Re: vpn1/fw1 NG to ipsec/racoon troubles, help please ...

From: Dru (dlavigne6@cogeco.ca)
Date: 07/27/02


Date: Sat, 27 Jul 2002 08:39:46 -0400 (EDT)
From: Dru <dlavigne6@cogeco.ca>
To: Matthew Grooms <mgrooms@seton.org>


On Fri, 26 Jul 2002, Matthew Grooms wrote:

> Hello,
>
> I have a freebsd related ipsec question. I have set up a checkpoint
> vpn1/fw1 NG ( feature pack 2 )gateway for vpn connectivity to the
> hospital I work for. Most of the guys on my team run linux/bsd at thier
> house so I have set up encrypt rules in vpn1 to allow us connect to the
> checkpoint box and tunnel into our network from home. In any case, one
> of my coworkers has had pretty good success with the freeswan ( can
> connect and route traffic ) but I am getting some weird behavior using
> racoon/kame ipsec. I was hoping somone could help me out with this. I
> have attached most configuration info in this email and am more than
> willing to try just about anything to get this up and running. I could
> even go so far as to set up a temporary profile in a sandbox if somone
> who knows what they are doing would like take a stab at it.
>
> I am running Checkpoint VPN1/FW1 with Feature pack 2 installed. The
> VPN1 side is set up to reflect my freebsd configuration. I am using
> preshared keys for authentication 3des/md5 & pfs. ( although I have
> tried a myriad of permutations ) The freebsd side is version 4.4 with
> the following kernel options.

<snip configs>

Have you tried a "tcpdump port 500" during Phase 1 negotiations? This will
show the proposal exchange so you can see which parts aren't matching up.
If that doesn't do it, send that output along with your racoon.conf file.

Dru

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • vpn1/fw1 NG to ipsec/racoon troubles, help please ...
    ... I have a freebsd related ipsec question. ... checkpoint box and tunnel into our network from home. ... VPN1 side is set up to reflect my freebsd configuration. ... racoon configuration parameters are set to 3des,md5,w/pfs ...
    (FreeBSD-Security)
  • Re: process checkpoint restore facility now in DragonFly BSD
    ... I'd also agree further discussion on DragonFly's checkpoint facility ... on the FreeBSD lists. ... >>done on DragonFly for checkpoint since then and if it was stopped, ...
    (freebsd-hackers)
  • Re: freebsd connecting to checkpoint vpn server howto
    ... > I would like to connect to my office via vpn. ... I've a freebsd workstation at ... > a secureremote client from checkpoint for windows 2000 and a certificate ... If it's an VPN based on IPsec, you should try IPsec + racoon. ...
    (comp.unix.bsd.freebsd.misc)
  • Re: Commerical VPN gateway
    ... sam wrote: ... FreeBSD 3.0 + checkpoint ... Remove the obvious part (including the dot) for my email address. ...
    (comp.unix.bsd.openbsd.misc)
  • Re: 5.3 interrupt storm (atapicam) and I/O error
    ... attached you will find a copy of my custom kernel ... config which did work without any issue under FreeBSD ... The following hardware configuration *won't* cause ... * harddrive attached to IDE channel #1 ...
    (freebsd-questions)