OpenBSD Journal

Building VPNs with OpenBSD and IPSEC

Contributed by jason on from the sup-dawg-we-heard-you-like-kryption dept.

Found a new blog post from a recent tweet by @knightgats. Check out his tutorial on setting up your own site-to-site VPN with OpenBSD IPSec. This is well-covered territory, but it never hurts to see a refresher for new users.

The author walks thorugh all steps of:

  • Enabling the IPSec protocols in /etc/sysctl.conf
  • Creating your /etc/ipsec.conf rules
  • Filtering the IPSec traffic with PF
  • Synchronizing your IPSec host keys
  • Troubleshooting your connection

(Comments are closed)


Comments
  1. By tdm (tdm) on

    Fantastic stuff! Any chance of seeing an IKEv2 / iked(4) howto? I've played around with it but couldn't get the EAP authentication working. I know it's still fairly new, though.

Credits

Copyright © - Daniel Hartmeier. All rights reserved. Articles and comments are copyright their respective authors, submission implies license to publish on this web site. Contents of the archive prior to as well as images and HTML templates were copied from the fabulous original deadly.org with Jose's and Jim's kind permission. This journal runs as CGI with httpd(8) on OpenBSD, the source code is BSD licensed. undeadly \Un*dead"ly\, a. Not subject to death; immortal. [Obs.]