<div>Hi.</div>
<div>I have problem with 1 VPN connection. </div>
<div>I need VPN connection between <a href="http://192.168.0.0/24">192.168.0.0/24</a> and <a href="http://2.2.2.2">2.2.2.2</a>.</div>
<div><a href="http://192.168.0.0/24===1.1.1.1---1.1.1.1.11..INTERNET..2.2.2.2">192.168.0.0/24===1.1.1.1---1.1.1.1.11..INTERNET..2.2.2.2</a></div>
<div>VPN server(<a href="http://1.1.1.1">1.1.1.1</a>) crashes often.</div>
<div> </div>
<div>The last DEBUG messages(plutodebug=all) states about 'conn A-B' before <a href="http://1.1.1.1">1.1.1.1</a> crash.<br><br>VPN server 1.1.1.1(openswan 2.4.9):<br>conn A-B<br> type=tunnel<br> compress=yes
<br> auto=start<br> authby=rsasig<br> auth=esp<br> esp=3des-md5<br> pfs=yes<br> <a href="mailto:leftid=@A_B">leftid=@A_B</a><br> left=<a href="http://1.1.1.1">1.1.1.1</a><br>
leftnexthop=1.1.1.1.11<br> leftsubnet=<a href="http://192.168.0.0/24">192.168.0.0/24</a><br> leftrsasigkey=...<br> <a href="mailto:rightid=@B_A">rightid=@B_A</a><br> right=<a href="http://2.2.2.2">
2.2.2.2</a><br> rightrsasigkey=...<br><br>VPN server 2.2.2.2(openswan 2.4.7)<br>conn A-B<br> type=tunnel<br> compress=yes<br> auto=start<br> authby=rsasig<br> auth=esp<br> esp=3des-md5
<br> pfs=yes</div>
<div> <a href="mailto:leftid=@B_A">leftid=@B_A</a><br> left=<a href="http://2.2.2.2">2.2.2.2</a><br> leftrsasigkey=...<br> <a href="mailto:rightid=@A_B">rightid=@A_B</a><br> right=<a href="http://1.1.1.1">
1.1.1.1</a><br> rightnexthop=1.1.1.1.11<br> rightsubnet=<a href="http://192.168.0.0/24">192.168.0.0/24</a><br> rightrsasigkey=...<br><br>I don't know why there are some strings with '(IPsec SA established)'.
</div>
<div><br>000 "A-B": <a href="http://192.168.0.0/24===1.1.1.1[@A_B]---1.1.1.1.11..2.2.2.2[@B_A]">192.168.0.0/24===1.1.1.1[@A_B]---1.1.1.1.11..2.2.2.2[@B_A]</a>; erouted; eroute owner: #40<br>000 "A-B": srcip=unset; dstip=unset; srcup=ipsec _updown; dstup=ipsec _updown;
<br>000 "A-B": ike_life: 3840s; ipsec_life: 28800s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0<br>000 "A-B": policy: RSASIG+ENCRYPT+COMPRESS+TUNNEL+PFS+UP; prio: 24,32; interface: eth1; encap: esp;
<br>000 "A-B": newest ISAKMP SA: #35; newest IPsec SA: #40;<br>000 "A-B": IKE algorithm newest: 3DES_CBC_192-MD5-MODP1536<br>000 "A-B": ESP algorithms wanted: 3DES(3)_000-MD5(1); flags=strict
<br>000 "A-B": ESP algorithms loaded: 3DES(3)_000-MD5(1); flags=strict<br>000 "A-B": ESP algorithm newest: 3DES_0-HMAC_MD5; pfsgroup=<Phase1><br>000 #40: "A-B":500 STATE_QUICK_R2 (IPsec SA established); EVENT_SA_REPLACE in 28251s; newest IPSEC; eroute owner
<br>000 #40: "A-B" used 222s ago; <a href="mailto:esp.e8caf0de@2.2.2.2">esp.e8caf0de@2.2.2.2</a> <a href="mailto:esp.4030d46a@1.1.1.1">esp.4030d46a@1.1.1.1</a> <a href="mailto:tun.1018@2.2.2.2">tun.1018@2.2.2.2</a>
<a href="mailto:tun.1016@1.1.1.1">tun.1016@1.1.1.1</a><br>000 #39: "A-B":500 STATE_QUICK_R2 (IPsec SA established); EVENT_SA_REPLACE in 28243s<br>000 #39: "A-B" <a href="mailto:esp.e8caf0dd@2.2.2.2">esp.e8caf0dd@2.2.2.2
</a> <a href="mailto:esp.4030d469@1.1.1.1">esp.4030d469@1.1.1.1</a> <a href="mailto:tun.1017@2.2.2.2">tun.1017@2.2.2.2</a> <a href="mailto:tun.1015@1.1.1.1">tun.1015@1.1.1.1</a><br>000 #35: "A-B":500 STATE_MAIN_R3 (sent MR3, ISAKMP SA established); EVENT_SA_REPLACE in 3239s; newest ISAKMP; lastdpd=-1s(seq in:0 out:0)
<br>000 #38: "A-B":500 STATE_QUICK_I2 (sent QI2, IPsec SA established); EVENT_SA_REPLACE in 27906s<br>000 #38: "A-B" <a href="mailto:esp.e8caf0df@2.2.2.2">esp.e8caf0df@2.2.2.2</a> <a href="mailto:esp.4030d468@1.1.1.1">
esp.4030d468@1.1.1.1</a> <a href="mailto:tun.1014@2.2.2.2">tun.1014@2.2.2.2</a> <a href="mailto:tun.1013@1.1.1.1">tun.1013@1.1.1.1</a><br>000 #37: "A-B":500 STATE_MAIN_I4 (ISAKMP SA established); EVENT_SA_REPLACE in 2641s; lastdpd=-1s(seq in:0 out:0)
</div>
<div> </div>
<div>I think that problem is in routing table:</div>
<div><a href="http://1.1.1.1">1.1.1.1</a>>ip route show | grep <a href="http://2.2.2.2">2.2.2.2</a><br><a href="http://2.2.2.2">2.2.2.2</a> via <a href="http://1.1.1.11">1.1.1.11</a> dev ipsec0</div>
<div> </div>
<div><a href="http://1.1.1.1">1.1.1.1</a> VPN server:</div>
<div>IP traffic go to <a href="http://2.2.2.2">2.2.2.2</a> through dev ipsec0.</div>
<div>But traffic go from <a href="http://2.2.2.2">2.2.2.2</a> through eth0.<br> </div>
<div>How can I resolve my problem? change routing? or ipsec.conf?</div>
<div>Thank you!</div>