Subject: Re: ipsec tunnels with one end fixed, other dynamic
To: Bill Studenmund <wrstuden@netbsd.org>
From: Paul Dokas <dokas@smtp.mn.mediaone.net>
List: tech-net
Date: 01/15/2002 20:52:03
On Tue, Jan 15, 2002 at 03:45:48PM -0800, Bill Studenmund wrote:
> Has anyone gotten this working?
>
> The idea is I have a laptop, and when I'm out on the road, it sets up a
> vpn to my house. I know I'd have to do something like have certificates
> set up.
Yes, I've gotten it working. I'm even using certificates to identify the
endpoints. However, using racoon to negotiate my keys, my fixed endpoint
panics on a regular basis. Apparently, there's a rather substantial bug
in the kernel somewhere. See kern/13813 for some details.
BTW, I'll gladly share my configuration files. Especially if it means
that someone will fix that bug ;-)
Paul
--
Paul Dokas dokas@cs.umn.edu
======================================================================
Don Juan Matus: "an enigma wrapped in mystery wrapped in a tortilla."