Subject: Re: IPsec configuration issues
From: Michael Richardson <>
Date: 03/12/2000 22:27:05
Subject: Re: IPsec configuration issues 
Date: Sun, 12 Mar 2000 22:27:05 -0500
From: Michael Richardson <>

>>>>> "Jason" == Jason R Thorpe <> writes:
    Jason> There's not an obvious way to do this from what's documented in the
    Jason> setkey(8) and racoon(8) manual pages.

    Jason> Any experts on these programs have some suggestions?

  I have spent some 15 days doing it as paid work, and I can't say that I'm
an expert yet. I assume that you are using the more recent code (the recently 
integrated -STABLE).
  My recommendations:
     1) setup of racoon at each end.
     2) test with

     ping -E 'out ipsec esp/transport/A-B/require' B

  I do not believe that there is a way to describe the policy that you want yet.

