IPSec and Racoon between 5.4 and 4.11

Daren Russell darenr at end-design.co.uk
Mon May 16 04:52:52 PDT 2005


Hi,

We have a VPN between two FBSD machines using IPSEC and Racoon.  I
managed to put this together a couple of years back with (getting) old
hardware, although I am certainly no expert.  One of the machines is
about to be replaced as it is occasionally conking out, and I though I
would try the 5.4 release on the new hardware (both existing machines
are running 4.9)

I have setup internally the layout and effectively replicated the
configs of both machines (except for the one being 5.4, and a second
running 4.11 instead of 4.9), but I cannot get them talking.  The
configs for Racoon/IPSec/psk have been transferred over with zero
changes.  The 5.4 machine is using standard IPSEC (not FAST_IPSEC), and
a standard tunnel works fine.  It's as soon as IPSec/Racoon is brought
in that it falls over.

Has anybody got 5.4 <-> 4.11 talking in this config, or does anybody
know of any pitfalls because of kernel changes?

The only other thing is the 5.4 machine is running amd64.

Thanks for any help / pointers.
Daren



More information about the freebsd-questions mailing list