Re: Can't set up an IPsec tunnel.

From: Lawrence Sica (lomifeh@hotmail.com)
Date: 01/24/02


From: "Lawrence Sica" <lomifeh@hotmail.com>
To: <freebsd-security@freebsd.org>
Date: Thu, 24 Jan 2002 11:22:27 -0800


----- Original Message -----
From: "Eric Anderson" <anderson@centtech.com>
To: "Lawrence Sica" <lomifeh@hotmail.com>
Cc: "dr3node" <rtfm@webburo.ru>; <freebsd-security@freebsd.org>
Sent: Thursday, January 24, 2002 11:06 AM
Subject: Re: Can't set up an IPsec tunnel.

> Can you post that here? Any changes you needed to make to allow the ESP
to be
> passed, and any tricks you needed to know to do it?
>

I'll look up my notes, I used an article on daemonnews as my basis but i do
remember having to allow with ipfw esp to pass throught

ipfw add allow esp from any to any for example

Also some udp stuff too, the ports are in /etc/services...and /etc/protocols
has info on esp you needto let through.

--Larry

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: Cant set up an IPsec tunnel.
    ... > Subject: Re: Can't set up an IPsec tunnel. ... >> IPSEC won't work through masquarading boxes or NAT firewalls. ... Big thing is allowing the firewall to pass esp. ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • Re: Cant set up an IPsec tunnel.
    ... Can't set up an IPsec tunnel. ... you have to do lan-to-lan tunneling to get it to work. ... Big thing is allowing the firewall to pass esp. ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)