Subject: Re: FreeS/WAN <-> KAME
To: None <netbsd-users@netbsd.org>
From: Noah L. Meyerhans <frodo@morgul.net>
List: netbsd-users
Date: 09/10/2002 14:14:06
--JSkcQAAxhB1h8DcT
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Mon, Sep 09, 2002 at 06:13:10PM -0400, Jan Schaumann wrote:
> I've been trying to follow these examples, but when I start ipsec on the
> Linux-site, it seems to try to use IPsec for all communication (I only
> want it to talk to the NetBSD machine at a certain port using IPsec).
> At the same time, on the NetBSD side, connections to the specified port
> on the Linux machine time out; racoon complains:

I don't think FreeS/WAN allows port-specific security assiciations.

I documented the process of getting FreeS/WAN and KAME to interoperate
at http://web.morgul.net/~frodo/docs/kame+freeswan_interop.html.  Most
of the documentation focuses on X.509 authentication between the two
IKE daemons, but you may still find it useful.

noah

--=20
 _______________________________________________________
| Web: http://web.morgul.net/~frodo/
| PGP Public Key: http://web.morgul.net/~frodo/mail.html=20

--JSkcQAAxhB1h8DcT
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE9fjZtYrVLjBFATsMRAgUwAJwL5TOaggjhCuw+Oi+hAFDBQi3NgACffMQz
TYV+xHWaK+9BaS608wx5e4k=
=ufHF
-----END PGP SIGNATURE-----

--JSkcQAAxhB1h8DcT--