Subject: Re: ipsec tunnels with one end fixed, other dynamic
To: Bill Studenmund <wrstuden@netbsd.org>
From: Paul Dokas <dokas@smtp.mn.mediaone.net>
List: tech-net
Date: 01/15/2002 20:52:03
On Tue, Jan 15, 2002 at 03:45:48PM -0800, Bill Studenmund wrote:
> Has anyone gotten this working?
> 
> The idea is I have a laptop, and when I'm out on the road, it sets up a
> vpn to my house. I know I'd have to do something like have certificates
> set up.

Yes, I've gotten it working.  I'm even using certificates to identify the
endpoints.  However, using racoon to negotiate my keys, my fixed endpoint
panics on a regular basis.  Apparently, there's a rather substantial bug
in the kernel somewhere.  See kern/13813 for some details.

BTW, I'll gladly share my configuration files.  Especially if it means
that someone will fix that bug ;-)

Paul
-- 
Paul Dokas                                            dokas@cs.umn.edu
======================================================================
Don Juan Matus:  "an enigma wrapped in mystery wrapped in a tortilla."