Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 21 Jul 2002 16:41:00 +0200
From:      lupe@lupe-christoph.de (Lupe Christoph)
To:        ticso@cicely.de
Cc:        chris scott <chris.scott@uk.tiscali.com>, freebsd-questions@FreeBSD.ORG, freebsd-security@FreeBSD.ORG
Subject:   Re: roaming ipsec policies and racoon
Message-ID:  <20020721144100.GD461@lupe-christoph.de>
In-Reply-To: <20020721132730.GB83916@cicely5.cicely.de>
References:  <008501c2304c$59fbd800$a4102c0a@viper> <20020721132730.GB83916@cicely5.cicely.de>

next in thread | previous in thread | raw e-mail | index | archive | help
On Sunday, 2002-07-21 at 15:27:31 +0200, Bernd Walter wrote:
> On Sun, Jul 21, 2002 at 01:16:18AM +0100, chris scott wrote:

> > I am currently trying playing with IPSEC and racoon to provide a secure services for my users. They all use either freebsd or windows 2k/XP clients. They unfortunately all have dynamic ips 8(. I have successfully configured the ipsec policies and have got round the dynamic IP problem with the freebsd clients by using  racoons peer and my identifier  features to initiate the shared key communication. This all works fine. However I don't know how to do the same thing with windows 2000/XP. I can setup the ipsec policies on the clients easily enough, as I can the preshared key. I have no idea how to set the identifiers though. Without this racoon doesn't match a key on the psk.txt file as it uses the hosts ip rather than whatever@this.com and hence fails the key exchange. Has anyone got any clues to point me in the correct direction?

> With Windows you have to either use PPTP or L2TP/IPSec-tranport mode.
> Windows native implementation of IPSec-tunnel mode only works with
> fixed IPs.
> You still have the option to use a different implementation than that
> of  Microsoft.

You will have to refresh the security policy every time you dial up.

Look here (the VPN tool will help you, having to use the "assistant"
is painful):
  http://vpn.ebootis.de/

AFAIR W2k SP2 is required.

HTH,
Lupe Christoph
-- 
| lupe@lupe-christoph.de       |           http://www.lupe-christoph.de/ |
| I have challenged the entire ISO-9000 quality assurance team to a      |
| Bat-Leth contest on the holodeck. They will not concern us again.      |
| http://public.logica.com/~stepneys/joke/klingon.htm                    |

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20020721144100.GD461>