Re: OpenBSD + isakmpd + VPN concentrator 3060

2008-09-27 Thread Claer
On Fri, Sep 26 2008 at 03:19, Christoph Leser wrote: This is interesting. We suffer from spurious connection losses since we started with OBSD ipsec. Do you have any details what caused your problem, and why setting DPD-check-interval helped? The problem was the following : Tunnels were

Re: OpenBSD + isakmpd + VPN concentrator 3060

2008-09-26 Thread Mariusz Makowski
want to mention that it's my begining with ipsec/isakmpd tunneling. My problem is about making connection from OpenBSD 4.3 to Cisco VPN concentrator 3060. Cisco concentrator is out of my range so i can't check log there and i only wish that configuration there is done well. Here it is my

Re: OpenBSD + isakmpd + VPN concentrator 3060

2008-09-26 Thread Claer
, Firstly i want to mention that it's my begining with ipsec/isakmpd tunneling. My problem is about making connection from OpenBSD 4.3 to Cisco VPN concentrator 3060. Cisco concentrator is out of my range so i can't check log there and i only wish that configuration there is done well. Here

Re: OpenBSD + isakmpd + VPN concentrator 3060

2008-09-26 Thread [EMAIL PROTECTED]
--- c.c.c.c_public_ip cisco d.d.d.d_net Regard, Mariusz Makowski Mariusz Makowski wrote: Mariusz Makowski wrote: Hello, Firstly i want to mention that it's my begining with ipsec/isakmpd tunneling. My problem is about making connection from OpenBSD 4.3 to Cisco VPN concentrator 3060. Cisco

Re: OpenBSD + isakmpd + VPN concentrator 3060

2008-09-26 Thread Christoph Leser
This is interesting. We suffer from spurious connection losses since we started with OBSD ipsec. Do you have any details what caused your problem, and why setting DPD-check-interval helped? In our environnement (we manage openbsd tunnels to cisco 3030 which is out of our scope) we debugged a

Re: OpenBSD + isakmpd + VPN concentrator 3060

2008-09-23 Thread Toni Mueller
Hi, On Sun, 21.09.2008 at 16:04:11 +0200, Mariusz Makowski [EMAIL PROTECTED] wrote: a.a.a.a_net obsd b.b.b.b_public_ip --- c.c.c.c_public_ip cisco d.d.d.d_net What i wan't to achiev is: - comunication from a.a.a.a_net to d.d.d.d_net -- isakmpd.conf -- [General] Listen-on=

OpenBSD + isakmpd + VPN concentrator 3060

2008-09-21 Thread Mariusz Makowski
Hello, Firstly i want to mention that it's my begining with ipsec/isakmpd tunneling. My problem is about making connection from OpenBSD 4.3 to Cisco VPN concentrator 3060. Cisco concentrator is out of my range so i can't check log there and i only wish that configuration there is done well

Re: OpenBSD + isakmpd + VPN concentrator 3060

2008-09-21 Thread Mariusz Makowski
Mariusz Makowski wrote: Hello, Firstly i want to mention that it's my begining with ipsec/isakmpd tunneling. My problem is about making connection from OpenBSD 4.3 to Cisco VPN concentrator 3060. Cisco concentrator is out of my range so i can't check log there and i only wish

Re: VPN Concentrator

2007-12-04 Thread Marc Balmer
Joseph C. Bender wrote: Scott Learmonth wrote: And Khalid - sorry to hijack your thread. Most of my road warriors are going to be on macs and too cheap to purchase VPN Tracker. Any successes I gave I'll certainly share. There's always OpenVPN. GUI via Tunnelblick

Re: VPN Concentrator

2007-12-04 Thread Khalid Schofield
On 1 Dec 2007, at 05:37, visc wrote: On 30-Nov-07, at 2:13 AM, Khalid Schofield wrote: Hi, I'd like to make a VPN Concentrator using openbsd. I want users to be able to authenticate using usernames and passwords and to either nat the users or give them an ip from our main dhcp server via

Re: VPN Concentrator

2007-12-04 Thread Khalid Schofield
, at 2:13 AM, Khalid Schofield wrote: Hi, I'd like to make a VPN Concentrator using openbsd. I want users to be able to authenticate using usernames and passwords and to either nat the users or give them an ip from our main dhcp server via a bridge. If I have say a mac user at home wanting

Re: VPN Concentrator

2007-12-04 Thread Stuart Henderson
On 2007/12/04 21:17, Khalid Schofield wrote: So how can i get an encrypted vpn service with username and password auth instead of certificates? We kind of skimmed over those bits. is authpf any good for you?

Re: VPN Concentrator

2007-12-03 Thread Joseph C. Bender
Scott Learmonth wrote: And Khalid - sorry to hijack your thread. Most of my road warriors are going to be on macs and too cheap to purchase VPN Tracker. Any successes I gave I'll certainly share. There's always OpenVPN. GUI via Tunnelblick http://www.tunnelblick.net/ -- Joseph

Re: VPN Concentrator

2007-12-03 Thread Chris Black
Joseph C. Bender wrote: Scott Learmonth wrote: And Khalid - sorry to hijack your thread. Most of my road warriors are going to be on macs and too cheap to purchase VPN Tracker. Any successes I gave I'll certainly share. There's always OpenVPN. GUI via Tunnelblick

Re: VPN Concentrator

2007-11-30 Thread Brian A. Seklecki
On Fri, 30 Nov 2007, Khalid Schofield wrote: Hi, I'd like to make a VPN Concentrator using openbsd. I want users to be able to authenticate using usernames and passwords and to either nat the users or give them an ip from our main dhcp server via a bridge. That's a tall order. In Cisco-land

Re: VPN Concentrator

2007-11-30 Thread visc
On 30-Nov-07, at 2:13 AM, Khalid Schofield wrote: Hi, I'd like to make a VPN Concentrator using openbsd. I want users to be able to authenticate using usernames and passwords and to either nat the users or give them an ip from our main dhcp server via a bridge. If I have say a mac user at home

Re: VPN Concentrator

2007-11-30 Thread Jason Dixon
On Dec 1, 2007, at 12:37 AM, visc wrote: On 30-Nov-07, at 2:13 AM, Khalid Schofield wrote: Hi, I'd like to make a VPN Concentrator using openbsd. I want users to be able to authenticate using usernames and passwords and to either nat the users or give them an ip from our main dhcp server via

VPN Concentrator

2007-11-30 Thread Khalid Schofield
Hi, I'd like to make a VPN Concentrator using openbsd. I want users to be able to authenticate using usernames and passwords and to either nat the users or give them an ip from our main dhcp server via a bridge. If I have say a mac user at home wanting to connect into my network using

Re: VPN Concentrator

2007-11-30 Thread Lars Noodén
Khalid Schofield wrote: ... How would I know which is better to use ... Definitely not PPTP: http://www.vpnc.org/vpn-standards.html IPsec or SSL seems

Re: VPN Concentrator

2007-11-30 Thread Scott Learmonth
On 30-Nov-07, at 9:57 PM, Jason Dixon wrote: On Dec 1, 2007, at 12:37 AM, visc wrote: On 30-Nov-07, at 2:13 AM, Khalid Schofield wrote: Hi, I'd like to make a VPN Concentrator using openbsd. I want users to be able to authenticate using usernames and passwords and to either nat the users