From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Babar Kazmi" Subject: Re: Routing a VPN.....confused Date: Mon, 15 Dec 2003 10:02:22 +0500 Sender: netfilter-admin@lists.netfilter.org Message-ID: Mime-Version: 1.0 Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable To: lists@spenneberg.org, mbrei@carolina.rr.com Cc: netfilter@lists.netfilter.org

Dear Ralf

Although it was not related to me but your site, http://www.spenneberg.com
really helped me out in some of my pending issues :)

Thank you.

Regards

 

Babar Kazmi.

 

>Am Son, 2003-12-14 um 03.24 schrieb Matt Brei:
> > Hi all,=20
> >=20
> > I'm trying to set up a VPN with my buddy back in Chica= go.  We're both=20
> > using iptables to nat our Internet connection to the r= est of the LAN and=20
> > filter out all the naughtiness on the cable modem conn= ection.  So far,=20
> > we've tried FreeS/WAN on the iptables routers, but as = soon as we start=20
> > the ipsec service, it kills the Internet connection.=20
>This sounds pretty much like a configuration issue using fre= eswan >=3D=20
>2.0. FreeS/WAN enables opportunistic encryption (OE) by defa= ult. This=20
>may interrupt your Internet connections since it tries to en= crypt=20
>everything by default. It uses policy groups for this. You p= robably have=20
>to disable these policy groups.=20
>=20
>Take a look at:=20
>http://www.freeswan.org/freeswan_trees/freeswan-2.04/doc/pol= icygroups.html#disable_policygroups=20
>=20
>Cheers,=20
>=20
>Ralf=20
>--=20
>Ralf Spenneberg=20
>RHCE, RHCX=20
>=20
>Book: VPN mit Linux=20
>Book: Intrusion Detection f=FCr Linux Server   htt= p://www.spenneberg.com=20
>IPsec-Howto      http://www.ipsec-howto.= org=20
>Honeynet Project Mirror:      =             &nb= sp;  http://honeynet.spenneberg.org=20
>=20


The new
MSN 8: smart spam protection and 2 months= FREE*