12.07.2015 Views

download

download

download

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Network Configuration—TunnelingThe racoon2 utility (available online at http://www.racoon2.wide.ad.jp/) is anadvanced IKE daemon that supports IKEv1 (defined in RFC 2407, 2408, 2409, and4109), IKEv2 (defined in RFC 4306), and Kerberized Internet Negotiation of Keys(KINK, defined in RFC 4430) key exchange protocols. It can be installed from portscollection and is located at /usr/ports/security/racoon2.However, there is another IKE daemon that does not support IKEv2 and newerprotocols, but is very easy to set up and configure, which is called ipsec-tools(/usr/ports/security/ipsec-tools). The ipsec-tools utility, which isbasically a fork from the original racoon project, offers basic key exchange usingIKEv1 protocols and shares the same configuration syntax with the originalracoon daemon.In order to configure the racoon daemon, you should first set up ipsec-tools andcreate appropriate configuration files as follows:# cd /usr/ports/security/ipsec-tools && make install cleanOnce the software is installed, you should create a configuration file based on theinstalled sample configuration files:# mkdir /usr/local/etc/racoon# cp /usr/local/share/examples/ipsec-tools/racoon.conf.sample /usr/local/etc/racoon/racoon.confNow you should edit the configuration file to fit your specific requirements. Asample racoon.conf file looks like the following code:path pre_shared_key "/usr/local/etc/racoon/psk.txt" ;remote anonymous{exchange_mode aggressive;lifetime time 24 hour ;proposal{encryption_algorithm 3des;hash_algorithm sha1;authentication_method pre_shared_key ;dh_group 2 ;}}sainfo anonymous{pfs_group 2;lifetime time 12 hour ;[ 140 ]

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!