Re: site-to-site vpn 4.0 to cisco 3000

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: c l <lahrcm@...>
Cc: <misc@...>
Date: Sunday, February 25, 2007 - 10:16 pm

On further study of the iskampd.conf man page, I am thinking that you
may be correct by turning you attention to the isakmpd.conf as a
possible trouble spot.

I notice that you specified group mod768 (Diffie -Hellman group 1)in
your ipsec statements. As I said, not having had occasion to run a
VPN before using OpenBSD as an endpoint, I am having to generalize
from all the other VPN setups that I have done. Generally, the
Diffie-Hellman group is only relevant in two places, one being the
'main' mode for phase 1 and the other being for PFS in phase 2 (-if-
PFS is enabled). I see that the isakmpd normally uses DH2 by default
for 'main' mode (so claims the man page), and this can be defined
otherwise (e.g. DH 1) if preferred. I -suspect- that the DH group
specified in the ipsecd.conf is not relevant to 'main' mode; it is
perhaps used only when PFS is configured.
So a possible problem might be that site #1 is using DH 2 for its
proposal and an edit to isakmpd.conf may be the solution. Or, an
alternative might be to reconfigure the VPN 3000 to use DH 2. If you
have PFS enabled, deconfigure it for now in order to simplify
things. Once you've got the VPN running, you can play around with
PFS enablement if you really need it.

I'm afraid I'm a bit hindered by having not used OpenBSD in any of
the 70+ VPNs I've set up in the past. Mostly, I've worked with
CheckPoint, Juniper, Cisco routers/PIX/ASA/VPN300, SonicWall, Nortel,
and LinkSys. None of my customers have selected OpenBSD for VPN, yet.

Bill

On Feb 25, 2007, at 14:48, c l wrote:

> Hello, thanks for the reply, it helped if I'm not mistaken. I

--
William Bloom
williambloom@mac.com

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
site-to-site vpn 4.0 to cisco 3000, c l, (Sun Feb 25, 1:23 pm)
Re: site-to-site vpn 4.0 to cisco 3000, William Bloom, (Sun Feb 25, 5:02 pm)
Re: site-to-site vpn 4.0 to cisco 3000, c l, (Sun Feb 25, 5:48 pm)
Re: site-to-site vpn 4.0 to cisco 3000, William Bloom, (Sun Feb 25, 10:16 pm)
Re: site-to-site vpn 4.0 to cisco 3000, William Bloom, (Sun Feb 25, 9:53 pm)
Re: site-to-site vpn 4.0 to cisco 3000 SOLVED, Claer, (Mon Feb 26, 5:02 am)
Re: site-to-site vpn 4.0 to cisco 3000 SOLVED, William Bloom, (Sun Feb 25, 10:19 pm)