<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style>
<!--
@font-face
        {font-family:"Cambria Math"}
@font-face
        {font-family:Calibri}
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif"}
a:link, span.MsoHyperlink
        {color:blue;
        text-decoration:underline}
a:visited, span.MsoHyperlinkFollowed
        {color:purple;
        text-decoration:underline}
span.EmailStyle17
        {font-family:"Arial","sans-serif";
        color:windowtext}
.MsoChpDefault
        {}
@page WordSection1
        {margin:70.85pt 2.0cm 2.0cm 2.0cm}
div.WordSection1
        {}
-->
</style>
</head>
<body lang="IT" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:10.0pt; font-family:"Arial","sans-serif"">Hello All!</span></p>
<p class="MsoNormal"><span style="font-size:10.0pt; font-family:"Arial","sans-serif""> </span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">It can happen that after a rekey I do get an “incomplete” xfrm policy (see below for an example).</span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">I call it “incomplete” because it’s missing the the “tmpl […] proto […]” part.</span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">Unfortunately I’m unable to replicate this problem at will.</span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> </span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> </span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">I’m running OpenSWAN 2.6.37 on a CentOS 5.3</span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> </span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span style="font-size:10.0pt; font-family:"Arial","sans-serif""># ipsec --version</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">Linux Openswan U2.6.37/K2.6.18-128.2.1.el5 (netkey)</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> </span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span style="font-size:10.0pt; font-family:"Arial","sans-serif""># [root@saas-vpn1 e1000 ipsec.d]# uname -a</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">Linux openswan1 2.6.18-128.2.1.el5 #1 SMP Tue Jul 14 06:36:37 EDT 2009 x86_64 x86_64 x86_64 GNU/Linux<br>
<br>
</span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> </span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">This is the VPN configuration:</span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> </span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""># cat /etc/ipsec.conf</span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> </span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">#</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""># Manual: ipsec.conf.5</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">#</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""># Please place your own config files in /etc/ipsec.d/ ending in .conf</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> </span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">version 2.0 # conforms to second version of ipsec.conf specification</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> </span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""># basic configuration</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">config setup</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> # Debug-logging controls: "none" for (almost) none, "all" for lots.</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> # klipsdebug=none</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> # plutodebug="control parsing"</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> # For Red Hat Enterprise Linux and Fedora, leave protostack=netkey</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> protostack=netkey</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> nat_traversal=yes</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> virtual_private=</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> oe=off</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> # Enable this if you see "failed to find any available worker"</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> nhelpers=0</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> </span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">#You may put your configuration (.conf) file in the "/etc/ipsec.d/" and uncomment this.</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">include /etc/ipsec.d/*.conf</span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> </span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""># cat /etc/ipsec.d/remote1.conf</span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> </span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">conn REMOTE1</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> leftsubnets={10.112.8.128/27 10.112.4.0/26}</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> rightsubnets={192.168.255.0/24}</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> left=<left-public-ip></span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> right=<right-public-ip></span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> auto=add</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> authby=secret</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> type=tunnel</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> ike=3des-sha1-modp1024</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> ikelifetime=28800s</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> pfs=yes</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> aggrmode=no</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> phase2=esp</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> phase2alg=aes-sha1-1024,aes128-sha1-1024,aes256-sha1-1024</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> keyingtries=0</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> salifetime=1800s</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> rekey=yes</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> dpddelay=30</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> dpdtimeout=120</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> dpdaction=restart_by_peer</span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> </span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> </span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">Policies dump</span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> </span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""># ip xfrm policy show</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> </span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">[…]</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">>>>>---Incomplete policy----<<<<</span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">src 10.112.8.129/32 dst 192.168.255.125/32 proto udp
</span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> dir out priority 2080
</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">>>>>---Incomplete policy----<<<<</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">[…]</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">---Working policies----</span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">src 192.168.255.0/24 dst 10.112.8.128/27
</span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> dir in priority 2248
</span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> tmpl src <right-remote-ip> dst <left-remote-ip></span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> proto esp reqid 17565 mode tunnel</span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> </span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">src 192.168.255.0/24 dst 10.112.4.0/26
</span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> dir in priority 2280
</span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> tmpl src <right-remote-ip> dst <left-remote-ip></span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> proto esp reqid 17569 mode tunnel</span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> </span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">src 10.112.8.128/27 dst 192.168.255.0/24
</span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> dir out priority 2248
</span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> tmpl src <left-remote-ip> dst <right-remote-ip></span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> proto esp reqid 17565 mode tunnel</span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> </span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">src 10.112.4.0/26 dst 192.168.255.0/24
</span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> dir out priority 2280
</span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> tmpl src <left-remote-ip> dst <right-remote-ip></span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> proto esp reqid 17569 mode tunnel</span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> </span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">src 192.168.255.0/24 dst 10.112.8.128/27
</span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> dir fwd priority 2248
</span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> tmpl src <right-remote-ip> dst <left-remote-ip></span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> proto esp reqid 17565 mode tunnel</span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> </span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">src 192.168.255.0/24 dst 10.112.4.0/26
</span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> dir fwd priority 2280
</span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> tmpl src <right-remote-ip> dst <left-remote-ip></span></p>
<p class="MsoNormal" style="margin-left:70.8pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> proto esp reqid 17569 mode tunnel</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">---Working policies----</span></p>
<p class="MsoNormal" style="margin-left:35.4pt"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">[…]</span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> </span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">Best regards,</span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif""> </span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:10.0pt; font-family:"Arial","sans-serif"">Giovanni.</span></p>
</div>
<p style="margin-bottom:8.0pt; margin-top:0.0pt"><span lang="EN-GB" style="font-size:8.0pt; font-family:'Arial',sans-serif; color:#535353; font-style:italic"><br>
<br>
<br>
Any use, distribution, copying or disclosure by any other person than the intended recipient of this electronic mail transmission is prohibited as a criminal offence.<br>
Pursuant to Legislative Decree n. 196/2003, you are hereby informed that this message and its attachments contain confidential information intended only for the use of the addressee.<br>
If you receive this transmission in error, please inform the sender immediately and delete the material. Thank You.
</span></p>
<p style="margin-top:0.0pt"><span lang="EN-GB" style="font-size:8.0pt; font-family:'Arial',sans-serif; color:#535353; font-style:italic">The information contained in the e-mail can’t be considered authorized by Reitek SpA in front of the addressee or third
parties. Reitek SpA has no responsibility in case of dissemination, duplication or damage of this communication.
</span></p>
</body>
</html>