<div>Hi,</div>
<div> </div>
<div>In /var/log/secure I have the follwing message:</div>
<div> </div>
<div>Mar 28 16:22:28 ns pluto[5175]: Could not change to directory '/etc/ipsec.d/ocspcerts'<br>Mar 28 16:22:28 ns pluto[5175]: Could not change to directory '/etc/ipsec.d/crls'<br>Mar 28 16:22:28 ns pluto[5175]: added connection description "tunnelipsec"
<br>Mar 28 16:22:28 ns pluto[5175]: listening for IKE messages<br>Mar 28 16:22:28 ns pluto[5175]: adding interface eth1/eth1 <a onclick="return top.js.OpenExtLink(window,event,this)" href="http://172.16.1.1:500/" target="_blank"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "172.16.1.1:500" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious:
172.16.1.1:500</a><br>Mar 28 16:22:28 ns pluto[5175]: adding interface eth0/eth0 <a onclick="return top.js.OpenExtLink(window,event,this)" href="http://165.98.224.82:500/" target="_blank"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "165.98.224.82:500" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 165.98.224.82:500</a><br>Mar 28 16:22:28 ns pluto[5175]: adding interface lo/lo
<a onclick="return top.js.OpenExtLink(window,event,this)" href="http://127.0.0.1:500/" target="_blank"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "127.0.0.1:500" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 127.0.0.1:500</a><br>Mar 28 16:22:28 ns pluto[5175]: adding interface lo/lo ::1:500 <br>Mar 28 16:22:28 ns pluto[5175]: loading secrets from "/etc/ipsec.secrets"
<br>Mar 28 16:22:29 ns pluto[5175]: "tunnelipsec" #1: initiating Main Mode<br> </div>
<div>In /var/log/message I hace the following messages:</div>
<div> </div>
<div>Mar 28 16:21:47 ns ipsec__plutorun: 104 "tunnelipsec" #1: STATE_MAIN_I1: initiate<br>Mar 28 16:21:47 ns ipsec__plutorun: ...could not start conn "tunnelipsec"<br>Mar 28 16:21:51 ns kernel: ip_tables: (C) 2000-2002 Netfilter core team
<br>Mar 28 16:22:21 ns kernel: NET: Unregistered protocol family 15<br>Mar 28 16:22:21 ns ipsec_setup: ...Openswan IPsec stopped<br>Mar 28 16:22:28 ns kernel: NET: Registered protocol family 15<br>Mar 28 16:22:28 ns ipsec_setup: KLIPS ipsec0 on eth0
<a onclick="return top.js.OpenExtLink(window,event,this)" href="http://165.98.224.82/255.255.255.252" target="_blank"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "165.98.224.82" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 165.98.224.82/255.255.255.252</a> broadcast <a onclick="return top.js.OpenExtLink(window,event,this)" href="http://165.98.224.83/" target="_blank"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "165.98.224.83" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious:
165.98.224.83</a> <br>Mar 28 16:22:28 ns ipsec_setup: ...Openswan IPsec started<br>Mar 28 16:22:29 ns ipsec__plutorun: 104 "tunnelipsec" #1: STATE_MAIN_I1: initiate <br>Mar 28 16:22:29 ns ipsec__plutorun: ...could not start conn "tunnelipsec"
<br> </div>
<div>Thanks,<br> </div><br><br>
<div><span class="gmail_quote">On 3/28/06, <b class="gmail_sendername">ted leslie</b> <<a href="mailto:tleslie@tcn.net">tleslie@tcn.net</a>> wrote:</span>
<blockquote class="gmail_quote" style="PADDING-LEFT: 1ex; MARGIN: 0px 0px 0px 0.8ex; BORDER-LEFT: #ccc 1px solid">where is this error showing?<br>if you do a<br>ipsec auto --up tunnelipsec<br><br>you should see useful info appear ...
<br>or run a status command to maybe in a barf<br><br>take out auto start and start it manually<br><br>-tl<br><br><br>On Tue, 28 Mar 2006 15:41:34 -0600<br>"Vida Luz Arista" <<a href="mailto:viaris@gmail.com">
viaris@gmail.com</a>> wrote:<br><br>> Hi All,<br>><br>> I have installed tpm openswan for Fedora Version 4, I need to establish a<br>> vpn with a cisco 800, the problem es that the VPN can't be established, the
<br>> message error in my linux is: ipsec__plutorun: ...could not start conn<br>> "tunnelipsec"<br>><br>> I don't have firewall then I Haven't iptables rules, If I don't have<br>> firewall I need iptables rules ? is necesary?
<br>><br>> My configuration is:<br>><br>> ipsec.conf<br>> =========<br>><br>> # /etc/ipsec.conf - Openswan IPsec configuration file<br>> #ike= "3des-md5-modp768"<br>>
<br>> version 2.0<br>><br>> config setup<br>> interfaces="ipsec0=eth0"<br>> klipsdebug=none<br>> plutodebug=none<br>> forwardcontrol=yes<br>><br>> conn tunnelipsec
<br>> type=tunnel<br>> left=<a href="http://165.98.224.82"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "165.98.224.82" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 165.98.224.82</a><br>> leftsubnet=<a href="http://172.16.1.0/24"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "172.16.1.0" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 172.16.1.0/24</a><br>> right= <a href="http://165.98.236.214"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "165.98.236.214" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious:
165.98.236.214</a><br>> rightsubnet=<a href="http://172.16.26.0/24"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "172.16.26.0" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 172.16.26.0/24</a><br>> esp=3des-md5-96<br>> keyexchange=ike<br>> pfs=no<br>> authby=secret<br>> ikelifetime=7800
<br>> compress=no<br>> auto=start<br>><br>> include /etc/ipsec.d/no_oe.conf<br>><br>> ipsec.secrets<br>><br>> =========<br>><br>> <a href="http://165.98.224.82"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "165.98.224.82" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 165.98.224.82</a>
<a href="http://165.98.236.214"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "165.98.236.214" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 165.98.236.214</a>: PSK "vp17226"<br>><br>><br>><br>> Configuration for the router is:<br>><br>><br>><br>> crypto isakmp policy 10<br>> encr 3des<br>> hash md5
<br>> authentication pre-share<br>> crypto isakmp key vp17226 address <a href="http://165.98.224.82"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "165.98.224.82" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 165.98.224.82</a><br>> !<br>> !<br>> crypto ipsec transform-set DICE esp-3des esp-sha-hmac<br>> !<br>
> crypto map DICE 10 ipsec-isakmp<br>> set peer <a href="http://165.98.224.82"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "165.98.224.82" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 165.98.224.82</a><br>> set transform-set DICE<br>> match address 100<br>><br>> interface Ethernet1<br>> description PRIVADA
<br>> ip address <a href="http://165.98.236.214"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "165.98.236.214" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 165.98.236.214</a> <a href="http://255.255.255.252"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "255.255.255.252" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 255.255.255.252</a><br>> duplex auto<br>> crypto map DICE<br>><br>><br>><br>> Somebody can help me? I need suggestions.
<br>><br>><br>><br>> Thanks in Advanced.<br>><br>> Regards.<br>><br>_______________________________________________<br><a href="mailto:Users@openswan.org">Users@openswan.org</a><br><a href="http://lists.openswan.org/mailman/listinfo/users">
http://lists.openswan.org/mailman/listinfo/users</a><br>Building and Integrating Virtual Private Networks with Openswan:<br><a href="http://www.amazon.com/gp/product/1904811256/104-3099591-2946327?n=283155">http://www.amazon.com/gp/product/1904811256/104-3099591-2946327?n=283155
</a><br></blockquote></div><br>