[Openswan Users] verify results

Chris Berry chris_berry-list-openswan at jm-associates.com
Thu Oct 28 17:00:32 CEST 2004


I noticed that a couple items failed.

Checking for RSA private key (/etc/ipsec.secrets)           ipsec 
showhostkey: no default key in "/etc/ipsec.secrets"
[FAILED]

I do have a file /etc/ipsec.secrets, and it does have info in it.

DNS checks.
Looking for forward key for cerebus.jmcollections.net 
/usr/lib/ipsec/verify: line 37: host: command not found
[NO KEY]

Not sure what this means

Checking NAT and MASQUERADING
  tun0x10c0 at 64.60.113.211:0                                  [FAILED]
REDNAT from 0.0.0.0/0 to 0.0.0.0/0 kills tunnel 192.168.1.0/24:0 -> 
192.168.100.0/24:0
[FAILED]
POSTPORTFW from 0.0.0.0/0 to 0.0.0.0/0 kills tunnel 192.168.1.0/24:0 -> 
192.168.100.0/24:0

Confused here.  Can someone provide some pointers so I can figure this out?

-- 
Chris Berry
chris_berry at jm-associates.com
Systems Administrator
JM Associates & Coast Business Service

"Yes, I'm aware this message is top-posted, and therefore violates 
RFC1855.  No, there isn't anything I can do about it.  This is now 
company policy, and all employees are instructed to comply."
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 250 bytes
Desc: OpenPGP digital signature
Url : http://lists.openswan.org/pipermail/users/attachments/20041028/78d7397b/signature-0001.bin


More information about the Users mailing list