Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

[Users] [PATCH] MSL2TP PAYLOAD MALFORMED workaround plus 2 .reg files

From: JuanJo Ciarlante <jjo-ipsec(at)mendoza.gov.ar>
Date: Mon May 05 2003 - 10:27:50 EDT


[ mail re-sent because didn't appear in ML ]

Hi Jacco

1st of all: thanks for your greAT tutorial abount setting up such a beast =)

Sometimes, apparently on client rekeying timer; MSL2TP sends malformed packets: they specify ISAKMP_NEXT_VID instead of ISAKMP_NEXT_NONE on last payload, thus triggering PAYLOAD MALFORMED responses and making pluto (correctly) ignore them.

Attached patch does workaround this situation by forcing ISAKMP_NEXT_NONE if space remaining == 0 (ie. the only choice); this patch gave me somewhat more reliability to reconnections from client.

Also, those two registry files setup PFS (as stated in your tutorial) _and_ IPCOMP, both succesfully tested.

Ken: lets see if other ppl success with this patch, so we inject into superfreeswan CVS

Regards

--Juanjo       freeswan algo: AES (+others), SHA2, MODP2048-4096 
               selectable algorithms support for Phase1 and 2.
	       
http://www.irrigacion.gov.ar/juanjo/ipsec/

#  Juan Jose Ciarlante (JuanJo PGP) jjo ;at; mendoza.gov.ar              #
# Key fingerprint = 76 60 A5 76 FD D2 53 E3 50 C7 90 20 22 8C F1 2D #
Do you need help?X



Users mailing list
Users@lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users
Received on Mon May 5 11:36:32 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:01:30 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library