Re: OpenBSD 5.5 ISAKMPD

2015-01-19 Thread Stuart Henderson
On 2015-01-17, Daniel Ouellet dan...@presscom.net wrote: Just go to 5.6 or even better to current that is almost 5.7 now and use ikev2 instead. This might add confusion though, ikev2 (iked) isn't compatible with v1, and I'm imagining that somebody with a specific set of parameters to use will

Re: OpenBSD 5.5 ISAKMPD

2015-01-19 Thread Daniel Ouellet
On 1/19/15 3:19 AM, Stuart Henderson wrote: On 2015-01-17, Daniel Ouellet dan...@presscom.net wrote: Just go to 5.6 or even better to current that is almost 5.7 now and use ikev2 instead. This might add confusion though, ikev2 (iked) isn't compatible with v1, and I'm imagining that somebody

Re: OpenBSD 5.5 ISAKMPD

2015-01-17 Thread Boris Goldberg
Hello Motty, Friday, January 16, 2015, 5:24:33 PM, you wrote: MC is actually OpenBSD 4.8 not OpenBSD 5.5, I apologize for the mistake. I'm trying to setup IPSec Tunnel using the following parameters. Phase 1 exchange encryption: AES256 Data Integrity: SHA256 DH: group 20 Agressive Mode

OpenBSD 5.5 ISAKMPD

2015-01-16 Thread Motty Cruz
Hello All, I'm trying to setup IPSec Tunnel using the following parameters. Phase 1 exchange encryption: AES256 Data Integrity: SHA256 DH: group 20 Agressive Mode phase 2 encryption: AESGCM256 HASH: SHA384 I can't find examples to configure isakmpd.conf using parameters above. [fw2-main-mode]

Re: OpenBSD 5.5 ISAKMPD

2015-01-16 Thread mxb
Hey, You probably want to start with ipsec.conf(5). isakmpd.conf is generated out of ipsec.conf. I think people running 5.4+ don’t even use it any more. Br //mxb On 16 jan 2015, at 21:22, Motty Cruz motty.c...@gmail.com wrote: Hello All, I'm trying to setup IPSec Tunnel using the

Re: OpenBSD 5.5 ISAKMPD

2015-01-16 Thread Motty Cruz
Thanks Br, I tried it but did not generated isakmpd for me. do you have any idea of what exchange_run: doi-initiator means? Thanks, Motty On 01/16/2015 01:16 PM, mxb wrote: Hey, You probably want to start with ipsec.conf(5). isakmpd.conf is generated out of ipsec.conf. I think people running

Re: OpenBSD 5.5 ISAKMPD

2015-01-16 Thread Daniel Ouellet
Just go to 5.6 or even better to current that is almost 5.7 now and use ikev2 instead. Much simpler to use. At a minimum just give it a trial for fun if you like. You may fall in love with it. (: 4.8 is so old that I am not sure anyone will care to answer it, or even remember if they had issue