Re: creating an IPsec SA with ports specified



Jiri Klimes <klimes@xxxxxxxxxx> writes:

> Hello,
>
> I am not able to create an IPsec SA with ports specified.
> I've been successful neither with setkey nor programmatically using PF_KEY
> messages.
>
> I use linux (kernel 2.6.13)
>
> 1) setkey (using version 0.6.4)
> add 10.0.11.41[2365] 10.0.11.33[2416] esp 0x10001
> -E des-cbc 0x3ffe05014819ffff
> -A hmac-md5 "authentication!!";

What do you want exactly to do by setting up ports ?

If you want to protect traffic for only some ports, then this must be
done in the SPD, not in the SAs.

If you really want to create static SAs to use UDP encapsulation on
ports 2365 -> 2416, then my next question will be "do you really hope
such configuration will work ????"....


Yvan.
.



Relevant Pages

  • Re: pen-test on a windows 2003 server box whit MS-SQL and Terminal Services
    ... Running automated tools ... and expecting to be successful is bad practice. ... manual testing on these ports. ... > also tried the tsgrinder for terminal services, ...
    (Pen-Test)
  • dladm aggregate aggr1 mac address messages during bootup
    ... An attempt to configure 2 x bge ports on the Sun Fire v240 to aggregate ... their links using Solaris 10's new dladm command was "partially" ... We noted the following messages upon a successful reboot; ...
    (SunManagers)
  • creating an IPsec SA with ports specified
    ... I am not able to create an IPsec SA with ports specified. ... I've been successful neither with setkey nor programmatically using PF_KEY ... I use linux (kernel 2.6.13) ...
    (comp.os.linux.security)
  • Re: Sony Clie PEG-TJ37 vs. FreeBSD CURRENT (long)
    ... Yeah, that's the part where you'd potentially ... >> ports are really available and hopefully get someone who really knows ... the only reason that I'm getting a successful ...
    (freebsd-current)
  • Re: Required ports
    ... cannot use the program to connect to his company within our network. ... successful. ... our firewall is blocking the ports his program is ... Can someone advise how to locate the required ports to be used by ...
    (comp.security.firewalls)