From owner-freebsd-current@FreeBSD.ORG Fri Apr 30 03:17:26 2004 Return-Path: Delivered-To: freebsd-current@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 6B34416A4CE for ; Fri, 30 Apr 2004 03:17:26 -0700 (PDT) Received: from coruscant.rfc1149.org (coruscant.rfc1149.org [217.160.130.147]) by mx1.FreeBSD.org (Postfix) with ESMTP id 330C343D62 for ; Fri, 30 Apr 2004 03:17:26 -0700 (PDT) (envelope-from arne@rfc2549.org) Received: by coruscant.rfc1149.org (Postfix, from userid 110) id 8ABF33FB3; Fri, 30 Apr 2004 12:17:25 +0200 (CEST) Received: from kamino.rfc1149.org (kamino.rfc1149.org [2001:8d8:81:11::2]) by coruscant.rfc1149.org (Postfix) with ESMTP id 3221E3CBE; Fri, 30 Apr 2004 12:17:21 +0200 (CEST) Received: by kamino.rfc1149.org (Postfix, from userid 1001) id 68A4235; Fri, 30 Apr 2004 12:17:20 +0200 (CEST) To: Eivind Olsen In-Reply-To: <340419687.1083326256@[10.122.7.143]> (Eivind Olsen's message of "Fri, 30 Apr 2004 11:57:36 +0200") References: <340419687.1083326256@[10.122.7.143]> From: Arne Schwabe Date: Fri, 30 Apr 2004 12:17:20 +0200 Message-ID: <863c6lbwi7.fsf@kamino.rfc1149.org> User-Agent: Gnus/5.110002 (No Gnus v0.2) Emacs/21.3 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-Spam-Checker-Version: SpamAssassin 2.60 (1.212-2003-09-23-exp) on coruscant.rfc1149.org X-Spam-Status: No, hits=-4.9 required=5.0 tests=BAYES_00 autolearn=ham version=2.60 X-Spam-Level: cc: freebsd-current@FreeBSD.org Subject: Re: IPSEC, IPv6, RELENG_5_2 X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 30 Apr 2004 10:17:26 -0000 Eivind Olsen writes: > Hello. > Does anyone know of a way to make hardware accelerated (Soekris > vpn1401 card) VPN work on a RELENG_5_2 box (or CURRENT, if need be..) > and at the same time support IPv6? > > I believe I need FAST_IPSEC to get hardware accelerated VPN/IPSEC, and > it doesn't look like I can compile in both FAST_IPSEC and INET6 at the > same time in the kernel. > I have read that FAST_IPSEC doesn't do IPSEC for IPv6 and that's OK > with me, but I'd still like to be able to use IPv6 for some > connections and IPSEC for a VPN-connection (running over IPv4). > > Anyone who knows if this is somehow possible? I had no problem compiling both FAST_IPSEC and IPv6 into a current kernel. If you want I can you my config. But be warned it is a stripped down config for a soekris router (no ps/2, no vga support, etc) yavin:options INET6 # IPv6 communications protocols yavin:options FAST_IPSEC arne@yavin:~% uname -a FreeBSD yavin.rfc1149.org 5.2-CURRENT FreeBSD 5.2-CURRENT #0: Thu Apr 22 20:41:02 CEST 2004 arne@kamino.rfc1149.org:/usr/src/sys/i386/compile/yavin i386 -- Ah, the beauty of OSS. Hundreds of volunteers worldwide volunteering their time inventing and implementing new exciting ways of old fashioned wheels.