[Openswan Users] Stale Sessions

Werner Otto werner.otto at thecloud.net
Fri Apr 8 19:12:40 CEST 2005


Hi All,

I am currently running openswan 2.2.0 on Fedora Core 3 Linux version
2.6.9 1.667smp. The problem is that after a while these session become
stale, in that the show connected on a netstat -rn, but I can't ping the
interface. This probably has to do with the timeout of the SA. I don't
know what is causing this behaviour? What debug would be useful to
attempt debugging this? 

Ipsec.conf 
config setup
        klipsdebug="none"
        plutodebug="none"
        interfaces=%defaultroute
        uniqueids=no

conn bh99s425-to-localnet
        type=tunnel
        left=194.42.124.11
        leftsubnet=0.0.0.0/0
        leftnexthop=194.42.124.1
        right=%any
        rightsubnet=10.157.134.0/26
        rightid=@cloud.net
        keyexchange=ike
        ikelifetime=480m
        keylife=60m
        pfs=no
        auth=esp
        authby=secret
        auto=add
        keyingtries=1

Regards
Werner Otto



More information about the Users mailing list