|
|||||||||||
|
[Users] Still not working! Maybe fragmented certificate exchange?
From: stuart <stuart(at)camart.co.uk>
Date: Mon Mar 31 2003 - 06:41:11 EST
Hello, I have been trying to get my win2k roadwarrior to work with my freeswan gateway but am having no luck (still). I have followed the advice given and attempted to sort this out myself but still whenever I try and ping a computer behind my gateway I just get a constant stream of : 'Negotiating IP Security' This doesn't stop until I stop pinging. The last thing I was advised to do was to reduce the size of my certificates from 2048 to 1024 bit certs (or to set my kernel to defrag by default - but this is always on now with later kernels of which my linux mandrake kernel is part). So I changed my cert sizes and now the length parameter in the exchange sequence is down from a horrid 8xxx to 1500 but I am still not connecting properly. I ran tcpdump on the external interface on the gateway and only showed those coming on port 500 - this shows some interesting fragmented' messages which I have posted @ http://www.camart.co.uk/freeswan/tcpdump.txt my new barf is @ http://www.camart.co.uk/freeswan/barf.txt and my new oakley log is @ http://www.camart.co.uk/freeswan/oakley.txt If anyone has any clues as to how to sort this out I would be very greatful - this is so frustrating because I had this working from this box a few monthes ago - the only things that have changed since then are:
installing win2k SP3
Thanks in advance (and in desperation . . .) Stuart stuart@camart.co.uk -----BEGIN PGP SIGNATURE-----
iQCVAwUAPogpXOuh6DeDjCODAQHeGQP9FTDsnRiVhY6ddUjL3AJHwzwZQele6BKL
pFL16j2vX+nc56R+BDiI3MuBQRa/abbHjASrgB/rqF3NN2T/zhsjwoVGW33BdUOb
h0sdfKM8Ub0IYPoQq05+AJggmE+vuvnZJ88UQn5Xh89MpVsv5Qjr05qGFDYUlAlU
cDm9vj40Pbk=
Users mailing list Users@lists.freeswan.org http://lists.freeswan.org/mailman/listinfo/users Received on Fri Apr 4 17:16:22 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:01:14 EDT |
||||||||||
|
|||||||||||