Possible IPsec Trouble in 5.2RC?

Nathan Kay mcnate at numenor.net
Fri Dec 19 06:34:02 PST 2003


On Thu, Dec 18, 2003 at 10:49:32PM -0800, Crist J. Clark wrote:
> IPsec does work, however. When I manually load up the SAD with
> setkey(8), the ESP tunnel comes up and everything is fine.

	Confirmed, IKE no longer works for my setup either, while manual
keying does.

> I think the problem is that the IKE traffic, 500/udp, is not bypassing
> the IPsec processing like it should.

	That's what looked like was going on in my setup as well.

-- 
Nathan Kay
Numenorean Networks
http://www.numenor.net
PGP Public Key: http://www.numenor.net/~mentat/pgp.asc

"Unix is like a Vorlon: It's incredibly powerful, gives terse,
 cryptic answers, and has a lot of things going on in the
 background."



More information about the freebsd-current mailing list