Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 27 Feb 2018 10:59:50 +0100
From:      Harry Schmalzbauer <freebsd@omnilan.de>
To:        freebsd-net@freebsd.org
Subject:   Re: if_ipsec(4) and IKEv1 [security/ipsec-tools, racoon.conf]
Message-ID:  <5A952C16.4080005@omnilan.de>
In-Reply-To: <5A952B38.8060007@omnilan.de>
References:  <5A952B38.8060007@omnilan.de>

next in thread | previous in thread | raw e-mail | index | archive | help
 Bezüglich Harry Schmalzbauer's Nachricht vom 27.02.2018 10:56 (localtime):
>  Hello,
>
> I'm out of ideas how to quick-start with if_ipsec(4) and IKEv1.
>
> I'm familar with security/ipsec-tools, but I couldn't find out how
> racoon(8) would interact with cloned if_ipsec(4) interfaces yet.
>
> Also, how to tell racoon(8) to generate such tunnel interfaces, hence
> policies?
> I guess the latter isn't implemented in racoon(8) (yet).
>
> But is racoon(8) supposed to work with static policies generated by
> if_ipsec(4)?

I doubt, since with 'ifconfig ipsec', I have to specify reqid.
How to tell racoon(8) which reqid to insert keys to ?

Thanks,

-harry




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?5A952C16.4080005>