iked vs. isakmpd + carp

2012-10-19 Thread Jim Miller
Two part question: 1. Anyone had any success getting iked and carp working on OpenBSD 5.1 (amd64)? We can get it working with isakmpd. The issue seems to be that iked wants to send out packets as the physical interface IP instead of the carp IP. iked documentation eludes to the fact that it

Re: iked vs. isakmpd + carp

2012-10-19 Thread Tyler Morgan
On 10/19/2012 1:16 AM, Jim Miller wrote: Two part question: 1. Anyone had any success getting iked and carp working on OpenBSD 5.1 (amd64)? We can get it working with isakmpd. The issue seems to be that iked wants to send out packets as the physical interface IP instead of the carp IP. iked

Re: iked vs. isakmpd + carp

2012-10-19 Thread Reyk Floeter
Hi, On Fri, Oct 19, 2012 at 8:10 PM, Tyler Morgan tyl...@tradetech.net wrote: On 10/19/2012 1:16 AM, Jim Miller wrote: Two part question: 1. Anyone had any success getting iked and carp working on OpenBSD 5.1 (amd64)? We can get it working with isakmpd. The issue seems to be that iked

Re: iked vs. isakmpd + carp

2012-10-19 Thread mxb
I think this can be fixed by: shell# cat /etc/isakmpd/isakmpd.conf [General] Listen-on= 1.2.3.4 I runs this setup in prod. It works. In my case 1.2.3.4 is a CARP:ed IP. //mxb On 19 okt 2012, at 20:10, Tyler Morgan tyl...@tradetech.net wrote: isakmpd wants to use the IP from the real

Re: iked vs. isakmpd + carp

2012-10-19 Thread Jim Miller
Thanks Reky. I'll stick with isakmp for now but would like to swtich to iked when its ready. BTW. Any known issues with isakmp and groups larger than modp1024? I still can't get isakmpd to use anything larger than that? -Jim On 10/19/12 3:35 PM, Reyk Floeter wrote: Hi, On Fri, Oct 19,