<div>Dear all:</div>
<div> </div>
<div>my client box openswan is 2.4.9 version which runs on arm linux 2.4.19. </div>
<div> </div>
<div>the server log is as follows:</div>
<div>2007-10-11 09:55:49 system info 00536 IKE<<a href="http://61.30.115.91">61.30.115.91</a>> Phase 2 msg ID <1870a061>: Responded to the peer's first message from user <CN=IPSEC,OU=Support,O=Dawningtech,L=Taipei,ST=Taiwan,C=TW>.
<br>2007-10-11 09:55:34 system info 00536 IKE<<a href="http://61.30.115.91">61.30.115.91</a>> Phase 2 msg ID <1ec5c04a>: Responded to the peer's first message from user <CN=IPSEC,OU=Support,O=Dawningtech,L=Taipei,ST=Taiwan,C=TW>.
<br>2007-10-11 09:54:58 system info 00536 IKE<<a href="http://61.30.115.91">61.30.115.91</a>> Phase 2 msg ID <1ec5c04a>: Responded to the peer's first message from user <CN=IPSEC,OU=Support,O=Dawningtech,L=Taipei,ST=Taiwan,C=TW>.
<br>2007-10-11 09:54:45 system info 00536 IKE<<a href="http://61.30.115.91">61.30.115.91</a>> Phase 1: Completed Main mode negotiations with a <28800>-second lifetime.<br>2007-10-11 09:54:45 system info 00536 IKE<
<a href="http://61.30.115.91">61.30.115.91</a>> Phase 1: Completed for user <CN=IPSEC,OU=Support,O=Dawningtech,L=Taipei,ST=Taiwan,C=TW>.</div>
<div>----------------------------------------------------------------------------------------------------------------------------------------------------------------------</div>
<div>what happened with the client ?</div>
<div> </div>
<div>Can anyone give me a suggestion?</div>
<div> </div>
<div>my ipsec.conf is </div>
<div>
<p>config setup<br> # Debug-logging controls: "none" for (almost) none, "all" for lots.<br> klipsdebug=all<br> plutodebug=all<br> nat_traversal=yes<br> interfaces="%defaultroute"
</p>
<p>include /etc/ipsec.d/no_oe.conf<br> <br>conn dawn-net<br> authby=rsasig<br> esp=3DES-SHA1<br> left=%defaultroute<br> leftsubnet=<a href="http://192.168.1.0/24">192.168.1.0/24</a><br> leftnexthop=%defaultroute
<br> leftcert=/etc/ipsec.d/mycert2.pem<br> leftrsasigkey=%cert<br> right=<a href="http://211.78.84.93">211.78.84.93</a><br> rightid="@<a href="http://SSG550.sti.com.tw">SSG550.sti.com.tw</a>"
<br> rightsubnet=<a href="http://10.2.111.0/24">10.2.111.0/24</a><br> rightnexthop=%defaultroute <br> auto=add<br> pfs=no<br></p></div>
<div> </div>