Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: linux-ipsec: freeswan-0.90 works, then hangs

From: Sean Healy <sch(at)klg.com>
Date: Thu Sep 17 1998 - 11:49:12 EDT

David Sainty wrote:
>
> How much memory do you have?

Both machines have 64MB with Pentium II processors, so I doubt it's memory or speed. Originally, I was using a 486/66 as one of the vpn machines (vpn1). Everything seemed fine until it started hanging. I replaced the 486 (temporarily) with another Pentium II.

One thing I noticed; it took a lot longer to hang with the 486/66 as vpn1 than with the Pentium II. I notice the Pentium II setup hanging within a few minutes of heavy TCP/IP activity.

It's very strange. When it works, it works great. But when it dies, I've been reseting the servers to re-establish the VPN. If I'm using an xterm from a workstation on network 2 to a server on network 1, and the VPN goes down, the xterm stops responding. It will eventually come back to life after the reboot. (But, it dies again within a few minutes.)

I tried a tcpdump to see the activity over the lines. The only thing odd I noticed is that I'm seeing some truncated packets with odd IP addresses. I am not using any of the subnets listed here. (Basic setup is vpn1/vpn2 at 192.168.10.1/192.168.10.2, with 192.168.20.0 on one side and 192.168.30.0 on the other.)

On vpn1:

10:25:56.3919 vpn2 > 69.0.0.104: truncated-ip - 12 bytes missing!244.94.8.0 >
69.0.0.84: (frag 38736:80@18248+) [tos 0xaf] [ttl 0] (bad cksum 9750!, optlen=-4
[|ip]) (ttl 127, id 1199, bad cksum 0!)

Do you need help?X

On vpn2:

10:16:51.3902 truncated-ip - 48 bytes missing!15.223.8.0 > 69.0.0.48: (frag 3877
1:72@4848) [tos 0x76] [ttl 0] (encap)

(The clocks, unfortunately, were not in sync.)

Is there anything special I can look for via tcpdump or from the klipsdebug log?

-- 
Sean Healy
Systems Administrator		Phone:	(416) 594-1026 ext. 768
KL Group Inc.			Fax:	(416) 594-1919
Toronto, Ontario, Canada		email:	sch@klg.com
Received on Thu Sep 17 12:48:35 1998

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:26 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library