[Openswan Users] Checkpoint connection problems
Brent.Foster at int-sol.com
Sun Aug 15 17:06:02 CEST 2004
I'm running OpenSwan 2.1.5 and have about 10 tunnels active on the
system. Just created a new
connection to a Checkpoint FW1 box and the tunnel works fine, except
that it will stop working
after a few hours. Sometimes it will auto-recover, sometimes I have to
-down and -up the
tunnel. In all cases OpenSwan thinks the tunnel is up and will route
traffic across the ipsec0 interface.
I think the problem is on the Checkpoint end (as I have other tunnels
that are connected to different
Checkpoint boxes) that work just fine. The checkpoint admin swears the
problem is on my end.
I saw a link at
problem and pointed me to a specific message on the mailing list
archives that doesn't exist
Does anyone know anything about this problem, or have any ideas on how
to fix it?
Here is a copy of this tunnel's status info:
32; erouted; eroute owner: #17
000 "ag1": ike_life: 3600s; ipsec_life: 28800s; rekey_margin: 540s;
rekey_fuzz: 100%; keyingtries: 0
000 "ag1": policy: PSK+ENCRYPT+TUNNEL+UP; prio: 29,32; interface:
000 "ag1": newest ISAKMP SA: #0; newest IPsec SA: #17;
000 #17: "ag1" STATE_QUICK_I2 (sent QI2, IPsec SA established);
EVENT_SA_REPLACE in 13434s; newest IPSEC; eroute owner
000 #17: "ag1" used 107s ago; esp.1da6ce at y.y.y.30 esp.2f784097 at x.x.x.2
tun.1016 at y.y.y.30 tun.1015 at x.x.x.2
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Users