Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: "FreeS/WAN - isakmpd" monday match... I offer a beer...

From: Andrew Rucker Jones <arjones(at)simultan.dyndns.org>
Date: Mon Dec 09 2002 - 15:08:19 EST

... or perhaps more likely isakmpd is not running on OpenBSD.

I've looked at everything, and the tcpdump output from the third machine cannot possibly match the OpenBSD log output. In the tcpdump output, Linux tries to send packets to OpenBSD, which has nothing listening on UDP port 500 (or is perhaps rejecting them because of firewall rules). In the log messages, i believe i see about three packets, all of them on their way to building a phase 1 SA. Linux sends something to OpenBSD, which reponds, then Linux sends the next packet in the phase 1 sequence, and so on. The Linux logs don't tell me anything. The configuration files look 100% right.

        So, check for possible firewall rules, check that isakmpd is running (the best thing to do is to kill all instances of isakmpd, and i mean do ps aux | grep isakmp and kill them all, stop FreeS/WAN, start isakmpd, then start FreeS/WAN -- i also noted that FreeS/WAN was sending a packet to OpenBSD that was for phase 2, which might imply to me that FreeS/WAN has some stale ISAKMP SA's hanging around), and also make sure that sysctl -a reports net.inet.esp.enable = 1. Before starting isakmpd and FreeS/WAN, be sure to start tcpdump and get a clean trace of the whole thing.

                        -&

Stephen J. Bevan wrote:
> goony writes:

-- 
GPG key / Schlüssel -- 
http://simultan.dyndns.org/~arjones/gpgkey.txt
Encrypt everything. / Alles verschlüsseln.
Received on Mon Dec 9 15:08:18 2002

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:31:55 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library