NetBSD-Users archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: IKEv2/IPsec VPN



On 9/20/2017 5:12 PM, Christos Zoulas wrote:
In article <e8da578e-c03b-7ae6-3062-b0da729dc179%gmail.com@localhost>,
Chuck Zmudzinski  <frchuckz%gmail.com@localhost> wrote:
I have used netbsd-6 and netbsd-7 with racoon to set up IKEv1/L2TP/IPsec
VPN with Windows clients. I have not tried IKEv2 and based on the little
research I have done I don't think it is possible using an out of the box
NetBSD/pkgsrc configuration. Even for IKEv1 I needed to hack the NetBSD
kernel to get IKEv1 and IPsec NAT-traversal to work with IPsec, and I used
a locally modified version of the ancient and apparently no longer
maintained rp-l2tp package to set up l2tp tunnels. If you don't need NAT
traversal, that is, if neither clients nor the server are behind a NAT box,
it might be easier to do...
In current and 8 it should work out of the box...

https://wiki.netbsd.org/tutorials/how_to_create_an_l2tp_ipsec_tunnel_between_an_android_or_iphone_or_ios_device_to_netbsd/

christos
I will try 8 and current and post my result in the next few days. I also will try racoon2 with IKEv2 sometime with 8 and current. As I understand it, racoon2 is in pkgsrc. It's also good to know xl2tpd works for l2tp/ipsec. I have been planning on trying it instead of using the
ancient rp-l2tp.

Chuck


Home | Main Index | Thread Index | Old Index