IPSec & OpenBSD

plug-discuss@lists.PLUG.phoenix.az.us plug-discuss@lists.PLUG.phoenix.az.us
Tue, 15 May 2001 14:06:40 -0500


Well, after many hours of trying to get IPSec working, I am turning here.
Yes, I have read the man pages, reademe's etc, but to no avail.

I have two OpenBSD boxes, one at work, the other at another location.
I have created the two files for each :isakmpd.conf and isakmpd.policy
I beleive I have them exactly like the samples in 'man vpn'.
I have also ensured /etc/sysctl.conf has the line for esp uncommented and
rebooted. 

I have run isakmpd in debug mode. It appears as if there is a key exchange
and an SA set up. I guess I am expecting interface enc0 to come up, but
nothing. I have also went to the length of clearing out ipf rules
(although no packets were getting denied by tail -f /var/log/ipflog)

If someone copuld help me out here I wouild be much appreciative.
I can also post my config files if someone would like.

In the end, I would like to set up an OpenBSD box as a vpn gateway with
mobile users using PGPNet. I have read this is possible, but I would first
like to see two OpenBSD's working.

I guess I am also a bit unclear on, or if, ipnat is required to access
the private nets.

v/r
mike