<HTML><BODY>Hi.<br><br>I have problem - tunnel up, but "left" side not ping (and telnet port) to rigth side. Trafic from "right" to "left" side all ok.<br><br>extip_cisco=IP cisco<br>extip_linux=IP Linux<br><br>shema:<br><br>10.0.0.0/21<----->eth0-(Linux 2.6.23.17-88.fc7)-eth1--<extip_linux>-------(ipsec)---------<extip_cisco>-----<cisco>-----<192.168.0.0/16><br><br>cat /etc/ipsec.conf<br> config setup<br> include /etc/ipsec.d/*.conf<br>cat /etc/ipsec.d/shlum.conf<br><br><br>conn shlum<br> type=tunnel<br> authby=secret<br> left=extip_linux<br> leftsubnet=10.0.0.0/21<br> leftsourceip=extip_linux<br> right=extip_cisco<br> rightsubnet=192.168.0.0/16<br> leftid=extip_linux<br> leftnexthop=%defaultroute<br> rightid=extip_cisco<br> rightnexthop=%direct<br> pfs=no<br> forceencaps = yes<br> ike = aes128-sha1,aes128-md5,3des-md5,3des-sha1<br> esp = aes128-md5,aes128-sha1,aes256,3des-md5,3des<br> keyexchange = ike<br> auto=start<br><br><br>service ipsec start<br> Starting Openswan IPsec 2.4.7<br><br>service ipsec status<br> IPsec running - pluto pid: 17736<br> pluto pid 17736<br> 1 tunnels up<br><br>route -n<br>[root@gw ~]# route -n<br>Kernel IP routing table<br>Destination Gateway Genmask Flags Metric Ref Use Iface<br>(extip_linux-2) 0.0.0.0 255.255.255.248 U 0 0 0 eth1<br>10.0.17.0 10.0.0.11 255.255.255.0 UG 0 0 0 eth0<br>10.8.1.0 10.0.0.11 255.255.255.0 UG 0 0 0 eth0<br>10.0.12.0 10.0.0.11 255.255.255.0 UG 0 0 0 eth0<br>10.0.13.0 10.0.0.11 255.255.255.0 UG 0 0 0 eth0<br>10.0.14.0 10.0.0.11 255.255.255.0 UG 0 0 0 eth0<br>10.0.15.0 10.0.0.11 255.255.255.0 UG 0 0 0 eth0<br>10.0.10.0 10.0.0.11 255.255.255.0 UG 0 0 0 eth0<br>10.0.11.0 10.0.0.11 255.255.255.0 UG 0 0 0 eth0<br>10.0.4.0 10.0.0.3 255.255.252.0 UG 0 0 0 eth0<br>10.0.0.0 0.0.0.0 255.255.252.0 U 0 0 0 eth0<br>169.254.0.0 0.0.0.0 255.255.0.0 U 0 0 0 eth1<br>192.168.0.0 extip_linux-1 255.255.0.0 UG 0 0 0 eth1<br>128.0.0.0 extip_linux-1 128.0.0.0 UG 0 0 0 eth1<br>0.0.0.0 extip_linux-1 0.0.0.0 UG 0 0 0 eth1<br><br><br>ip xfrm policy<br>src 192.168.0.0/16 dst 10.0.0.0/21<br> dir in priority 2448 ptype main<br> tmpl src extip_cisco dst extip_linux<br> proto esp reqid 16385 mode tunnel<br>src 10.0.0.0/21 dst 192.168.0.0/16<br> dir out priority 2448 ptype main<br> tmpl src extip_linux dst extip_cisco<br> proto esp reqid 16385 mode tunnel<br>src 192.168.0.0/16 dst 10.0.0.0/21<br> dir fwd priority 2448 ptype main<br> tmpl src extip_cisco dst extip_linux<br> proto esp reqid 16385 mode tunnel<br><br><br>ip xfrm state<br>src extip_linux dst extip_cisco<br> proto esp spi 0x87ff9df7 reqid 16385 mode tunnel<br> replay-window 32<br> auth hmac(sha1) 0x56272c16c736f8a57ef7eb54ab8331c84f528839<br> enc cbc(aes) 0xcf9c91365cb338c7c6867f073619b15d37842f2093a4dcdb212752b3bca3ba67<br> sel src 0.0.0.0/0 dst 0.0.0.0/0<br>src extip_cisco dst extip_linux<br> proto esp spi 0xd81dc534 reqid 16385 mode tunnel<br> replay-window 32<br> auth hmac(sha1) 0xfb5e1daaa3fca7d475af8db684ed60739ba10df3<br> enc cbc(aes) 0xe64c534709e97f87167aac535c02bc951af1fb5eed2604f782dea264d9d1e79e<br> sel src 0.0.0.0/0 dst 0.0.0.0/0<br><br><br>[root@gw ~]# traceroute 192.168.8.1<br>traceroute to 192.168.8.1 (192.168.8.1), 30 hops max, 40 byte packets<br> 1 extip_linux-1.permonline.ru (extip_linux-1) 1.171 ms 1.065 ms 0.997 ms<br> 2 90.150.2.26 (90.150.2.26) 1.152 ms 1.361 ms 1.574 ms<br> 3 90.150.2.26 (90.150.2.26) 1.551 ms 1.509 ms 1.699 ms<br> 4 * * *<br> 5 * * *<br> 6 * * *<br> 7 * * *<br> 8 * * *<br> 9 * * *<br>10 * * *<br>11 * * *<br><br>ping 192.168.8.1<br>PING 192.168.8.1 (192.168.8.1) 56(84) bytes of data.<br><br>--- 192.168.8.1 ping statistics ---<br>8 packets transmitted, 0 received, 100% packet loss, time 7000ms<br><br>in /var/log/messages, i see error message<br>kernel: ICMP: 192.168.8.1: Source Route Failed.<br><br>ps. rigth side from cisco ping left well ok.<br><br>how fix problem? <br>Thanks.<br><br>----<br>Trushin Igor<br>Russia | Perm</BODY></HTML>