Gentoo Archives: gentoo-hardened

From: Prabhat Gupta <prabhat@××××××.com>
To: Martin Bene <martin.bene@×××××××××.com>, gentoo-server <gentoo-server@g.o>, gentoo-hardened <gentoo-hardened@g.o>
Subject: Re: AW: [gentoo-hardened] Freeswan installation and setup
Date: Tue, 23 Sep 2003 15:33:52
Message-Id: 3F70649F.8060708@ascinc.com
In Reply to: AW: [gentoo-hardened] Freeswan installation and setup by Martin Bene
1 Martin,
2
3 Thanks. I will try that.
4 Do you know any tutorial on freeswan setup or any suggestions for my setup.
5
6 I have following setup:
7
8 Net A <--->Netgear router <--> cable modem ---INTERNET ---- cable modem
9 <--->Dlink router <--> Net B
10
11 In the net A, I have a gentoo machine with iptables firewall installed
12 and I am trying to install FREESWAN. The same situation is on Net B. I
13 want to setup a VPN between net A and net B.
14
15 I will appreciate any help.
16
17 Thanks
18 Prabhat
19
20
21
22 Martin Bene wrote:
23
24 >Hi Prabhat,
25 >
26 >I just went trough a comparable install about a week ago.
27 >
28 >
29 >
30 >>I am using latest gentoo-sources (~x86). I enabled the IPSec
31 >>in kernel and emerged super-freeswan. I am getting alot of errors while
32 >>
33 >>
34 >starting
35 >
36 >
37 >>the ipsec.
38 >>
39 >>
40 >
41 >I went with the stable series; installed versions:
42 > net-misc/super-freeswan-1.99_p4
43 > sys-kernel/gentoo-sources-2.4.20-r7
44 >
45 >Freeswan emerge worked as expected, no problems.
46 >
47 >firewall root # /etc/init.d/ipsec start
48 >ipsec_setup: Starting FreeS/WAN IPsec
49 >Usuper-freeswan-1.99_kb4/Ksuper-freeswan-1.99.7rc2...
50 >
51 >Startup of freeswan doesn't produce any unexpected error messages either.
52 >
53 >My configuration uses X.509 certs to allow a bunch of road warriors to
54 >connect, setup of required cert files etc followed the installation
55 >instructions for the x.509 patch found on http://www.strongsec.com/freeswan/
56 >
57 >No patches are required for the gentoo-kernel sources (they already include
58 >the suoer-freeswan patches).
59 >
60 >Bye, Martin
61 >
62 >
63 >
64 >
65
66 --
67 P r a b h a t G u p t a
68 /\/\*
69
70 Senior Software Engineer
71 Alternative System Concepts, Inc.
72 www.ascinc.com
73 22 Haverhill Road
74 Windham, NH 03087
75
76 Phone: (603) 437-2234 (o)