OpenBSD Journal

Tip of the Trade: Easy IPSec

Contributed by dwc on from the man ipsec.conf(5) dept.

Internet.com's ServerWatch has discovered how easy IPSec can be and did a very brief write-up in Tip of the Trade: Easy IPSec.

From the article:

Setting up an open source IPSec implementation has traditionally been difficult and complex, to the point that as a security solution it almost doesn't make sense. Even high-end commercial implementations tend to cause hair loss and frustration. But finally, there is an open source IPSec implementation that is easy to administer, free of cost and based on a high-quality secure operating system: OpenBSD.

The article also mentions Zero to IPSec in 4 minutes, where the same conclusions were reached almost exactly a year ago. Nice to see easy IPSec is still important today. ;)

(Comments are closed)


Comments
  1. By vpn in blue (86.91.41.86) on

    and so I am setting up a VPN network with OBSD around the world at this very time (all out operating company's are being connected).
    About 15 locations from Canada,Europe,middele east,far east and Aussies.

    It takes a little more then 4 min :-) but in 5 it is done :-)

    To make it more fun, all the OBSD VPN boxes are fitted with blue-neon light internally (casemodding). Complete waste of time and utherly pointless, I know...but boy do those OBSD boxes stand out :-))





    Comments
    1. By Anonymous Coward (68.104.220.48) on

      > and so I am setting up a VPN network with OBSD around the world at this very time (all out operating company's are being connected).
      > About 15 locations from Canada,Europe,middele east,far east and Aussies.
      >
      > It takes a little more then 4 min :-) but in 5 it is done :-)
      >
      > To make it more fun, all the OBSD VPN boxes are fitted with blue-neon light internally (casemodding). Complete waste of time and utherly pointless, I know...but boy do those OBSD boxes stand out :-))

      Any chance you can get your organization to donate some percentage of their cost savings to the project?

      VPNs are an easy win because commercial solutions on the level of OpenBSD tend to cost exhorbant amounts of money and deliver inferior scalability (and tend to cost even more for the HA you get from pfsync + sasync). Not to mention outrageous prices on support contracts. Coupled with the pretty blinking blue lights, you ought to be able to make a pretty good case to management...

    2. By Anonymous Coward (24.37.236.100) on

      > and so I am setting up a VPN network with OBSD around the world at this very time (all out operating company's are being connected).
      > About 15 locations from Canada,Europe,middele east,far east and Aussies.
      >
      > It takes a little more then 4 min :-) but in 5 it is done :-)
      >
      > To make it more fun, all the OBSD VPN boxes are fitted with blue-neon light internally (casemodding). Complete waste of time and utherly pointless, I know...but boy do those OBSD boxes stand out :-))
      >

      Where in Canada? Are they hiring? :-)

    3. By Anonymous Coward (202.45.125.5) on

      > and so I am setting up a VPN network with OBSD around the world at this very time (all out operating company's are being connected).
      > About 15 locations from Canada,Europe,middele east,far east and Aussies.

      Where in Australia? Are they hiring? :-)

  2. By ed (190.24.115.46) emoranb@hotmail.com on

    I need one example of ipsec.conf and the config in win xp. i dont find one site.

    thanks

    Comments
    1. By Anonymous Coward (24.37.236.100) on

      > I need one example of ipsec.conf and the config in win xp. i dont find one site.
      >
      > thanks


      If you get it elsewhere and working, please post...

    2. By Joachim Schipper (Joachim) on

      > I need one example of ipsec.conf and the config in win xp. i dont find one site.

      Search the misc@ archives, this has been asked many, many times.

          Joachim

      Comments
      1. By sthen (85.158.44.148) on

        > I need one example of ipsec.conf and the config in win xp. i dont find one site.
        >
        > Search the misc@ archives, this has been asked many, many times.

        The answers are a bit variable though and it can take a bit of digging. Try this. (btw, for those who don't know: Windows' built-in-easy-gui-wizard-way uses L2TPv2-over-IPSEC, I don't think there's a decent L2TP implementation running on OpenBSD).

        Comments
        1. By Motley Fool (MotleyFool) on

          > > I need one example of ipsec.conf and the config in win xp. i dont find one site.
          > >
          > > Search the misc@ archives, this has been asked many, many times.
          >
          > The answers are a bit variable though and it can take a bit of digging. Try


          The link to ""smartvpn dial-up connection management" from draytek." in the linked post is broken, try the following instead: ftp://ftp.draytek.com/tools/VPN/3.2.5/VPN.zip

  3. By Tom H. (63.231.163.138) tmh.public@gmail.com on

    I setup and used a VPN from an OpenBSD gateway to a FreeBSD gateway between home and work. It was great, although getting the x509 certificates correct was a bit of a pain. After a while, though, I realized it was overkill and started using port forwarding over SSH. When a VPN is overkill for your application, you can still get great security with SSH.

Credits

Copyright © - Daniel Hartmeier. All rights reserved. Articles and comments are copyright their respective authors, submission implies license to publish on this web site. Contents of the archive prior to as well as images and HTML templates were copied from the fabulous original deadly.org with Jose's and Jim's kind permission. This journal runs as CGI with httpd(8) on OpenBSD, the source code is BSD licensed. undeadly \Un*dead"ly\, a. Not subject to death; immortal. [Obs.]