Hacker News new | ask | show | jobs
by equalunique 3414 days ago
I'd only use StrongSwan if an OpenBSD gateway is not an option. Configuring IPsec IKEv2 on OpenBSD is very simple.
2 comments

I would like to try that instead of a Linux implementation - it would be a great help if you would like to link to some (working) tutorials... of course I found something on search engines, but I expect to find many outdated things (as always with these kind of knowledge), so a link to THE right thing would be a very lovely shortcut. Thanks!
Yeah, I moved over to OpenBSD from FreeBSD because of their no-bullshit approach to supporting IPSEC -- everything just worked out of the box.

I was thrilled when FreeBSD added IPSEC support in 11-RELEASE, but was less excited to learn that IPSEC_NAT_T wasn't compiled in, making it impossible to use strongswan. Oh well, maybe in 11.1 :)

> I was thrilled when FreeBSD added IPSEC support in 11-RELEASE

You're welcome.