requires less manual effort. Thanks, and best regards, Peter Müller > Hi, > > I wish to block all attempts by “shodan.io”. Basically I run an Op

Re: Restart single iked connections

2020-01-26 Thread Peter Müller
connections break down due to an iked restart, as Stephan already pointed out. So any advice on this is appreciated a lot. :-) Thanks, and best regards, Peter Müller > Hi *, > > I am in a situation where I've got hosts that handle IPsec connection > with multiple endpoints. > >

Re: strongSwan cannot install IPsec policies on OpenBSD

2020-02-17 Thread Peter Müller
t; bytes_o, rekeying in 42 minutes >N2NTESTCONN{1}: 10.xxx.xxx.2/32 === 10.yyy.yyy.0/24 Traffic from the remote IPsec peer (which is a Linux machine) successfully reaches the OpenBSD system ("5040 bytes_i"), but responses do not make it back ("0 bytes_o"). Actually

Re: Detecting DoH using PF

2020-02-18 Thread Peter Müller
+Become+One+With+the+Packet+Be+the+Query+See+the+Query/25628 Thanks, and best regards, Peter Müller > Hi Erik, > > On Mon, Feb 17, 2020 at 06:07:59PM +, Erik Lauritsen wrote: > | Hi, > | > | Is a DNS over HTTPS recognizable somehow so that it can be fingerprinted > | and

Re: strongSwan cannot install IPsec policies on OpenBSD

2020-02-20 Thread Peter Müller
(and other ones, if necessary) looks like. Sorry for bringing this up again, but I am out of ideas now and packaging strongSwan for OpenBSD would not make sense if it could not be used properly. :-) Thanks again for any advice on this. Best regards, Peter Müller

strongSwan cannot install IPsec policies on OpenBSD

2020-02-14 Thread Peter Müller
ablish CHILD_SA, keeping IKE_SA To those who are running strongSwan as an IPsec client on OpenBSD: Which is the best procedure in this case? Are there other methods of installing IPsec policies into the kernel available? Thanks for any help in advance. Best regards, Peter Müller P.S.: I

Re: strongSwan cannot install IPsec policies on OpenBSD

2020-02-16 Thread Peter Müller
Hello Stuart, thanks for your quick reply. > On 2020-02-14, Peter Müller wrote: >> Hello openbsd-misc, >> >> during some flaws in OpenIKED, I am forced to use strongSwan as an IPsec >> client on an >> OpenBSD 6.6 machine. While establishing an IKE_SA wo

Re: IPsec and MTU / fragmentation

2020-02-10 Thread Peter Müller
t regards, Peter Müller > Hi misc@, > > I've set up an IPsec tunnel to for serving my website from my home. The > tunnel works quite well most of the time, but if I try to deliver big > files over it, the HTTP client never gets a response. After some > testing, if I