Project

General

Profile

Download (38.3 KB) Statistics
| Branch: | Tag: | Revision:

# Date Author Comment
372d28b0 06/03/2009 05:58 AM Seth Mos

Eventhough you can set the racoon admin socket to a different path in the configuration it will be ignored by ipsec-tools 0.8+
Align all the sockets into the new path /var/db/racoon so that we can find it.
Remove the old killall -HUP racoon as this prevents the newer racoon from properly loading it's initial configuration. This might actually also have been a possible problem on the old ipsec-tools...

3283437d 06/02/2009 10:36 PM Scott Ullrich

Oops, make that /bin/mkdir

47c13f03 05/31/2009 08:36 PM Chris Buechler

fix static route deletion

08d591b5 05/30/2009 08:51 PM Scott Ullrich

Ensure /var/db/racoon exists

0958770c 04/06/2009 12:35 AM Chris Buechler

Since they're listed by name, order alphabetically.

c1285ca6 03/26/2009 05:27 AM Chris Buechler

Change log message. This doesn't necessarily mean the IP has changed, so it was misleading.

12df13d4 03/26/2009 05:15 AM Chris Buechler

Log actual interface rather than CARP interface

e28d3bb3 03/23/2009 09:36 PM Scott Ullrich

Ensure dpddelay is a value, not that its simply set leading to racoon.conf errors:

my /var/etc/racoon.conf file has: "dpd_delay ;"

Reported in ##pfSense on FreeNODE by Overrand

310b1aa7 03/15/2009 04:44 AM Chris Buechler

Prevent creation of invalid racoon.conf with omitted or non-numeric DPD delay.

6ae008d9 03/13/2009 06:48 AM seth

Add the DPD option to the mobile ipsec page. The DPD option makes the most sense for the mobile IPSEC clients as this is
helps cleaning up any dangling SA entries before their lifetime expires.
The default value is 120 seconds.
Move the NAT-T into the actual layout instead of on top of it.

563c9ca9 03/13/2009 03:33 AM seth

Add DPD backend configuration to the racoon configuration.

be7b496c 03/13/2009 03:08 AM seth

Use NAT-T when enabled on a per tunnel basis

e5cd25db 02/14/2009 08:19 PM Chris Buechler

changes from smos@

413273aa 02/09/2009 02:35 AM Chris Buechler

Initial changes for NAT-T

554e2211 02/01/2009 12:35 AM Chris Buechler

fix for IPsec timeouts/issues with large frames

2c64a07a 01/16/2009 08:28 AM Seth Mos

Make sure we match the right SPI to src and dst address, otherwise the purge of the old
spi fails.

bf92bc79 01/15/2009 09:00 AM Seth Mos

- Add proper support for using hostnames for the remote IPsec gateway.
- Make IPsec reloading granular, this resolves the long standing issue
that a IPsec reload will cause all tunnels to drop.
- Change IPsec edit screen description for remote gateway that a IP...

37c99423 01/05/2009 08:58 PM Scott Ullrich

Include IPSEC reload patch from Seth Mos which was tested on his work
IPSEC cluster.

82d046c5 11/19/2008 05:27 AM Scott Ullrich

Do not destroy enc0

f44fe780 11/09/2008 03:18 AM Scott Ullrich

Remove newlines at end of files

6e867889 11/07/2008 06:25 AM Seth Mos

Correct path to netstat

e9569d37 11/06/2008 03:40 PM Seth Mos

Correct Route lookup

a7ddc539 11/06/2008 03:25 PM Seth Mos

Surpress enc0 creation

7d0e5565 11/06/2008 01:00 PM Seth Mos

Lookup remote endpoint in routing table before attempting to delete route.

ba1e7572 11/06/2008 12:34 PM Seth Mos

Mute killall commands

65732d96 11/03/2008 01:31 PM Seth Mos

Extra sighup not needed on 7

92525855 10/04/2008 11:56 PM Chris Buechler

add missing quotes in mobile IPsec my_identifier

6f00d853 09/22/2008 04:40 AM Chris Buechler

missing spaces for mobile IPsec

f5780da7 09/06/2008 08:44 PM Seth Mos

Check in fix that hopefully fixes IPSEC on pppoe or pptp

2de2f25c 09/01/2008 09:15 AM Seth Mos

Disable DPD per default. It is not always safe and can result in
flapping tunnels.

cff1543c 08/17/2008 08:53 PM Seth Mos

attempt to fix ipsec for carp interfaces. Please test!

25bf86b1 08/17/2008 08:22 PM Seth Mos

Switch over to ipsec-tools setkey preferred over the native FreeBSD setkey

e739d9a5 07/25/2008 09:46 PM Scott Ullrich

Use /sbin/setkey

9f8b7ccb 07/08/2008 07:27 PM Seth Mos

Change /sbin/setkey to ipsec-tools /usr/local/sbin/setkey

9de90743 06/07/2008 02:09 AM Chris Buechler

The physical interface must be passed to find_interface_ip()

this was breaking the racoon.conf for OPT WAN IPsec when interface is not statically addressed

ce24ce9a 06/06/2008 02:24 PM Seth Mos

Correctly process non carp interfaces

c65fc017 06/06/2008 02:10 PM Seth Mos

Correctly update static routes on change

20fdc10f 06/05/2008 08:51 AM Seth Mos

Make the vpn configuration add static routes on interfaces other then WAN.
link_carp_interface_to_parent() now correctly returns parent interface instead of always WAN.

3eee46dc 05/17/2008 02:16 AM Scott Ullrich

Do not quote an empty string when the DN identifier is blank.

Obtained-from: m0n0wall

2133e06a 04/10/2008 08:10 AM Seth Mos

bump dpd from 20 to 120

b844d9b2 04/05/2008 10:20 PM Seth Mos

Use DPD and frag support we already have

45658a0e 04/01/2008 09:18 PM Seth Mos

MFC: Send extra sighup after starting
Might fix mobile ipsec after startup

73a98657 02/05/2008 09:11 AM Seth Mos

With the current Racoon we need to inform that we are reloading
our SPD entries with a SIGHUP

cf7a5161 02/01/2008 09:32 PM Seth Mos

Update to racoon-0.7-cvs with Timo Teras patches.
Use setkey -f because spd loading works normally now.

02821543 01/15/2008 05:29 PM Seth Mos

attempt loading SPD entries 4 times

989f0b08 01/15/2008 11:36 AM Seth Mos

Somehow sending a SIGHUP before flushing and reloading works better then
after. Technically a SIGHUP to racoon should not do anything.

81cf1a89 01/15/2008 08:22 AM Seth Mos

Flush both SA and SPD entries

abd9c036 01/14/2008 09:37 PM Seth Mos

Make 3 passes at loading the SPD entries as this will fail on large configurations > 250 tunnels
Tested by smos@ 399 tunnels 239 active, ok by sullrich@

f971bb63 11/05/2007 05:33 PM Scott Ullrich

IPSEC keep alive pinger using the wrong source IP address

Ticket #1482

a7204435 11/01/2007 05:54 PM Scott Ullrich

Adding keep alive host to IPsec causes warning in webGUI

Ticket #1509

9dcb92da 10/19/2007 08:52 PM Bill Marquette

Ticket #1482 - set the source to an interface that is inside the subnet definition

fb0259fe 08/04/2007 08:27 PM Scott Ullrich

Sync NATT support from m0n0wall

ab325235 07/08/2007 09:04 PM Seth Mos

Oops, correct path to binaries

11688040 07/06/2007 09:07 PM Seth Mos

MFC IPSEC fixes from seth, this should properly reload and handle large
configs > 300 tunnels.

3fcb53b6 06/02/2007 09:17 PM Scott Ullrich

use killall

d2d602ff 06/02/2007 09:10 PM Scott Ullrich
  • Flush SPD's on reload
  • Kilall -HUP racoon if its already running since racoonctl is brokie brokie
153e730b 06/02/2007 08:51 PM Scott Ullrich
  • Remove path from racoon grep
  • Remove [r] from racoon and simply grep for racoon
33b1881c 06/02/2007 08:49 PM Scott Ullrich

Correct ps location

d5be613c 06/02/2007 08:48 PM Scott Ullrich

Kill trailing space

0fabced3 05/20/2007 04:52 PM Seth Mos

Commit forgotten vpn_ipsec_force_reload()

9a66dfe5 05/11/2007 07:14 AM Seth Mos

Do not flush SPA and SPD before starting. It upsets racoon.

c2d2e176 05/10/2007 08:02 AM Seth Mos

Rework stop and start logic. If we are already alive, reload instead of stop and start.
Tested by Seth.

6bc17e95 04/27/2007 08:19 PM Scott Ullrich

PPPoE server fixes

Ticket #1283

357cde41 03/20/2007 05:46 PM Scott Ullrich

Add link_carp_interface_to_parent() function

87e72a58 03/18/2007 01:58 AM Scott Ullrich

Allow CARP addresses to be the IPSEC endpoint.

This cleans up the code GREATLY and removes the FAILOVER IPSEC hack.

0caf2436 03/18/2007 12:40 AM Scott Ullrich

Make tabs consistent

0f9c365d 03/18/2007 12:36 AM Scott Ullrich

Use a comma to seperate multiple hosts instead of a carriage return which is being stripped by the package manager

8da8f2f8 03/17/2007 07:53 PM Scott Ullrich

Allow multiple racoon listen ips so that racoon can live on two different wan carp ips (multiple isps)

71602b14 03/02/2007 08:20 PM Scott Ullrich

Only install listen directive when value is filled in.

0feec714 02/08/2007 10:03 PM Scott Ullrich

Backport IPSEC filtering to 1.0.1.

Requested and will be tested by Seth

4f181571 01/19/2007 04:36 PM Scott Ullrich

Add back missing WINS statement that was accidently chopped in commit #9051

Ticket #1209

c52719a8 09/22/2006 11:22 PM Scott Ullrich

Do not destroy previous items, whiping out the listen directive.

dc50c7ec 06/08/2006 04:51 AM Scott Ullrich

Disable sasyncd. Sniff sniff. I gave it all I could, cap'n.

Maybe 1.1.

0e16b9ca 04/08/2006 02:04 AM Scott Ullrich

We're in 2006 now, toto

88964924 03/11/2006 08:35 PM Scott Ullrich

Ticket #854 fixes

  • Compute the correct amount of ng interface for pptp and pppoe
  • Restart mpd processes in one function so that duplicates do not end up in mpd.conf file
48bff85c 02/05/2006 10:03 PM Scott Ullrich
  • Sleep a little longer after killing mpd to allow it to cleanup
  • If there was a problem killing mpd, try killing once more and log the attempt
f5969e91 01/25/2006 01:58 AM Scott Ullrich

Add c/r

c1f5a46b 01/24/2006 11:51 PM Scott Ullrich

MFC vpn ping code

e263fe9a 01/18/2006 08:00 PM Scott Ullrich

Remove trailing newline

110d1076 01/15/2006 07:27 PM Scott Ullrich

Use correct variable for radius issued ips

767a716e 01/15/2006 03:33 AM Scott Ullrich

Correct warnings and errors found eclipse

68d408c7 01/05/2006 11:13 PM Scott Ullrich

Set: set link mru 1492 in addition to set link mtu 1492

5264023a 01/05/2006 10:50 PM Scott Ullrich

Do not apply option when radius is disabled

5dfdc1fb 01/05/2006 07:16 PM Scott Ullrich

Allow issuing of PPOE ips from RADIUS server

Ticket #709

ee953edc 01/04/2006 01:26 AM Scott Ullrich

Import m0n0wall 1.21 PPTP Server

c25a575f 12/26/2005 02:51 AM Scott Ullrich

Remove auto establish. It's never worked.

d1d7f663 12/26/2005 01:59 AM Scott Ullrich

Alert that we are auto establishing tunnel

af1f6a1f 12/24/2005 09:22 PM Scott Ullrich

Back off a little bit on the insane debugging levels. This brings the debugging levels back similar to m0n0wall.

fe227c69 12/22/2005 06:59 PM Scott Ullrich

Move setkey to /sbin/setkey from /usr/sbin/setkey due to FreeBSD changing the location.

45449ae0 12/19/2005 05:34 PM Scott Ullrich
  • Use 0.0.0.0/0 so radius can allocate ips
  • Do not set link mtu twice
637acd36 11/12/2005 06:35 PM Scott Ullrich
  • Turn of ACE. It doesn't work at all.
  • Killall racoon. IPSEC Tools racoon seems to work a bit diff
a636c6ba 11/05/2005 01:30 AM Scott Ullrich

Enable padlock support

a5a0c4c7 10/13/2005 09:31 PM Scott Ullrich

Move )

Pointy-hat-to: Me

89e910c6 10/13/2005 09:29 PM Scott Ullrich

Missing )

Pointy-hat-to: Me

cefde762 10/13/2005 08:50 PM Scott Ullrich

Forced commit to note that failover ipsec should be enabled as well (even if your not using failover, it simply sets the racoon listen ip address)

ab80b66f 10/13/2005 08:49 PM Scott Ullrich

Add NATT support. Currently this option is disabled. To enable simply set the <developer/> tag inside <system> in config.xml

816f2e58 09/23/2005 10:05 PM Scott Ullrich

Use correct mtu for pptp when wan is pppoe.

Have I mentioned how much I HATE pptp lately?

93f2d54e 08/31/2005 11:45 PM Scott Ullrich

Set /sbin/sysctl net.inet.ipsec.crypto_support=1 if Padlock

13beee7d 08/31/2005 11:34 PM Scott Ullrich

Detect ACE in CPU line

e6f48f2e 08/31/2005 11:13 PM Scott Ullrich

Do not set net.inet.ipsec.crypto_support