Hi,
does anyone have an experience how many IPSec tunnels Solaris 10 is able manage. A rough estimation would be great.
I know it's hardly dependent on the hardware used, so if anyone says on a 490 with 2 CPUs and 4GB RAM a maximum of 1000 IPSec tunnels is possible, that would be great.
I... (1 Reply)
Hello,
I have configured IPSEC between two AIX Server v5.2 using IKE transport. When I try to transfer a files from one server to another, it is very very slow and the file transfer has been terminated after 25% completes. How to overcome this problem? Please advsie. Thanks (0 Replies)
Hello,
I'm trying to setup a gateway VPN between two routers across an unsecured network between two local networks. The routers are both linux and I'm using the ipsec tools, racoon and setkey. So far hosts from either local net can successfully ping hosts on the other local net without issue.
... (0 Replies)
Hi,
I am trying to set a policy between 2 machines for all the ports except for 22 i.e. for tcp - basically I want to bypass ssh. But my policy doesn't seem to work. Here are the entries
spdadd 1.2.3.4 4.3.2.1 any -P out prio 100 ipsec esp/transport//require ah/transport//require;
spdadd... (0 Replies)
Hi, this is my first post...:p
Hello Admin :)
Can I have an ask for something with my configuration ?
I have finished some kind of the tutorial to build ipsec site to site, and the "step" has finished completely.
I have a simulation with a local design topology with two PC's (FreeBSD ... (0 Replies)
hello,
after configuration ipsec in ip4 I can not ping between client and server whereas I had success ping before configuration!
I also generate different key for AH and ESP as i have shown below.
what is my problem and what should i do to have ping and test the configuration?
code:
... (0 Replies)
Hi Guys,
Please could you tell me if it is possible to have a single rule/filter to allow a certain port range instead of a separate rule for each port?
I'm sure it must be possible but I am unable to find the syntax.
Thanks
Chris (4 Replies)
Hi ! all I am just trying to check range in my datafile
pls tell me why its resulting wrong
admin@IEEE:~/Desktop$ cat test.txt
0 28.4
5 28.4
10 28.4
15 28.5
20 28.5
25 28.6
30 28.6
35 28.7
40 28.7
45 28.7
50 28.8
55 28.8
60 28.8
65 28.1... (2 Replies)
Hi all,
I have installed Openswan and configured IPSec and works perfect, but for some unknown reasons it stop working. I see that the tunnels are up and established. The route to the destination are added. Everything by the book seems to be ok. But somehow when i start to ping the other side (... (4 Replies)
Discussion started by: ivancd
4 Replies
LEARN ABOUT CENTOS
ipsec_tncfg
IPSEC_TNCFG(8) Executable programs IPSEC_TNCFG(8)NAME
ipsec_tncfg - manipulate KLIPS virtual interfaces
SYNOPSIS
ipsec tncfg
ipsec tncfg --create virtual
ipsec tncfg --delete virtual
ipsec tncfg --attach --virtual virtual --physical physical
ipsec tncfg --detach --virtual virtual
ipsec tncfg --clear
ipsec tncfg --version
ipsec tncfg --help
KLIPS
Note that tncfg is only supported on the KLIPS stack which uses ipsecX interfaces bound to physical interfaces
DESCRIPTION
The purpose of tncfg is to attach/detach IPsec virtual interfaces (e.g. ipsec0) to/from physical interfaces (e.g. eth0) through which
packets will be forwarded once processed by KLIPS.
When using the MAST stack, tncfg is used to create and delete virtual interfaces known as mastXXX. mast stands for Mooring and XXX.
The form with no additional arguments lists the contents of /proc/net/ipsec_tncfg. The format of /proc/net/ipsec_tncfg is discussed in
ipsec_tncfg(5).
The --attach form attaches the virtual interface to the physical one.
The --detach form detaches the virtual interface from whichever physical interface it is attached to.
The --clear form clears all the virtual interfaces from whichever physical interfaces they were attached to.
Virtual interfaces typically have names like ipsec0 or mast0 while physical interfaces typically have names like eth0 or ppp0.
EXAMPLES
ipsec tncfg --create mast12
creates the mast12 device.
ipsec tncfg --create ipsec4
creates an ipsec4 device, but does not attach it.
ipsec tncfg --attach --virtual ipsec0 --physical eth0
attaches the ipsec0 virtual device to the eth0 physical device.
FILES
/proc/net/ipsec_tncfg, /usr/local/bin/ipsec
SEE ALSO ipsec(8), ipsec_manual(8), ipsec_eroute(8), ipsec_spi(8), ipsec_spigrp(8), ipsec_klipsdebug(8), ipsec_tncfg(5)HISTORY
Written for the Linux FreeS/WAN project <http://www.freeswan.org/> by Richard Guy Briggs.
AUTHOR
Paul Wouters
placeholder to suppress warning
libreswan 12/16/2012 IPSEC_TNCFG(8)