Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 1 Oct 2004 08:23:53 -0700
From:      "Michael Kreykenbohm" <mkj1@wkcorp.com>
To:        <freebsd-questions@freebsd.org>
Subject:   dynamic IPSEC: Holy grail sighted
Message-ID:  <HNEMKEGOGLPNEIDBEMGJMEAACAAA.mkj1@wkcorp.com>

next in thread | raw e-mail | index | archive | help

I have a router/ FreeBSd with a network on the other side with a Dynamic IP.
At the other end is a static IP router/ FreeBsd box.

I was using a manually keyed encryption,
now I have the racoon to do the key negotiation.

I can change the static gif0 interfaces at the VPn dynamic router using the
dhclient-exit-loop.

But what about the server gif0 interface. The gif0 tunnel attributes want
the
VPN's router address, and I would need an "exit-hook" from racoon to set
this up,
more then just setting the SPD keys.


Any idea where to latch that from. I'v though about watchdogs (check the SPD
keys),
but is there a better way.


Michael Kreykenbohm



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?HNEMKEGOGLPNEIDBEMGJMEAACAAA.mkj1>