From owner-freebsd-security Sun Jul 21 7:41: 9 2002 Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.FreeBSD.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 73E5E37B400; Sun, 21 Jul 2002 07:41:04 -0700 (PDT) Received: from antalya.lupe-christoph.de (pD9E887AE.dip0.t-ipconnect.de [217.232.135.174]) by mx1.FreeBSD.org (Postfix) with ESMTP id 4279043E3B; Sun, 21 Jul 2002 07:41:03 -0700 (PDT) (envelope-from lupe@lupe-christoph.de) Received: by antalya.lupe-christoph.de (Postfix, from userid 1000) id 3741C74C; Sun, 21 Jul 2002 16:41:00 +0200 (CEST) Date: Sun, 21 Jul 2002 16:41:00 +0200 To: ticso@cicely.de Cc: chris scott , freebsd-questions@FreeBSD.ORG, freebsd-security@FreeBSD.ORG Subject: Re: roaming ipsec policies and racoon Message-ID: <20020721144100.GD461@lupe-christoph.de> References: <008501c2304c$59fbd800$a4102c0a@viper> <20020721132730.GB83916@cicely5.cicely.de> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20020721132730.GB83916@cicely5.cicely.de> User-Agent: Mutt/1.3.28i From: lupe@lupe-christoph.de (Lupe Christoph) Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org On Sunday, 2002-07-21 at 15:27:31 +0200, Bernd Walter wrote: > On Sun, Jul 21, 2002 at 01:16:18AM +0100, chris scott wrote: > > I am currently trying playing with IPSEC and racoon to provide a secure services for my users. They all use either freebsd or windows 2k/XP clients. They unfortunately all have dynamic ips 8(. I have successfully configured the ipsec policies and have got round the dynamic IP problem with the freebsd clients by using racoons peer and my identifier features to initiate the shared key communication. This all works fine. However I don't know how to do the same thing with windows 2000/XP. I can setup the ipsec policies on the clients easily enough, as I can the preshared key. I have no idea how to set the identifiers though. Without this racoon doesn't match a key on the psk.txt file as it uses the hosts ip rather than whatever@this.com and hence fails the key exchange. Has anyone got any clues to point me in the correct direction? > With Windows you have to either use PPTP or L2TP/IPSec-tranport mode. > Windows native implementation of IPSec-tunnel mode only works with > fixed IPs. > You still have the option to use a different implementation than that > of Microsoft. You will have to refresh the security policy every time you dial up. Look here (the VPN tool will help you, having to use the "assistant" is painful): http://vpn.ebootis.de/ AFAIR W2k SP2 is required. HTH, Lupe Christoph -- | lupe@lupe-christoph.de | http://www.lupe-christoph.de/ | | I have challenged the entire ISO-9000 quality assurance team to a | | Bat-Leth contest on the holodeck. They will not concern us again. | | http://public.logica.com/~stepneys/joke/klingon.htm | To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message