[Openswan Users] L2TP/IPsec with double NAT

Paul Wouters paul at xelerance.com
Wed Aug 10 23:52:27 CEST 2005


On Wed, 10 Aug 2005, Stefano Pazzaglia wrote:

> What the hell means 000 xxx.xxx.xxx.91/32:0 -17-> 213.140.19.123/32:0 =>
> %hold 0    %acquire-netlink????????

A broken NETKEY implementation. There is a workaround in openswan 2.3.1 I
believe. Or run a newer NETKEY, eg from 2.6.12.x.

When using L2TP, you must not specify a subnet=.

Paul


More information about the Users mailing list