<div>HI Paul,<br><br>I did as you said, but didn&#39;t work.<br>The client can&#39;t connect to server. If I remove<span style="font-family: monospace;"> </span>rekey=no it connect to server.<br><br>Any idea ?<br><br>Thanks.
<br><br>-- <br>Frederico Madeira<br><a href="mailto:fmadeira@gmail.com">fmadeira@gmail.com</a><br><a href="http://www.madeira.eng.br">www.madeira.eng.br</a>
<br>
<pre>-------- Mensagem encaminhada --------<br>De: Paul Wouters &lt;<a href="mailto:paul@xelerance.com" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">paul@xelerance.com</a>&gt;<br>Para: Frederico Madeira &lt;
<a href="mailto:fmadeira@gmail.com" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">fmadeira@gmail.com</a>&gt;<br>Cc: <a href="mailto:users@openswan.org" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
users@openswan.org</a><br>Assunto: Re: [Openswan Users] IP cache on ADSL Connections<br>Data: Thu, 8 Nov 2007 19:14:34 -0500 (EST)<br><br>On Thu, 8 Nov 2007, Frederico Madeira wrote:<br><br>&gt; I added this parameter on both 
ipsec.conf, after this the tunnel didn&#39;t came up.<br><br>the side with rekey=no needs to use auto=add, as it cannot start.<br><br>Paul<br><br>&gt; I got this in logs<br>&gt;<br>&gt; Nov  8 17:04:33 vpn pluto[12245]: packet from 
<a href="http://189.70.198.203:500" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">189.70.198.203:500</a>:<br>&gt; initial Main Mode message received on <a href="http://201.36.53.68:500" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
201.36.53.68:500</a> but no<br>&gt; connection has been authorized<br>&gt; Nov  8 17:05:13 vpn pluto[12245]: packet from <a href="http://189.70.198.203:500" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
189.70.198.203:500</a>:<br>&gt; ignoring unknown Vendor ID payload [4f455a7e4261425d725c705f]<br>&gt; Nov  8 17:05:13 vpn pluto[12245]: packet from <a href="http://189.70.198.203:500" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
189.70.198.203:500</a>:<br>&gt; received Vendor ID payload [Dead Peer Detection]<br>&gt; Nov  8 17:05:13 vpn pluto[12245]: packet from <a href="http://189.70.198.203:500" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
189.70.198.203:500</a>:<br>&gt; received Vendor ID payload [RFC 3947] meth=109, but port floating is<br>&gt; off<br>&gt; Nov  8 17:05:13 vpn pluto[12245]: packet from <a href="http://189.70.198.203:500" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
189.70.198.203:500</a>:<br>&gt; received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03] meth=108,<br>&gt; but port floating is off<br>&gt; Nov  8 17:05:13 vpn pluto[12245]: packet from <a href="http://189.70.198.203:500" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
189.70.198.203:500</a>:<br>&gt; received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02] meth=107,<br>&gt; but port floating is off<br>&gt; Nov  8 17:05:13 vpn pluto[12245]: packet from <a href="http://189.70.198.203:500" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
189.70.198.203:500</a>:<br>&gt; received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n] meth=106,<br>&gt; but port floating is off<br>&gt; Nov  8 17:05:13 vpn pluto[12245]: packet from <a href="http://189.70.198.203:500" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
189.70.198.203:500</a>:<br>&gt; ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]<br>&gt; Nov  8 17:05:13 vpn pluto[12245]: packet from <a href="http://189.70.198.203:500" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
189.70.198.203:500</a>:<br>&gt; initial Main Mode message received on <a href="http://201.36.53.68:500" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">201.36.53.68:500</a> but no<br>&gt; connection has been authorized
<br>&gt;<br>&gt; Bellow my ipsec.conf:<br>&gt;<br>&gt; config setup<br>&gt;         # Debug-logging controls:  &quot;none&quot; for (almost) none, &quot;all&quot; for lots.<br>&gt;         # klipsdebug=none<br>&gt;         # plutodebug=&quot;control parsing&quot;
<br>&gt;         nat_traversal=yes<br>&gt;<br>&gt; include /etc/ipsec.d/*.conf<br>&gt;<br>&gt; conn client_to_server<br>&gt;     left=201.xx.xx.xx                # Local vitals<br>&gt;     leftsubnet=<a href="http://192.168.10.0/24" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
192.168.10.0/24</a>       #<br>&gt;     <a href="mailto:leftid=@vpn.server" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">leftid=@vpn.server</a>         #<br>&gt;     leftrsasigkey=0sAQPMugwfC6uU.........
<br>&gt;     leftnexthop=201.xx.xx.Xx      # correct in many situations<br>&gt;     right=<a href="http://host01.no-ip.org" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">host01.no-ip.org</a>            # Remote vitals
<br>&gt;     rightsubnet=<a href="http://192.168.20.0/24" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">192.168.20.0/24</a>        #<br>&gt;     <a href="mailto:rightid=@client.server" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
rightid=@client.server</a>        #<br>&gt;     rightrsasigkey=0sAQOmxV.......<br>&gt;     rightnexthop=%defaultroute     # correct in many situations<br>&gt;     auto=start                       # authorizes but doesn&#39;t start this
<br>&gt;                                    # connection at startup<br>&gt;<br>&gt; Thanks.<br>&gt;<br>&gt;<br><br></pre>
<table cellpadding="0" cellspacing="0" width="100%">
<tbody><tr>
<td>
<table cellpadding="0" cellspacing="0" width="100%">
<tbody><tr>
<td>
<b><font color="#000000">Frederico Madeira</font></b><br>
<a href="mailto:fred@fonar.com.br" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">fred@fonar.com.br</a><br>
<i><font color="#000000">Wivox / Fonar </font></i><br>
Tel: 55 81.3313.0005<br>
<tt>Cel 55.81.9959.2534 </tt><tt><font color="#800000">(NOVO)</font></tt>
</td>
</tr>
</tbody></table>
</td>
</tr>
</tbody></table>
</div>

<br clear="all"><br><br>