<html>
<head>
<meta content="text/html; charset=ISO-8859-15"
http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<div class="moz-cite-prefix"><font face="DejaVu Sans Mono">Hello
Leto,<br>
<br>
<font face="DejaVu Sans Mono">Thanks for your answer. <br>
<br>
<font face="DejaVu Sans Mono">I tried to <font face="DejaVu
Sans Mono">enable debug for klips dynamically using "ipsec
whack --name<font face="DejaVu Sans Mono"> mcz
--debug-klips" while a ping was running and the eroute
counter was inc<font face="DejaVu Sans Mono"><font
face="DejaVu Sans Mono">r</font>emented, but I got
no trace in the <font face="DejaVu Sans Mono">log...<br>
<br>
I cannot set klipsdebug in <font face="DejaVu Sans
Mono">ipsec.conf because: (1) the <font
face="DejaVu Sans Mono">problem happens <font
face="DejaVu Sans Mono">infrequently</font>
(about once a week), (2) big amount of data <font
face="DejaVu Sans Mono">flows</font> in that
connection each night and (3) if I restart ipsec
everything works until the next blocking point.<br>
<br>
<font face="DejaVu Sans Mono">I'm stuck<font
face="DejaVu Sans Mono">!<br>
<br>
<font face="DejaVu Sans Mono">Best regards,</font><br>
</font></font></font></font></font></font></font></font></font></font></font>
<div class="moz-signature">--<br>
<font color="#000000">Francis<br>
</font><br>
<br>
</div>
Le 10/03/2013 21:42, Leto a écrit :<br>
</div>
<blockquote
cite="mid:90AE7C13-CCAC-4694-B5A0-2B9E4355D379@gmail.com"
type="cite">
<pre wrap="">if that happened, check with ipsec eroute, and for a few seconds do ipsec klipsdebug --all followed by --none and then check dmesg for information
On the road...
On 2013-03-10, at 6:01, <a class="moz-txt-link-abbreviated" href="mailto:fg@numlog.fr">fg@numlog.fr</a> wrote:
</pre>
<blockquote type="cite">
<pre wrap="">Hello,
I use Openswan 2.6.38 (klips) in a virtual machine based on UML with kernel version 2.6.35.13-uml.
>From time to time (about once a week), there is no traffic flowing across the eroutes. ISAKMP is apparently running smoothly (in the log re-keying is OK, DPD also and the eroutes are present).
Any clue on the way to investigate ?
Thanks in advance and best regards,
Francis
_______________________________________________
<a class="moz-txt-link-abbreviated" href="mailto:Users@lists.openswan.org">Users@lists.openswan.org</a>
<a class="moz-txt-link-freetext" href="https://lists.openswan.org/mailman/listinfo/users">https://lists.openswan.org/mailman/listinfo/users</a>
Micropayments: <a class="moz-txt-link-freetext" href="https://flattr.com/thing/38387/IPsec-for-Linux-made-easy">https://flattr.com/thing/38387/IPsec-for-Linux-made-easy</a>
Building and Integrating Virtual Private Networks with Openswan:
<a class="moz-txt-link-freetext" href="http://www.amazon.com/gp/product/1904811256/104-3099591-2946327?n=283155">http://www.amazon.com/gp/product/1904811256/104-3099591-2946327?n=283155</a>
</pre>
</blockquote>
</blockquote>
<br>
</body>
</html>