[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

isakmpd questions



1) Is there a way to turn off NAT-T either globally or on a peer-by-peer basis? I'm trying to interconnect with some peers that don't support NAT-T and can get confused by it.

2) Is the keynote policy checked both when we initiate and when the far end initiates, or just when the far end initiates (I mean initiates phase2)?

3) The isakmpd(8) man page says that -K turns off keynote for when policies are arranged by other programs. Where could I find some sample configs that use these alternative validation methods?

			Alexey

P.S. Sorry if this is not the right list. Also, I'm not subscribed, so please reply directly. Thank you.



Visit your host, monkey.org