[Openswan Users] IKE Phase2 fails, cannot respond to IPsec SA

t.henneberger at hcs-computer.de t.henneberger at hcs-computer.de
Mon Sep 27 15:22:58 CEST 2004


Hello

I am refering to my mail " Phase1 IKE working ? Phase2 apparently not" 
from this morning ;)

According to my log I seem to have a problem establishing the IPsec SAs
because of my ipsec.conf.

Here is what Pluto is telling me:
pluto: "roadwarrior"[2] 192.168.1.111 #1: cannot respond to IPsec SA request because no connection is known for 192.168.1.0/24===192.168.1.35[S=C]...192.168.1.111[0.0.0.0,S=C]
pluto: state transition function for STATE_QUICK_RO failed: INVALID_ID_INFORMATION

My ipsec.conf:
version 2

config setup
klipsdebug=none
plutodebug=control

conn %default
keyingtries=1
compress=no
keyexchange=ike
authby=secret

conn roadwarrior
left=192.168.1.35
right=%any
rightid=%any
auto=add

include /etc/ipsec.d/example/no_oe.conf
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.openswan.org/pipermail/users/attachments/20040927/e1362c90/attachment.htm


More information about the Users mailing list