diff options
Diffstat (limited to 'sbin')
-rw-r--r-- | sbin/brconfig/brconfig.8 | 14 | ||||
-rw-r--r-- | sbin/ipsecadm/ipsecadm.8 | 22 |
2 files changed, 18 insertions, 18 deletions
diff --git a/sbin/brconfig/brconfig.8 b/sbin/brconfig/brconfig.8 index c953bfc17f8..5d24f7e0c66 100644 --- a/sbin/brconfig/brconfig.8 +++ b/sbin/brconfig/brconfig.8 @@ -1,4 +1,4 @@ -.\" $OpenBSD: brconfig.8,v 1.38 2002/09/06 21:36:52 deraadt Exp $ +.\" $OpenBSD: brconfig.8,v 1.39 2002/12/06 16:28:48 markus Exp $ .\" .\" Copyright (c) 1999-2001 Jason L. Wright (jason@thought.net) .\" All rights reserved. @@ -339,23 +339,23 @@ Configure the gif0 interface: Create Security Associations (SAs) between the external IP address of each bridge: .Bd -literal -# ipsecadm new esp -spi 4242 -dst 4.3.2.1 -src 1.2.3.4 \e\ +# ipsecadm new esp -spi 4242 -dst 4.3.2.1 -src 1.2.3.4 \\ -enc 3des -auth md5 -keyfile keyfile1 -authkeyfile authkeyfile1 .Ed .Pp .Bd -literal -# ipsecadm new esp -spi 4243 -dst 1.2.3.4 -src 4.3.2.1 \e\ +# ipsecadm new esp -spi 4243 -dst 1.2.3.4 -src 4.3.2.1 \\ -enc 3des -auth md5 -keyfile keyfile2 -authkeyfile authkeyfile2 .Ed .Pp Setup ingress flows so that traffic is allowed between the two bridges for the above associations: .Bd -literal -(on bridge1) # ipsecadm flow -dst 4.3.2.1 -out \e\ - -transport etherip -require \e\ +(on bridge1) # ipsecadm flow -dst 4.3.2.1 -out \\ + -transport etherip -require \\ -addr 1.2.3.4 255.255.255.255 4.3.2.1 255.255.255.255 -(on bridge2) # ipsecadm flow -dst 1.2.3.4 -out \e\ - -transport etherip -require \e\ +(on bridge2) # ipsecadm flow -dst 1.2.3.4 -out \\ + -transport etherip -require \\ -addr 4.3.2.1 255.255.255.255 1.2.3.4 255.255.255.255 .Ed .Pp diff --git a/sbin/ipsecadm/ipsecadm.8 b/sbin/ipsecadm/ipsecadm.8 index 131c80701e5..23dd212c864 100644 --- a/sbin/ipsecadm/ipsecadm.8 +++ b/sbin/ipsecadm/ipsecadm.8 @@ -1,4 +1,4 @@ -.\" $OpenBSD: ipsecadm.8,v 1.52 2002/09/06 21:36:52 deraadt Exp $ +.\" $OpenBSD: ipsecadm.8,v 1.53 2002/12/06 16:28:48 markus Exp $ .\" .\" Copyright 1997 Niels Provos <provos@physnet.uni-hamburg.de> .\" All rights reserved. @@ -641,41 +641,41 @@ only flush SAs of type ip4. Setup a SA which uses new esp with 3des encryption and HMAC-SHA1 authentication: .Bd -literal -# ipsecadm new esp -enc 3des -auth sha1 -spi 100a -dst 169.20.12.2 \e\ - -src 169.20.12.3 \e\ - -key 638063806380638063806380638063806380638063806380 \e\ +# ipsecadm new esp -enc 3des -auth sha1 -spi 100a -dst 169.20.12.2 \\ + -src 169.20.12.3 \\ + -key 638063806380638063806380638063806380638063806380 \\ -authkey 1234123412341234123412341234123412341234 .Ed .Pp Setup a SA for authentication with old ah only: .Bd -literal -# ipsecadm old ah -auth md5 -spi 10f2 -dst 169.20.12.2 -src 169.20.12.3 \e\ +# ipsecadm old ah -auth md5 -spi 10f2 -dst 169.20.12.2 -src 169.20.12.3 \\ -key 12341234deadbeef .Ed .Pp Setup a flow requiring use of AH: .Bd -literal -# ipsecadm flow -dst 169.20.12.2 -proto ah \e\ +# ipsecadm flow -dst 169.20.12.2 -proto ah \\ -addr 10.1.1.0 255.255.255.0 10.0.0.0 255.0.0.0 -out -require .Ed .Pp Setup an inbound SA: .Bd -literal -# ipsecadm new esp -enc blf -auth md5 -spi 1002 -dst 169.20.12.3 \e\ - -src 169.20.12.2 \e\ - -key abadbeef15deadbeefabadbeef15deadbeefabadbeef15deadbeef \e\ +# ipsecadm new esp -enc blf -auth md5 -spi 1002 -dst 169.20.12.3 \\ + -src 169.20.12.2 \\ + -key abadbeef15deadbeefabadbeef15deadbeefabadbeef15deadbeef \\ -authkey 12349876432167890192837465098273 .Ed .Pp Setup an ingress flow on for the inbound SA: .Bd -literal -# ipsecadm flow -addr 10.0.0.0 255.0.0.0 10.1.1.0 255.255.255.0 \e\ +# ipsecadm flow -addr 10.0.0.0 255.0.0.0 10.1.1.0 255.255.255.0 \\ -dst 169.20.12.2 -proto esp -in -require .Ed .Pp Setup a bypass flow: .Bd -literal -# ipsecadm flow -bypass -out \e\ +# ipsecadm flow -bypass -out \\ -addr 10.1.1.0 255.255.255.0 10.1.1.0 255.255.255.0 .Ed .Pp |