Building VPNs with OpenBSD and IPSEC

Found a new blog post from a recent tweet by @knightgats. Check out his tutorial on setting up your own site-to-site VPN with OpenBSD IPSec. This is well-covered territory, but it never hurts to see a refresher for new users.

The author walks thorugh all steps of:

  • Enabling the IPSec protocols in /etc/sysctl.conf
  • Creating your /etc/ipsec.conf rules
  • Filtering the IPSec traffic with PF
  • Synchronizing your IPSec host keys
  • Troubleshooting your connection

  1. By tdm (tdm) on

    Fantastic stuff! Any chance of seeing an IKEv2 / iked(4) howto? I've played around with it but couldn't get the EAP authentication working. I know it's still fairly new, though.


