|
|||||||||||
|
Re: [Users] protocol/port in Phase 1 ID Payload must be 0/0 or
From: Thomas Ristic <thr(at)odn.de>
Date: Sat Feb 28 2004 - 07:25:57 EST
On Wed, 2004-02-25 at 13:40, Jorge Costa wrote:
Hi! Cisco 800 Series has a bug in their IKE implementation that will prevent keyexchange with FreeSWAN. While Cisco is wrong according to the RFC, the bug can be easily fixed on FreeSWAN side. Unfortunately the FreeSWAN developer community wants to stick close to the RFC and will not offer a workaround. For more on this discussion, see the list archives. Here are some relevant entries: http://lists.freeswan.org/pipermail/users/2003-January/017808.htmlhttp://lists.freeswan.org/pipermail/design/2002-January/001810.htmlhttps://lists.freeswan.org/archives/users/2003-November/msg00005.htmlhttps://lists.freeswan.org/archives/design/2003-November/msg00002.htmlhttps://lists.freeswan.org/archives/users/2003-November/msg00007.htmlhttps://lists.freeswan.org/archives/design/2003-November/msg00004.html This tiny patch applies against 1.99 and everything works for me: http://ristic.info/files/linux-freeswan.patch Regards Thomas Ristic FreeS/WAN Users mailing list users@lists.freeswan.org https://mj2.freeswan.org/cgi-bin/mj_wwwusr Received on Sat Feb 28 07:30:26 2004 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:02:06 EDT |
||||||||||
|
|||||||||||