Re : Re : vpn isakmpd ipsec, one side with only one interface

2012-02-18 Thread Mik J
teFW <- LAN 2 -> SomeDevice > > De : Wesley M. >@ : Mik J >Cc : misc@openbsd.org >Envoyi le : Vendredi 17 fivrier 2012 5h45 >Objet : Re: Re : vpn isakmpd ipsec, one side with only one interface > >I know ssh works also very well. But the com

Re: Re : vpn isakmpd ipsec, one side with only one interface

2012-02-16 Thread Wesley M.
l original - >> De : Wesley M. > >> @ : Markus Wernig >> Cc : > misc@openbsd.org >> Envoyi le : Jeudi 16 fivrier 2012 15h59 >> Objet : Re: vpn > isakmpd ipsec, one side with only one interface >> >> I have it working ;-) >> > What i ha

Re : vpn isakmpd ipsec, one side with only one interface

2012-02-16 Thread Mik J
mounted between OpenBSD and RemoteFW. - Mail original - > De : Wesley M. > @ : Markus Wernig > Cc : misc@openbsd.org > Envoyi le : Jeudi 16 fivrier 2012 15h59 > Objet : Re: vpn isakmpd ipsec, one side with only one interface > > I have it working ;-) > Wh

Re: vpn isakmpd ipsec, one side with only one interface

2012-02-16 Thread Wesley M.
I have it working ;-) What i have done : Create a vether0 with : inet 172.17.2.21 255.255.255.0 Create a bridge0, add to it vether0 and the physical card... PF : filter the bridge Create the vpn, i can reach the ftp :-) Pretty cool Thank's to vether !! Cheers, Wesley MOUEDINE ASSABY On Thu, 16

Re: vpn isakmpd ipsec, one side with only one interface

2012-02-16 Thread Markus Wernig
Hi I'm not sure if this will work, but you could try creating a loopback interface (lo2) on FWC with the IP address that the FTP server should be reachable on and then set up a regular VPN between FWA and FWC just for that one IP address: ike esp from 172.17.2.21/32 to 192.168.0.0/24 peer ip_fwA .