Re: IPSEC on Solaris 8

From: adam morley (adam@gmi.com)
Date: 10/02/01


Date: Tue, 2 Oct 2001 02:00:58 -0700
From: adam morley <adam@gmi.com>
To: SUN-sec Mailinglist <focus-sun@securityfocus.com>
Subject: Re: IPSEC on Solaris 8
Message-ID: <20011002020057.A9950@chopin.gmi.com>

On Mon, Oct 01, 2001 at 10:37:59AM +0200, Conny Stefors wrote:
> Hi,
> Is there anybody out there who has used the IPSEC feature in Solaris 8?
> I would like to have two Solaris 8 servers encrypt all there traffic
> between them.

yeah, i do a fully meshed ipsec production network on solaris 8 4/01. all data is run through 3des, and auth'ed with md5 before hopping on the network.

>
> The man-pages for the IPSEC feature is unfortunatly not very good :-(

they are good once you know what you are doing, the key is figuring out what you are doing first! your best bets are to start with the answerbooks if you have them, or just hop onto docs.sun.com:

Overview of IPsec:

http://docs.sun.com/ab2/coll.47.11/SYSADV3/@Ab2PageView/22211?DwebQuery=ipsec&oqt=ipsec&Ab2Lang=C&Ab2Enc=iso-8859-1

Implementing IPsec:

http://docs.sun.com/ab2/coll.47.11/SYSADV3/@Ab2PageView/22882?DwebQuery=ipsec&oqt=ipsec&Ab2Lang=C&Ab2Enc=iso-8859-1

that should get you started. look at all the examples, definately read the overview, so that you know what all the commands are actually doing. the flat file config for ipsec seems kludgy at first, but its actually really cool once you get into it because it lets you really narrow down what settings you want and such.

note there is a section where two machines encrypt all data between them, thats probably the section (under implementing ipsec) that you want to look at.

>
> Cheers,
> Conny



Relevant Pages

  • UPDATE: Site-to-Site VPN Using Solaris 9
    ... Solaris 9/10 IPsec tunnel to some other device? ... The problem comes in Phase 2 when the Solaris endpoint is telling ...
    (SunManagers)
  • XP -> NAT -> Sol10 VPN?
    ... I think I'm pretty much toast on this setup, but I thought I'd ask anyway, ... shared filesystem from my Ultra 5 running Solaris 10 at work. ... All my attempts to set up IPSec on the XP box have failed. ... I don't have a Sun ...
    (comp.unix.solaris)
  • Problem with IKE / IPSec in solaris
    ... We are facing problems while using the IPSEC features of Solaris 9, ... The number of messages being exchanged on this TCP connection is medium ... IPSEC SAs, IKE Daemon on the respective application (local as well as ...
    (SunManagers)
  • Re: IPSec between Solais 9/10 and XP
    ... >Yes, I know XP Home sucks, that's why 5/6 of my computers don't run XP. ... >40 Solaris systems, ideally over IPSec. ... This means you can't have Windows talk IPsec to Solaris 8 (which ...
    (comp.unix.solaris)
  • Query regarding behavior of IKE/IPSec in Solaris-9
    ... We are facing problems while using the IPSEC features of solaris, ... The number of messages being exchanged on this TCP connection is ... IPSEC SAs, IKE Daemon on the respective application (local as well as ...
    (comp.unix.solaris)