<html>
<head>
<style type="text/css">
<!--
body { margin-top: 4px; margin-bottom: 1px; margin-right: 4px; margin-left: 4px; line-height: normal; font-variant: normal }
p { margin-top: 0; margin-bottom: 0 }
-->
</style>
</head>
<body style="margin-top: 4px; margin-bottom: 1px; margin-right: 4px; margin-left: 4px">
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">Hi,</font> </p>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">Thanks for the feedback,unfortunately no success, will keyingtries=0 work??</font> </p>
<br>
<p style="margin-bottom: 0; margin-top: 0">
<font size="2" face="Dialog">Kind Regards</font><br><br>>>> "Juan Pablo" <jp.espino@gmail.com> 06/22/07 1:26 AM >>><br>Hi,<br><br>Try with ike_lifetime = 28800 sec and ipsec_lifetime=3600 in both ends<br>and see if it works. Also try to capture traffic with<br>Ethereal/Wireshark or something similar when you lose the connection.<br><br>On 6/20/07, Peter Njiiri <pnjiiri@novell.ae> wrote:<br>><br>><br>> Hi<br>><br>> ikelifetime is commented out thus I presume it might be taking the default:<br>><br>><br>> conn %default<br>><br>> # Default: %forever (try forever)<br>><br>> #keyingtries=3<br>><br>> # Sig keys (default: %dnsondemand)<br>><br>> leftrsasigkey=%cert<br>><br>> rightrsasigkey=%cert<br>><br>> # Lifetimes, defaults are 1h/8hrs<br>><br>> #ikelifetime=20m<br>><br>> #keylife=1h<br>><br>> #rekeymargin=8m<br>> ipsec auto --status log excerpt is below (I've omitted certificate<br>> information):<br>><br>><br>> 000 interface lo/lo ::1<br>><br>> 000 interface lo/lo ::1<br>><br>> 000 interface lo/lo 127.0.0.1<br>><br>> 000 interface lo/lo 127.0.0.1<br>><br>> 000 interface eth1/eth1 10.30.7.9<br>><br>> 000 interface eth1/eth1 10.30.7.9<br>><br>> 000 %myid = (none)<br>><br>> 000 debug none<br>><br>> 000<br>><br>> 000 "hamadtownzen01":   ike_life: 3600s; ipsec_life: 28800s; rekey_margin:<br>> 540s; rekey_fuzz: 100%; keyingtries: 3<br>><br>> 000 "hamadtownzen01":   policy: RSASIG+ENCRYPT+TUNNEL+PFS+UP; prio: 32,24;<br>> interface: eth1;<br>><br>> 000 "hamadtownzen01":   newest ISAKMP SA: #1; newest IPsec SA: #2;<br>><br>> 000<br>><br>> 000 #2: "hamadtownzen01" STATE_QUICK_I2 (sent QI2, IPsec SA established);<br>> EVENT_SA_REPLACE in 26826s; newest IPSEC; eroute owner<br>><br>> 000 #2: "hamadtownzen01" esp.f3f82e06@10.30.2.10 esp.de5fa75d@10.30.7.9<br>> tun.0@10.30.2.10 tun.0@10.30.7.9<br>><br>> 000 #1: "hamadtownzen01" STATE_MAIN_I4 (ISAKMP SA established);<br>> EVENT_SA_REPLACE in 1995s; newest ISAKMP<br>><br>> 000<br>><br>><br>> Kind Regards<br>><br>> Peter<br>><br>><br>> >>> "Juan Pablo" <jp.espino@gmail.com> 06/19/07 11:07 PM >>><br>><br>> Hi,<br>><br>> Every 6 or 7 hours mmmm it sounds to me a Main Mode re-negotiation<br>> issue. What is the value for ikelifetime?, let us see some logs also.<br>><br>> On 6/19/07, Peter Njiiri <pnjiiri@novell.ae> wrote:<br>> > Hi Kevin<br>> > The two servers are connected via a WAN. The Internet connection is<br>> constantly on and I noticied that the tunnel disconnects after some hours,<br>> 6hrs or 7 hrs. Will check if the rekey=yes works otherwise, are there other<br>> recommendations you have for this issue?<br>> ><br>> > Thanks for the feedback,Peter!<br>> ><br>> > >>> Kevin <kevin@sepit.com.au>  >>><br>> > What type of internet connections are each endpoint using and how stable<br>> > are they?  I ask this because I had problems with tunnels apparently not<br>> > staying up and it turned out that the internet connection dropping out<br>> > even for a very short time was causing the problem.<br>> ><br>> > Regards<br>> > Kevin<br>> ><br>> > Paul Wouters wrote:<br>> ><br>> > >On Mon, 18 Jun 2007, Peter Njiiri wrote:<br>> > ><br>> > ><br>> > ><br>> > >>The connection is Gatewat-to_gateway connection using FreeSwan<br>> (ipsec.conf) will adding the rekey=yes line work for FreeSwan? Thanks for<br>> the feedback<br>> > >><br>> > >><br>> > ><br>> > >See below on the remark when one of the endpoints is on dynamic ip<br>> (roadwarrior).<br>> > >AFAIK, freeswan also had rekey=yes as the default, so i dont think it is<br>> going to help you.<br>> > ><br>> > >freeswan is unsupported and has not seen all required security patches.<br>> You should migrate<br>> > >to openswan.<br>> > ><br>> > >Paul<br>> > ><br>> > ><br>> > ><br>> > >>Regards,Peter<br>> > >><br>> > >><br>> > >><br>> > >>>>>Paul Wouters <paul@xelerance.com>  >>><br>> > >>>>><br>> > >>>>><br>> > >>On Mon, 18 Jun 2007, Peter Njiiri wrote:<br>> > >><br>> > >><br>> > >><br>> > >>>I just need to know how a persistent connection can be established when<br>> VPN is up. I always have to restart the VPN after some hours as it seems<br>> that the SA connection/handshake is dropped?Is there a line that can be<br>> added into the ipsec.conf file??? I need the VPN to be running consistently<br>> 24-7?<br>> > >>><br>> > >>><br>> > >>If you use rekey=yes (the default!) then it should work already. If this<br>> is a roadwarrior connection,<br>> > >>then the roadwarrior has to initiate the rekey and the server should use<br>> rekey=no.<br>> > >><br>> > >>Paul<br>> > >><br>> > >><br>> > >><br>> > ><br>> > ><br>> > ><br>> ><br>> ><br>> > --<br>> > This message has been scanned for viruses and<br>> > dangerous content by MailScanner, and is<br>> > believed to be clean.<br>> ><br>> > _______________________________________________<br>> > Users@openswan.org<br>> > <a href="http://lists.openswan.org/mailman/listinfo/users">http://lists.openswan.org/mailman/listinfo/users</a><br>> > Building and Integrating Virtual Private Networks with Openswan:<br>> ><br>> <a href="http://www.amazon.com/gp/product/1904811256/104">http://www.amazon.com/gp/product/1904811256/104</a>-3099591-2946327?n=283155<br>> ><br>> > _______________________________________________<br>> > Users@openswan.org<br>> > <a href="http://lists.openswan.org/mailman/listinfo/users">http://lists.openswan.org/mailman/listinfo/users</a><br>> > Building and Integrating Virtual Private Networks with Openswan:<br>> ><br>> <a href="http://www.amazon.com/gp/product/1904811256/104">http://www.amazon.com/gp/product/1904811256/104</a>-3099591-2946327?n=283155<br>> ><br>><br>><br>> --<br>> Juan Pablo<br>><br>><br>><br>
</p>
</body>
</html>