<html dir="ltr"><head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style title="owaParaStyle"><!--P {
        MARGIN-TOP: 0px; MARGIN-BOTTOM: 0px
}
--></style>
</head>
<body ocsi="x">
<div dir="ltr"><font face="Tahoma" color="#000000" size="2">Hi all,</font></div>
<div dir="ltr"><font face="tahoma" size="2"></font> </div>
<div dir="ltr"><font face="tahoma" size="2">we have the following problem(s).</font></div>
<div dir="ltr"><font face="tahoma" size="2"></font> </div>
<div dir="ltr"><font face="tahoma" size="2">We have a DUT (device under test) which has a known bug regarding IPSec rekeying, if initiated by OpenSwan. So we thought about using "rekey=no" in OpenSwan as a workaround.</font></div>
<div dir="ltr"><font face="tahoma" size="2"></font> </div>
<div dir="ltr"><font face="tahoma" size="2">1) We expect OpenSwan to never initiate rekeying. But OpenSwan will do rekeying, if asked to. Is this assumtion correct?</font></div>
<div dir="ltr"><font face="tahoma" size="2"></font> </div>
<div dir="ltr"><font face="tahoma" size="2">2) Every time the DUT tries to initiate rekeying, we get the following message:</font></div>
<div dir="ltr"><font face="tahoma" size="2"></font> </div>
<div dir="ltr"><span lang="DE">
<p>Mar 3 14:49:21 ipsectest pluto[19759]: "vpnk"[5] 172.30.64.140 #5: cannot install eroute -- it is in use for "vpnk"[4] 172.30.64.140 #4</p>
<p><font face="times new roman"></font> </p>
<p><font face="times new roman">Any idea what is going wrong?</font></p>
<p><font face="times new roman"></font> </p>
<p><font face="times new roman">Kind Regards,</font></p>
<p><font face="times new roman"></font> </p>
<p><font face="times new roman">Michael</font></p>
<p><font face="times new roman"></font> </p>
<p><font face="times new roman">PS: ipsec.conf and logfile as attachement</font></p>
<p><font face="times new roman"></font> </p>
<p> </p>
</span></div>
<div dir="ltr"><font face="tahoma" size="2"></font> </div>
</body>
</html>