Re: replacement of security/ipsec-tools

2020-01-11 Thread Victor Sudakov
Victor Sudakov wrote: > > > > If you ever find good documentation/howto for strongswan on FreeBSD, > > please share with me. > > Really, please! I know there are people present here using strongswan. > > I would like to try and replace racoon with it. Now thanks to Sergey Matveev and some good

Re: replacement of security/ipsec-tools

2020-01-11 Thread Victor Sudakov
Michael Grimm wrote: [dd] > > Then this mail made my day: > > >> What do I need? > >>#) a VPN tunnel between two hosts > >>#) both local networks reachable from the remote host > > > > That is what kernel IPSec is for, you can even do it on static keys > > without any ISAKMP daemon lik

[Bug 242744] IPSec in transport mode between FreeBSD hosts blackholes TCP traffic

2020-01-11 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=242744 Bjoern A. Zeeb changed: What|Removed |Added CC||b...@freebsd.org --- Comment #26

Re: [PATCH] ipoib: Patch for crash in icmp_error, fault trap 12

2020-01-11 Thread Hans Petter Selasky
Thank you for your patch: https://svnweb.freebsd.org/changeset/base/356633 --HPS ___ freebsd-net@freebsd.org mailing list https://lists.freebsd.org/mailman/listinfo/freebsd-net To unsubscribe, send any mail to "freebsd-net-unsubscr...@freebsd.org"

Re: replacement of security/ipsec-tools

2020-01-11 Thread Karl Denninger
On 1/11/2020 05:23, Victor Sudakov wrote: > Victor Sudakov wrote: >>> If you ever find good documentation/howto for strongswan on FreeBSD, >>> please share with me. >> Really, please! I know there are people present here using strongswan. >> >> I would like to try and replace racoon with it. > Now

[Bug 242744] IPSec in transport mode between FreeBSD hosts blackholes TCP traffic

2020-01-11 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=242744 --- Comment #27 from Victor Sudakov --- (In reply to Bjoern A. Zeeb from comment #26) Bjoern, can you formulate in a few own words what behavior you deem appropriate in accordance with the later RFCs? I can only say that what we have now