Working with FreeS/Wan – shared secret
Hi,
I got the latest vaporsec to work with linux freeswan with shared secret.
I had to set the local IP in the Main pannel (couldn't this be done automatically BTW ?)
The settings are :
Main
Mode Mail
Proposal Check Clain
Node size 16
Phase1
Lifetime 1h
DH Group 2
Encryption 3des
Authentication MD5
Phase 2
Lifetime 8h
PFS Group 2
Encryption 3des
Authentication hmac_md5
ID
Address
Address
I couldn't get the id to work (ie : @me.domain.com) - not sure why.
Just removed the leftid / rightid from my freeswan config.
Oh, as a sidenote, some config which could be added is Lifetime depenting on transfered traffic :
lifetime time 60 sec ; # sec,min,hour
lifetime byte 2 MB ; # B,KB,GB
Didn't tested with certificates yet (freeswan patched is needed for this : www.freeswan.ca for more info)
Some usefull freeswan/kame links :
http://www.freeswan.ca/docs/freeswan-2.00/doc/interop.html#kame