Racoon without compression

Loren M. Lang lorenl at alzatex.com
Mon Feb 21 12:24:44 GMT 2005


On Tue, Feb 15, 2005 at 06:03:17PM -0500, Christopher Rued wrote:
> Hi all,
> 
> I'm trying to set up a VPN connection to a NetScreen VPN using racoon.  
> I configured all of the settings (I think) to match those specified on 
> the NetScreen, except for compression_algorithm.
> 
> The only option for compression_algorithm given to me by racoon is 
> deflate.  The NetScreen VPN is configured with "Compression: None".
> 
> Am I out of luck here?

No, compression is not needed for IPSec.  The only compression
algorithm racoon supports is defate, but that doesn't mean it won't run
without compression.  The settings in /etc/ipsec.conf are what tell
FreeBSD's IPSec to use or not use compression.  ESP is an encryption
layer that you can enable in ipsec.conf and IPComp is a compression
layer, if you only setup ESP then no compression takes place.

> 
> Please be sure to inclue me on any replies, as I am not subscibed to the 
> list.
> 
> TIA
> 
> --Chris
> 
> _______________________________________________
> freebsd-questions at freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-questions
> To unsubscribe, send any mail to "freebsd-questions-unsubscribe at freebsd.org"

-- 
I sense much NT in you.
NT leads to Bluescreen.
Bluescreen leads to downtime.
Downtime leads to suffering.
NT is the path to the darkside.
Powerful Unix is.

Public Key: ftp://ftp.tallye.com/pub/lorenl_pubkey.asc
Fingerprint: B3B9 D669 69C9 09EC 1BCD  835A FAF3 7A46 E4A3 280C
 


More information about the freebsd-questions mailing list