Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

[Users] "no connection authorized"?

From: Terence Parker <tparker(at)deltapath.com>
Date: Mon Mar 03 2003 - 07:06:45 EST


I'm trying to a machine with a Real IP to an NATed host, and have successfully done so - connecting the NATed machine to two separate hosts. However, after establishing the initial connection, it will last at most one day before dying. When I attempt to reconnect, I would get the following messages (given below) repeated over and over in the logs.

Surely by reconnecting both sides should make an attempt to re-authorize the machines, so I shouldn't be getting such a message? I'm not sure what is the cause of this.

I have tried variations of rekeymargin, keylife, and ikelifetime in the ipsec.conf file - but changing ikelifetime has only allowed the connection to stay up for 24 hours as opposed to the default 8. However, I thought it should renegotiate a key before this expires anyway. (i've tried changing rekeymargin too).

Should I lower the lifetime values? I'm not sure what is the problem here.

Any help would be appreciated.

Thanks,

Terence Parker

Mar 3 08:01:10 [pluto] packet from 67.120.114.18:113: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03]
Mar 3 08:01:10 [pluto] packet from 67.120.114.18:113: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02]
Mar 3 08:01:10 [pluto] packet from 67.120.114.18:113: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]
Mar 3 08:01:10 [pluto] packet from 67.120.114.18:113: initial Main Mode message received on 202.64.84.144:500 but no connection has been authorized Mar 3 08:01:31 [pluto] packet from 67.120.114.18:113: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03]
Mar 3 08:01:31 [pluto] packet from 67.120.114.18:113: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02]
Mar 3 08:01:31 [pluto] packet from 67.120.114.18:113: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]
Mar 3 08:01:31 [pluto] packet from 67.120.114.18:113: initial Main Mode message received on 202.64.84.144:500 but no connection has been authorized



Users mailing list
Users@lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users Received on Mon Mar 3 09:17:12 2003
Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:00:27 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library