|
|||||||||||
|
Re: "FreeS/WAN - isakmpd" monday match... I offer a beer...
From: Andrew Rucker Jones <arjones(at)simultan.dyndns.org>
Date: Mon Dec 09 2002 - 15:08:19 EST ... or perhaps more likely isakmpd is not running on OpenBSD. I've looked at everything, and the tcpdump output from the third machine cannot possibly match the OpenBSD log output. In the tcpdump output, Linux tries to send packets to OpenBSD, which has nothing listening on UDP port 500 (or is perhaps rejecting them because of firewall rules). In the log messages, i believe i see about three packets, all of them on their way to building a phase 1 SA. Linux sends something to OpenBSD, which reponds, then Linux sends the next packet in the phase 1 sequence, and so on. The Linux logs don't tell me anything. The configuration files look 100% right. So, check for possible firewall rules, check that isakmpd is running (the best thing to do is to kill all instances of isakmpd, and i mean do ps aux | grep isakmp and kill them all, stop FreeS/WAN, start isakmpd, then start FreeS/WAN -- i also noted that FreeS/WAN was sending a packet to OpenBSD that was for phase 2, which might imply to me that FreeS/WAN has some stale ISAKMP SA's hanging around), and also make sure that sysctl -a reports net.inet.esp.enable = 1. Before starting isakmpd and FreeS/WAN, be sure to start tcpdump and get a clean trace of the whole thing. -&
Stephen J. Bevan wrote:
-- GPG key / Schlüssel -- http://simultan.dyndns.org/~arjones/gpgkey.txt Encrypt everything. / Alles verschlüsseln.Received on Mon Dec 9 15:08:18 2002 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:31:55 EDT |
||||||||||
|
|||||||||||