<br><br>
<div><span class="gmail_quote">2007/10/11, Paul Wouters <<a href="mailto:paul@xelerance.com">paul@xelerance.com</a>>:</span></div>
<blockquote class="gmail_quote" style="PADDING-LEFT: 1ex; MARGIN: 0px 0px 0px 0.8ex; BORDER-LEFT: #ccc 1px solid">On Thu, 11 Oct 2007, ??? wrote:<br><br>> my client box openswan is 2.4.9 version which runs on arm linux
2.4.19.<br>><br>> the server log is as follows:<br>> 2007-10-11 09:55:49 system info 00536 IKE<<a href="http://61.30.115.91">61.30.115.91</a>> Phase 2 msg ID<br>> <1870a061>: Responded to the peer's first message from user
<br>> <CN=IPSEC,OU=Support,O=Dawningtech,L=Taipei,ST=Taiwan,C=TW>.<br>> 2007-10-11 09:55:34 system info 00536 IKE<<a href="http://61.30.115.91">61.30.115.91</a>> Phase 2 msg ID<br>> <1ec5c04a>: Responded to the peer's first message from user
<br>> <CN=IPSEC,OU=Support,O=Dawningtech,L=Taipei,ST=Taiwan,C=TW>.<br>> 2007-10-11 09:54:58 system info 00536 IKE<<a href="http://61.30.115.91">61.30.115.91</a>> Phase 2 msg ID<br>> <1ec5c04a>: Responded to the peer's first message from user
<br>> <CN=IPSEC,OU=Support,O=Dawningtech,L=Taipei,ST=Taiwan,C=TW>.<br>> 2007-10-11 09:54:45 system info 00536 IKE<<a href="http://61.30.115.91">61.30.115.91</a>> Phase 1:<br>> Completed Main mode negotiations with a <28800>-second lifetime.
<br>> 2007-10-11 09:54:45 system info 00536 IKE<<a href="http://61.30.115.91">61.30.115.91</a>> Phase 1:<br>> Completed for user<br>> <CN=IPSEC,OU=Support,O=Dawningtech,L=Taipei,ST=Taiwan,C=TW>.
<br><br>I am not sure. what does the openswan end say?<br><br>> conn dawn-net<br>> authby=rsasig<br>> esp=3DES-SHA1<br>> left=%defaultroute<br>> leftsubnet=<a href="http://192.168.1.0/24">
192.168.1.0/24</a><br>> leftnexthop=%defaultroute<br>> leftcert=/etc/ipsec.d/mycert2.pem<br>> leftrsasigkey=%cert<br>> right=<a href="http://211.78.84.93">211.78.84.93</a><br>> rightid="@
<a href="http://SSG550.sti.com.tw">SSG550.sti.com.tw</a>"<br>> rightsubnet=<a href="http://10.2.111.0/24">10.2.111.0/24</a><br>> rightnexthop=%defaultroute<br>> auto=add<br>> pfs=no
<br><br>It's very unusual to use certificates and specify a rightid= that's not a full DN<br>while using no leftid= (and thus a DN)</blockquote>
<div> </div>
<div>If I didn't specify rightid="@...", during phase I process,it will stop and show "invalid ID...",the same ipsec.conf can be run on x86 linux machine.</div>
<div> </div>
<div>the attached file are up1.txt(while up my service log )/ping1.txt </div>
<div> </div>
<div>After up the net-to-net service, the route -n is as follows</div>
<div> $ route -n<br>Kernel IP routing table<br>Destination Gateway Genmask Flags Metric Ref Use Iface<br><a href="http://192.168.1.0">192.168.1.0</a> <a href="http://0.0.0.0">0.0.0.0</a>
<a href="http://255.255.255.0">255.255.255.0</a> U 0 0 0 eth0<br><a href="http://192.168.1.0">192.168.1.0</a> <a href="http://0.0.0.0">0.0.0.0</a> <a href="http://255.255.255.0">255.255.255.0
</a> U 0 0 0 ipsec0<br><a href="http://10.2.111.0">10.2.111.0</a> <a href="http://192.168.1.233">192.168.1.233</a> <a href="http://255.255.255.0">255.255.255.0</a> UG 0 0 0 ipsec0
<br><a href="http://0.0.0.0">0.0.0.0</a> <a href="http://192.168.1.233">192.168.1.233</a> <a href="http://0.0.0.0">0.0.0.0</a> UG 0 0 0 eth0<br> </div>
<blockquote class="gmail_quote" style="PADDING-LEFT: 1ex; MARGIN: 0px 0px 0px 0.8ex; BORDER-LEFT: #ccc 1px solid">Show the output of: ipsec auto replace dawn-net ; ipsec auto --up dawn-net<br>--<br>Building and integrating Virtual Private Networks with Openswan:
<br><a href="http://www.amazon.com/gp/product/1904811256/104-3099591-2946327?n=283155">http://www.amazon.com/gp/product/1904811256/104-3099591-2946327?n=283155</a><br></blockquote><br>