12.07.2015 Views

download

download

download

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Network Configuration—TunnelingOnce the policies are configured, you may enable automatic IPSec setup from the/etc/rc.conf file by adding the following lines:ipsec_enable="YES"ipsec_file="/etc/ipsec.conf"Note that you do not have to specify the second line, as it points to /etc/ipsec.conf, by default. It is only needed if you have chosen a different name for yoursetkey configuration file.You should manually load security policies by running the following ipsec rc script:# /etc/rc.d/ipsec startInstalling ipsec manual keys/policies.You are almost done. You should check the following three steps to make sureeverything is in place:1. Check the status if gif tunnel is using the ifconfig utility.2. Check whether racoon daemon is running and is listening on udp 500, usingthe sockstat –l4 command.3. Check whether the setkey policies that you defined are actually installedusing the setkey –DP command.If appropriate policies are installed, the output of the setkey –DP command shouldlook like the following command line:# setkey -DP0.0.0.0/0[any] 0.0.0.0/0[any] ip4in ipsecesp/transport//requirecreated: Jun 23 23:41:41 2007 lastused: Jun 23 23:41:41 2007lifetime: 0(s) validtime: 0(s)spid=16435 seq=1 pid=1534refcnt=10.0.0.0/0[any] 0.0.0.0/0[any] ip4out ipsecesp/transport//requirecreated: Jun 23 23:41:41 2007 lastused: Jun 23 23:41:41 2007lifetime: 0(s) validtime: 0(s)spid=16434 seq=0 pid=1534refcnt=1[ 142 ]

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!