Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Zero to IPSec in 4 minutes
Dragos Ruiu

This short article looks at how to get a fully functional IPSec VPN up and running between two fresh OpenBSD installations in about four minutes flat.

Comments Mode:
Zero to IPSec in 4 minutes 2006-03-01
Ron W. Szpak (1 replies)
Re: Zero to IPSec in 4 minutes 2007-02-24
Reza A.
Zero to IPSec in 4 minutes 2006-03-01
Anonymous
Zero to IPSec in 4 minutes 2006-03-01
Anonymous (1 replies)
Zero to IPSec in 4 minutes 2006-03-01
Anonymous
pf.conf typo? 2006-03-01
Will B (1 replies)
Re: pf.conf typo? 2006-03-01
Kelly Martin
Zero to IPSec in 4 minutes 2006-03-02
Anonymous (1 replies)
Re: Zero to IPSec in 4 minutes 2006-03-09
Anonymous
Zero to IPSec in 4 minutes 2006-03-02
Anonymous
editing rc.conf 2006-03-02
marco
rc.conf typo? 2006-03-06
nikns
Zero to IPSec in 4 minutes 2006-03-07
NGardner
Zero to IPSec in 4 minutes -DHCP? 2006-03-20
JB (1 replies)
Zero to IPSec in 4 minutes 2006-03-20
Anonymous (1 replies)
Re: Zero to IPSec in 4 minutes 2006-05-04
hackmann (1 replies)
Zero to IPSec in 4 minutes 2006-12-02
Anonymous
IPSec LAN 2007-02-14
Bigg Scuza
Zero to IPSec in 4 minutes 2007-08-08
Anonymous
Zero to IPSec in 4 minutes 2007-09-27
Anonymous
Zero to IPSec in 4 minutes 2008-01-04
Davan
Need to enable ESP/AH 2008-03-01
Tom - lobato (at) tiencon.com (dot) br [email concealed]
Great article! I just have a complement and a suggestion.

on OpenBSD 4.0 (not tested on later versions) I had to enable ESP and AH to get IPsec working (I`ve not tried to enable each one only). Before it I got errors as below:

isakmpd: exchange_run: doi->initiator failed isakmpd: pf_key_v2_get_spi: GETSPI: Operation not supported

isakmpd: initiator_send_HASH_SA_NONCE: doi->get_spi failed

To enable, run from shell:

sysctl net.inet.esp.enable=1

sysctl net.inet.ah.enable=1

(to set it on boot uncomment and set to =1 these lines in /etc/sysctl.conf)

As a suggestion, you could add some pointers to documentation about how to set up more complex IPsec scenarios, since this is a basic one.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/infocus/1859/1079#1079







 

Privacy Statement
Copyright 2007, SecurityFocus