I am trying to set use IPsec to transport (not tunnel) between an XP client and Monowall. Because
the Monowall GUI does not allow setting this up I am trying to to use setkey to establish the
policy. When I enter the setkey commands (see below) in the monowall exec.php page I get the listed
reply. When I check the status.php there is no entries in the SPD or SAD, just like the commands
did not take.
(returns $ /usr/sbin/setkey -FP)
(returns $ /usr/sbin/setkey -F)
/usr/sbin/setkey -c spdadd 18.104.22.168/32 22.214.171.124/32 any -P out
(returns $ /usr/sbin/setkey -c spdadd 126.96.36.199/32 188.8.131.52/32 any -P out)
/usr/sbin/setkey -c ipsec esp/transport/184.108.40.206-220.127.116.11/require
(returns $ /usr/sbin/setkey -c ipsec esp/transport/18.104.22.168-22.214.171.124/require)
/usr/sbin/setkey -c spdadd 126.96.36.199/32 188.8.131.52/32 any -P in
(returns $ /usr/sbin/setkey -c spdadd 184.108.40.206/32 220.127.116.11/32 any -P in)
/usr/sbin/setkey -c ipsec esp/transport/18.104.22.168-22.214.171.124/require
(returns $ /usr/sbin/setkey -c ipsec esp/transport/126.96.36.199-188.8.131.52/require)
I replace 184.108.40.206 in the example with 192.168.2.1 (the ip of the WLAN nic)
I replace 220.127.116.11 in the example with 192.168.2.98 (the ip of the XP client)
I have tried adding " ; " to the end of each command and the results are the same.
I would appreciate any help on setting up the transport policy without using the GUI. Thanks, Bob.
Ring in the New Year with Photo Calendars. Add photos, events, holidays, whatever.