ipsec setup question

From: Alwyn Goodloe (agoodloe@gradient.cis.upenn.edu)
Date: 01/07/02


Date: Mon, 7 Jan 2002 13:49:19 -0500 (EST)
From: Alwyn Goodloe <agoodloe@gradient.cis.upenn.edu>
To: <freebsd-security@FreeBSD.ORG>


 Hi folks, I am trying to set up an IPV4 over IPV4 tunnel on a testbed of
four systems I have setup for research. Because its research my configuration
is probably a bit different than most of you would run in practice.
The first test would have a tunnel bewteen the two ends of the network.
(You can think of this as the client and server both acting as gateways
with two routers in between).

From the somewhat limited documentation I did the
following:

gifconfig gif0 inet 192.168.1.3 192.168.5.12
ifconfig gif0 inet 192.168.1.3 192.168.5.12
route add -net 192.168.5.12 -interface gif0

Unfortunately I get the error message:

error_message=/kernel:gif_out:recursively called too many times

Anyone got any ideas??

Also I would like to nest tunnels and by that I mean

say have an end to end tunnel with ESP but have each intermediate router
(there are two of them) check AH headers on the packet. Anyone see any
problems with this.

Alwyn Goodloe
agoodloe@gradient.cis.upenn.edu

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: ipsec setup question
    ... I am trying to set up an IPV4 over IPV4 tunnel on a testbed of ... > The first test would have a tunnel bewteen the two ends of the network. ... > Unfortunately I get the error message: ... The physical endpoints can't be the same as the tunnel endpoints. ...
    (FreeBSD-Security)
  • This is heady - DMVPN / HSRP
    ... My company has two Cisco 2800 routers with IPSec and FW IOS, ... I am wanting to run HSRP on both the inside and outside - no problem. ... specifically with the Tunnel interfacecreated with GRE Multicast. ... of the tunnel interface on the active router. ...
    (comp.dcom.sys.cisco)
  • Re: Cant map drives over multi-homed network (VPN)
    ... Those routers pass all traffic between them through the tunnel if you ... have it setup correctly - you said you can ping a computer from one side ... since you are using a "workgroup" you need to make sure ...
    (microsoft.public.win2000.networking)
  • Re: ethernet keepalive
    ... that would give me possibility to SEE on routers if link between ... switch1 and switch2 is broken. ... If that's more common network scenario, ... A tunnel destination will follow the same routing path as your ...
    (comp.dcom.sys.cisco)
  • Re: ethernet keepalive
    ... that would give me possibility to SEE on routers if link between ... switch1 and switch2 is broken. ... If that's more common network scenario, ... A tunnel destination will follow the same routing path as your ...
    (comp.dcom.sys.cisco)