[Openswan Users]

foren titze foren.titze at gmx.net
Wed Jul 13 09:57:59 CEST 2005


Am Mittwoch, 13. Juli 2005 01:59 schrieb Paul Wouters:
> On Tue, 12 Jul 2005, Foren wrote:
> > the error above I had it since I use the ipsec modules from
> > openswan-2.3.1. erlier I have used the af_key with the native ipsec-stack
> > from kernel-2.6.
> >
> > Now, I get no error, the tunnel commes up and the l2tpd does nothing.
> >
> > The l2tpd-logfile don't says me anything, no entry.
> >
> > I think it's not the tunnel config, because this is working.linux-vpn2:~# 
> What does 'ipsec verify' say?
#ipsec verify

Checking your system to see if IPsec got installed and started correctly:
Version check and ipsec on-path                                 [OK]
Linux Openswan 2.3.1 (klips)
Checking for IPsec support in kernel                            [OK]
Checking for RSA private key (/etc/ipsec.secrets)               [FAILED]
ipsec showhostkey: no default key in "/etc/ipsec.secrets"
Checking that pluto is running                                  [OK]
Two or more interfaces found, checking IP forwarding            [OK]
Checking NAT and MASQUERADEing                                  [OK]
Checking for 'ip' command                                       [OK]
Checking for 'iptables' command                                 [OK]
Opportunistic Encryption Support                                [DISABLED
>
RSA is X509

ben
>
> These problems most likely are related to:
> - firewalling
> - natting ipsec packets to pieces
> - no ip forwarding
> - bogus 2.6 martians/icmp redirects/
> - rp_filter
>
> > TRY: Windows XP SP2 to Linux Openswan-2.3.1 with Kernel 2.6.11.7
>
> I have made this work in my setups using NETKEY. Behind NAT with L2TP.
>
> Paul


More information about the Users mailing list