replacement of security/ipsec-tools

Karl Denninger karl at denninger.net
Mon Jan 13 16:28:37 UTC 2020


On 1/13/2020 10:26, Victor Sudakov wrote:
> Karl Denninger wrote:
>
> [dd]
>
>> Strongswan works fine with Win10 HOWEVER note that Windows 10 until
>> somewhat recently (last summer, I believe) and ALL PREVIOUS VERSIONS
>> (e.g. Win7, 8, etc.) had a SEVERE problem with IkeV2 connections, which
> Karl,
>
> Thanks a lot for the detailed info. I may need it one day.
>
> For the present, however, I'm interested not in an IPSec VPN (in Windows
> terminology) but in a simple transport mode IPSec between a FreeBSD and a
> Windows host. 
>
> My only option for that is IKEv1 because IKEv2 is configured on Windows
> 10 and Windows 2016 from PowerShell only, and I need to configure a
> secure connection via Group Policy editor (mmc). I'm still too weak of
> heart to use PowerShell for IPSec setup.
>
> I have this working successfully with racoon (on pre-shared keys) and am
> investigating the possibility to replace racoon with strongswan.

Gotcha.... I misunderstood the application...  I've not attempted to set
that up here....


-- 
Karl Denninger
karl at denninger.net <mailto:karl at denninger.net>
/The Market Ticker/
/[S/MIME encrypted email preferred]/
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4897 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://lists.freebsd.org/pipermail/freebsd-net/attachments/20200113/bc4d2706/attachment.bin>


More information about the freebsd-net mailing list