From owner-freebsd-security@FreeBSD.ORG Sat Apr 10 05:32:55 2004 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 08E1216A4CE for ; Sat, 10 Apr 2004 05:32:55 -0700 (PDT) Received: from transport.cksoft.de (transport.cksoft.de [62.111.66.27]) by mx1.FreeBSD.org (Postfix) with ESMTP id 7A00F43D31 for ; Sat, 10 Apr 2004 05:32:54 -0700 (PDT) (envelope-from bzeeb-lists@lists.zabbadoz.net) Received: from transport.cksoft.de (localhost [127.0.0.1]) by transport.cksoft.de (Postfix) with ESMTP id 8D4321FF931; Sat, 10 Apr 2004 14:32:52 +0200 (CEST) Received: by transport.cksoft.de (Postfix, from userid 66) id 8BC311FF91D; Sat, 10 Apr 2004 14:32:50 +0200 (CEST) Received: by mail.int.zabbadoz.net (Postfix, from userid 1060) id 70D8C154DB; Sat, 10 Apr 2004 12:32:36 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by mail.int.zabbadoz.net (Postfix) with ESMTP id 665EA154DA; Sat, 10 Apr 2004 12:32:36 +0000 (UTC) Date: Sat, 10 Apr 2004 12:32:36 +0000 (UTC) From: "Bjoern A. Zeeb" X-X-Sender: bz@e0-0.zab2.int.zabbadoz.net To: Nikolay Petrov In-Reply-To: <1185611253.20040410151233@hq.panda.bg> Message-ID: References: <1185611253.20040410151233@hq.panda.bg> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII X-Virus-Scanned: by AMaViS cksoft-s20020300-20031204bz on transport.cksoft.de cc: freebsd-security@freebsd.org Subject: Re: IPSec debug X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 10 Apr 2004 12:32:55 -0000 On Sat, 10 Apr 2004, Nikolay Petrov wrote: Hi, > I have FreeBSD box with network interface having y.y.y.y ip address. > On same box i configure next ipsec ploicys to process trafic from > hardware ipsec enabled device. > > spdadd 0.0.0.0/0 x.x.x.x/24 any -P out ipsec esp/tunnel/y.y.y.y-z.z.z.z/require; > spdadd x.x.x.x/24 0.0.0.0/0 any -P in ipsec esp/tunnel/z.z.z.z-y.y.y.y/require; > > Is it possible to see decrypted incoming packets, and outgoing packets > before are they encrypted IMHO no. I think OpenBSD has if_enc(4) for this. -- Bjoern A. Zeeb bzeeb at Zabbadoz dot NeT 56 69 73 69 74 http://www.zabbadoz.net/