Hi,
does anyone have an experience how many IPSec tunnels Solaris 10 is able manage. A rough estimation would be great.
I know it's hardly dependent on the hardware used, so if anyone says on a 490 with 2 CPUs and 4GB RAM a maximum of 1000 IPSec tunnels is possible, that would be great.
I... (1 Reply)
Hello,
I have configured IPSEC between two AIX Server v5.2 using IKE transport. When I try to transfer a files from one server to another, it is very very slow and the file transfer has been terminated after 25% completes. How to overcome this problem? Please advsie. Thanks (0 Replies)
Hello,
I'm trying to setup a gateway VPN between two routers across an unsecured network between two local networks. The routers are both linux and I'm using the ipsec tools, racoon and setkey. So far hosts from either local net can successfully ping hosts on the other local net without issue.
... (0 Replies)
Hi,
I am trying to set a policy between 2 machines for all the ports except for 22 i.e. for tcp - basically I want to bypass ssh. But my policy doesn't seem to work. Here are the entries
spdadd 1.2.3.4 4.3.2.1 any -P out prio 100 ipsec esp/transport//require ah/transport//require;
spdadd... (0 Replies)
Hi, this is my first post...:p
Hello Admin :)
Can I have an ask for something with my configuration ?
I have finished some kind of the tutorial to build ipsec site to site, and the "step" has finished completely.
I have a simulation with a local design topology with two PC's (FreeBSD ... (0 Replies)
hello,
after configuration ipsec in ip4 I can not ping between client and server whereas I had success ping before configuration!
I also generate different key for AH and ESP as i have shown below.
what is my problem and what should i do to have ping and test the configuration?
code:
... (0 Replies)
Hi Guys,
Please could you tell me if it is possible to have a single rule/filter to allow a certain port range instead of a separate rule for each port?
I'm sure it must be possible but I am unable to find the syntax.
Thanks
Chris (4 Replies)
Hi ! all I am just trying to check range in my datafile
pls tell me why its resulting wrong
admin@IEEE:~/Desktop$ cat test.txt
0 28.4
5 28.4
10 28.4
15 28.5
20 28.5
25 28.6
30 28.6
35 28.7
40 28.7
45 28.7
50 28.8
55 28.8
60 28.8
65 28.1... (2 Replies)
Hi all,
I have installed Openswan and configured IPSec and works perfect, but for some unknown reasons it stop working. I see that the tunnels are up and established. The route to the destination are added. Everything by the book seems to be ok. But somehow when i start to ping the other side (... (4 Replies)
Discussion started by: ivancd
4 Replies
LEARN ABOUT CENTOS
ipsec_addconn
IPSEC_ADDCONN(8) Executable programs IPSEC_ADDCONN(8)NAME
ipsec_addconn - load a given policy into the pluto IKE daemon
SYNOPSIS
ipsec addconn --configsetup [--rootdir dir] [--config filename] [--ctlbase socketfile] [--verbose] [--noexport] [--warningsfatal]
ipsec addconn --liststack [--rootdir dir] [--config filename] [--ctlbase socketfile] [--verbose] [--noexport] [--warningsfatal]
ipsec addconn --checkconfig [--rootdir dir] [--config filename] [--ctlbase socketfile] [--verbose] [--warningsfatal]
ipsec addconn --autoall [--rootdir dir] [--config filename] [--ctlbase socketfile] [--verbose] [--warningsfatal] [--defaultroute addr]
[--defaultroutenexthop addr]
ipsec addconn [--rootdir dir] [--config filename] [--ctlbase socketfile] [--verbose] [--warningsfatal] [--defaultroute addr]
[--defaultroutenexthop addr] name1 [name2 ..]
ipsec addconn [--listall] [--liststart] [--listroute] [--listadd] [--listignore] [--rootdir dir] [--config filename] [--ctlbase socketfile]
[--verbose] [--warningsfatal]
ipsec addconn --help
DESCRIPTION
ipsec addconn takes a config file (or stdin) containing the format of ipsec.conf, or the format of individual "conn" sections, and uses
that information to load named or all connections defined in that configuration file into the running libreswan pluto IKE daemon. If no
configuration file is specified, the default configuration file is used. If no pluto socket is specified, the default socket location will
be used.
When --addall is used, all connections defined in the config file will be operated on. Otherwise, only the specified connection names will
be affected.
When addcon is run, connections that have the auto= option set to add, start or route will be loaded, routed or initiated. If a connection
was loaded or initiated already, it will be replaced.
When --configsetup is specified, the configuration file is parsed for the config setup section and printed to the terminal usable as a
shell script. These are prefaced with export unless --noexport is specified.
When --checkconfig is specified, the configuration file is parsed and all sections are checked for correct syntax. If an error is found,
information about it is printed to the terminal.
When --listroute or --liststart is specified, no connections are added or replaced, only shown. This command can be used to verify which
connections the addcon command would act upon, without actually performing any action.
HISTORY
Man page written for the Libreswan project <http://www.libreswan.org/> by Paul Wouters
AUTHOR
Paul Wouters
placeholder to suppress warning
libreswan 12/16/2012 IPSEC_ADDCONN(8)