<html>
<head>
<style type="text/css">
<!--
body { font-variant: normal; margin-left: 4px; margin-top: 4px; margin-bottom: 1px; margin-right: 4px; line-height: normal }
p { margin-top: 0; margin-bottom: 0 }
-->
</style>
</head>
<body style="margin-left: 4px; margin-top: 4px; margin-right: 4px; margin-bottom: 1px">
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">Hi</font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">ikelifetime is commented out thus I presume it might be taking the default:</font> </p>
<br>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">conn %default</font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog"># Default: %forever (try forever)</font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">#keyingtries=3</font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog"># Sig keys (default: %dnsondemand)</font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">leftrsasigkey=%cert</font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">rightrsasigkey=%cert</font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog"># Lifetimes, defaults are 1h/8hrs</font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">#ikelifetime=20m</font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">#keylife=1h</font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">#rekeymargin=8m</font><br><font size="2" face="Dialog">ipsec auto --status log excerpt is below (I've omitted certificate information):</font> </p>
<br>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">000 interface lo/lo ::1</font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">000 interface lo/lo ::1</font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">000 interface lo/lo 127.0.0.1</font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">000 interface lo/lo 127.0.0.1</font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">000 interface eth1/eth1 10.30.7.9</font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">000 interface eth1/eth1 10.30.7.9</font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">000 %myid = (none)</font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">000 debug none</font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">000 </font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">000 "hamadtownzen01": ike_life: 3600s; ipsec_life: 28800s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 3</font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">000 "hamadtownzen01": policy: RSASIG+ENCRYPT+TUNNEL+PFS+UP; prio: 32,24; interface: eth1; </font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">000 "hamadtownzen01": newest ISAKMP SA: #1; newest IPsec SA: #2; </font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">000 </font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">000 #2: "hamadtownzen01" STATE_QUICK_I2 (sent QI2, IPsec SA established); EVENT_SA_REPLACE in 26826s; newest IPSEC; eroute owner</font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">000 #2: "hamadtownzen01" </font><a href="mailto:esp.f3f82e06@10.30.2.10"><u><font face="Dialog" color="#0000ff" size="2"><i>esp.f3f82e06@10.30.2.10</i></font></u></a><font size="2" face="Dialog"> </font><a href="mailto:esp.de5fa75d@10.30.7.9"><u><font face="Dialog" color="#0000ff" size="2"><i>esp.de5fa75d@10.30.7.9</i></font></u></a><font size="2" face="Dialog"> </font><a href="mailto:tun.0@10.30.2.10"><u><font face="Dialog" color="#0000ff" size="2"><i>tun.0@10.30.2.10</i></font></u></a><font size="2" face="Dialog"> </font><a href="mailto:tun.0@10.30.7.9"><u><font face="Dialog" color="#0000ff" size="2"><i>tun.0@10.30.7.9</i></font></u></a><font size="2" face="Dialog"></font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">000 #1: "hamadtownzen01" STATE_MAIN_I4 (ISAKMP SA established); EVENT_SA_REPLACE in 1995s; newest ISAKMP</font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">000 </font> </p>
<br>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">Kind Regards</font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">Peter</font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<br>
>>> "Juan Pablo" <jp.espino@gmail.com> 06/19/07 11:07 PM >>><br>Hi,<br><br>Every 6 or 7 hours mmmm it sounds to me a Main Mode re-negotiation<br>issue. What is the value for ikelifetime?, let us see some logs also.<br><br>On 6/19/07, Peter Njiiri <pnjiiri@novell.ae> wrote:<br>> Hi Kevin<br>> The two servers are connected via a WAN. The Internet connection is constantly on and I noticied that the tunnel disconnects after some hours, 6hrs or 7 hrs. Will check if the rekey=yes works otherwise, are there other recommendations you have for this issue?<br>><br>> Thanks for the feedback,Peter!<br>><br>> >>> Kevin <kevin@sepit.com.au>  >>><br>> What type of internet connections are each endpoint using and how stable<br>> are they?  I ask this because I had problems with tunnels apparently not<br>> staying up and it turned out that the internet connection dropping out<br>> even for a very short time was causing the problem.<br>><br>> Regards<br>> Kevin<br>><br>> Paul Wouters wrote:<br>><br>> >On Mon, 18 Jun 2007, Peter Njiiri wrote:<br>> ><br>> ><br>> ><br>> >>The connection is Gatewat-to_gateway connection using FreeSwan (ipsec.conf) will adding the rekey=yes line work for FreeSwan? Thanks for the feedback<br>> >><br>> >><br>> ><br>> >See below on the remark when one of the endpoints is on dynamic ip (roadwarrior).<br>> >AFAIK, freeswan also had rekey=yes as the default, so i dont think it is going to help you.<br>> ><br>> >freeswan is unsupported and has not seen all required security patches. You should migrate<br>> >to openswan.<br>> ><br>> >Paul<br>> ><br>> ><br>> ><br>> >>Regards,Peter<br>> >><br>> >><br>> >><br>> >>>>>Paul Wouters <paul@xelerance.com>  >>><br>> >>>>><br>> >>>>><br>> >>On Mon, 18 Jun 2007, Peter Njiiri wrote:<br>> >><br>> >><br>> >><br>> >>>I just need to know how a persistent connection can be established when VPN is up. I always have to restart the VPN after some hours as it seems that the SA connection/handshake is dropped?Is there a line that can be added into the ipsec.conf file??? I need the VPN to be running consistently 24-7?<br>> >>><br>> >>><br>> >>If you use rekey=yes (the default!) then it should work already. If this is a roadwarrior connection,<br>> >>then the roadwarrior has to initiate the rekey and the server should use rekey=no.<br>> >><br>> >>Paul<br>> >><br>> >><br>> >><br>> ><br>> ><br>> ><br>><br>><br>> --<br>> This message has been scanned for viruses and<br>> dangerous content by MailScanner, and is<br>> believed to be clean.<br>><br>> _______________________________________________<br>> Users@openswan.org<br>> <a href="http://lists.openswan.org/mailman/listinfo/users">http://lists.openswan.org/mailman/listinfo/users</a><br>> Building and Integrating Virtual Private Networks with Openswan:<br>> <a href="http://www.amazon.com/gp/product/1904811256/104">http://www.amazon.com/gp/product/1904811256/104</a>-3099591-2946327?n=283155<br>><br>> _______________________________________________<br>> Users@openswan.org<br>> <a href="http://lists.openswan.org/mailman/listinfo/users">http://lists.openswan.org/mailman/listinfo/users</a><br>> Building and Integrating Virtual Private Networks with Openswan:<br>> <a href="http://www.amazon.com/gp/product/1904811256/104">http://www.amazon.com/gp/product/1904811256/104</a>-3099591-2946327?n=283155<br>><br><br><br>--<br>Juan Pablo<br>
</p>
</body>
</html>