<html>
<head>
<style><!--
.hmmessage P
{
margin:0px;
padding:0px
}
body.hmmessage
{
font-size: 10pt;
font-family:Tahoma
}
--></style>
</head>
<body class='hmmessage'>
Please check your iptables rulesets - your default policy on the OUTPUT chain is DROP ( which IMHO is very restrictive ). A "tcpdump" on the outside interface would give you some more insight into the IKE packet sent and received and any issues with firewall / fragmentation.<br> thanks. <br><br><span style="font-family: Tahoma,Helvetica,Sans-Serif; font-style: italic; font-weight: bold;">-<span style="font-family: Times New Roman,Times,Serif;"> Simon Charles - </span></span><br><br><br><br><br>> Date: Mon, 11 Apr 2011 11:57:39 -0400<br>> From: paul@xelerance.com<br>> To: crackhd2@gmail.com<br>> CC: users@openswan.org<br>> Subject: Re: [Openswan Users] 3DES-SHA still supported? What am I doing wrong?<br>> <br>> On Mon, 11 Apr 2011, Ben Schmidt wrote:<br>> <br>> > after I added "plutostderrlog=/var/log/pluto.log" in the config<br>> > Section of /etc/ipsec.conf and restarting openswan I got this log in<br>> > the newly created logfile: http://pastebin.com/cUZGR2z6<br>> <br>> It just shows the same. Your first packet is ignored. either it is<br>> filtered or the other side did not like it and did not respond. Check<br>> networking, firewalls and the configs on both ends. Easiest if you can<br>> get the remote end logs to see why it is ignoring you.<br>> <br>> Paul<br>> _______________________________________________<br>> Users@openswan.org<br>> http://lists.openswan.org/mailman/listinfo/users<br>> Micropayments: https://flattr.com/thing/38387/IPsec-for-Linux-made-easy<br>> Building and Integrating Virtual Private Networks with Openswan: <br>> http://www.amazon.com/gp/product/1904811256/104-3099591-2946327?n=283155<br>                                            </body>
</html>