Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: [Users] Multiple RWs with X.509

From: Andreas Steffen <andreas.steffen(at)strongsec.net>
Date: Tue Feb 18 2003 - 11:02:29 EST

With roadwarrior connectios (i.e. with right=%any) it is normal behaviour that an arbitrary roadwarrior connection is chosen when a roadwarrior starts initiating. As soon as the ID is received from the roadwarrior in message MI3 a switch is made to the correct connection (in your case from wall-albatros to fishbowl-albatross).

The error

"wall-albatross" xxx.xx.xx.xx #2193: no suitable connection for peer 'C=CH, ST=ZH, L=Zurich, O=madduck.net, ... rwB'

means that ipsec auto --status does not show a connection with that ID. This may be due to an error that occured when the connection definition "fishbowl-albatross" was loaded on the gateway during Pluto startup. So please check if "fishbowl-albatross" shows up in ipsec auto -status and matches character-per-character with the Peer ID.

Regards

Andreas

martin f krafft wrote:
> I am using the X.509 patch and trying to allow multiple RWs to connect

-- 
=======================================================================
Andreas Steffen                   e-mail: andreas.steffen@strongsec.com
strongSec GmbH                    home:   
http://www.strongsec.com
Alter Zürichweg 20                phone:  +41 1 730 80 64
CH-8952 Schlieren (Switzerland)   fax:    +41 1 730 80 65
==========================================[strong internet security]===


_______________________________________________
Users mailing list
Users@lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users
Received on Tue Feb 18 11:39:59 2003
Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:00:20 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library