4 esp_transport 用 racoon协商 用setkey设置 spd

在racoon设置部分不改变的情况下. 手动用 setkey设置 spd条目时只更改用 transport模式. 就可以实现了.


spdadd -4 192.168.125.14/32 192.168.125.10/32 any -P in ipsec esp/transport/192.168.125.14-192.168.125.10/require;
spdadd -4 192.168.125.10/32 192.168.125.14/32 any -P out ipsec esp/transport/192.168.125.10-192.168.125.14/require;


那么问题来了. 在 racoon相关的设置中. 没有关于 transport 或tunnel模式的选择. 

如果在 racoon.conf里设置 generate_policy on; 它会默认生成什么模式呢?  试了一下会出错. 应该是找不到相应的 spd条目什么的.

是什么情况下设置 generate_policy on; 来工作呢? 


确实是对端为动态时才能使用的.

generate_policy (on | off | require | unique);
                     This directive is for the responder.  Therefore you should set passive to on in order that racoon(8) only becomes a responder.  If the respon‐
                     der does not have any policy in SPD during phase 2 negotiation, and the directive is set to on, then racoon(8) will choose the first proposal
                     in the SA payload from the initiator, and generate policy entries from the proposal.  It is useful to negotiate with clients whose IP address
                     is allocated dynamically.  Note that an inappropriate policy might be installed into the responder's SPD by the initiator, so other communica‐
                     tions might fail if such policies are installed due to a policy mismatch between the initiator and the responder.  on and require values mean
                     the same thing (generate a require policy).  unique tells racoon to set up unique policies, with a monotoning increasing reqid number (between
                     1 and IPSEC_MANUAL_REQID_MAX).  This directive is ignored in the initiator case.  The default value is off.


也许应该继续看一下. 当esponder. 的情况?

最好还能支持个 l2tp协议. 让windows, 智能手机啥地连接上.

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值