From: Stephen C. <scl...@ea...> - 2010-12-30 15:34:37
|
Hello, I have a couple of questions maybe someone here could answer. 1) does ipsec-tools support configuration of ipv6 ipsec tunnels? 2) is it possible to pass ipv4 packets across the ipv6 ipsec tunnels. EG. Gateway A Gateway B 192.168.1.0/24 - 2001:470:1f00:ffff::190 <- ipv6 ipsec tunnel -> 2001:470:1f00:ffff::191 - 192.168.2.0/24 private net Thanks, Steve -- "They that give up essential liberty to obtain temporary safety, deserve neither liberty nor safety." (Ben Franklin) "The course of history shows that as a government grows, liberty decreases." (Thomas Jefferson) |
From: VANHULLEBUS Y. <va...@fr...> - 2011-01-18 15:21:57
|
On Thu, Dec 30, 2010 at 10:34:29AM -0500, Stephen Clark wrote: > Hello, Hi. > I have a couple of questions maybe someone here could answer. > > 1) does ipsec-tools support configuration of ipv6 ipsec tunnels? Yes. If you have issues, please fill a bug report :-) > 2) is it possible to pass ipv4 packets across the ipv6 ipsec tunnels. Yes. If you use FreeBSD as IPsec stack, you'll need a not too old version (fixed at lease 1 year ago, iirc), as I remember we fixed a bug in PFkey interface which prevented doing such configurations. On other stacks, I never tried, but it should work too. Yvan. |
From: Stephen C. <scl...@ea...> - 2011-01-18 15:46:17
|
On 01/18/2011 10:21 AM, VANHULLEBUS Yvan wrote: > On Thu, Dec 30, 2010 at 10:34:29AM -0500, Stephen Clark wrote: > >> Hello, >> > Hi. > > > >> I have a couple of questions maybe someone here could answer. >> >> 1) does ipsec-tools support configuration of ipv6 ipsec tunnels? >> > Yes. If you have issues, please fill a bug report :-) > > > >> 2) is it possible to pass ipv4 packets across the ipv6 ipsec tunnels. >> > Yes. > > If you use FreeBSD as IPsec stack, you'll need a not too old version > (fixed at lease 1 year ago, iirc), as I remember we fixed a bug in > PFkey interface which prevented doing such configurations. > > On other stacks, I never tried, but it should work too. > > > Yvan. > > > Thanks for the response - we will be using linux ipsec-tools 0.7.2 Are there plans for making an 0.8.x official release soon? News: 2009-04-22 IPsec-tools 0.7.2 released -- "They that give up essential liberty to obtain temporary safety, deserve neither liberty nor safety." (Ben Franklin) "The course of history shows that as a government grows, liberty decreases." (Thomas Jefferson) |
From: Stefan B. <ste...@cu...> - 2011-01-18 15:51:23
|
Am 18.01.2011 16:46, schrieb Stephen Clark: > 2009-04-22 > IPsec-tools 0.7.2 released ouch - this news is not up to date. Currently stable is 0.7.3 cheers -- Stefan Bauer ----------------------------------------- PGP: 36D1 1570 DCAD B767 EABE F60D 6BCA 7AD4 79EB C4EC -------- plzk.de - Linux - because it works ---------- |
From: VANHULLEBUS Y. <va...@fr...> - 2011-01-18 15:58:46
|
On Tue, Jan 18, 2011 at 10:46:09AM -0500, Stephen Clark wrote: [...] > Are there plans for making an 0.8.x official release soon? yes :-) We were planning to release it at the end of 2010, and we're a bit late (mostly my fault). We should release a beta1 really soon. Yvan. |
From: Stephen C. <scl...@ea...> - 2011-01-18 18:32:28
|
On 01/18/2011 10:58 AM, VANHULLEBUS Yvan wrote: > On Tue, Jan 18, 2011 at 10:46:09AM -0500, Stephen Clark wrote: > [...] > >> Are there plans for making an 0.8.x official release soon? >> > yes :-) > > We were planning to release it at the end of 2010, and we're a bit > late (mostly my fault). > We should release a beta1 really soon. > > > Yvan. Thanks for the effort you put in. Regards, Steve |