[Openswan Users] pfkey write failed

sasa sasa at shoponweb.it
Fri Nov 25 13:06:18 CET 2005


Hi,
I have a problem with vpn connection site-to-site, in the log file I have:

Nov 25 11:41:16 fw2 pluto[17396]: "frattacis" #3: Informational Exchange 
message must be encrypted
Nov 25 11:41:23 fw2 pluto[17396]: "frattacis" #7: next payload type of 
ISAKMP Hash Payload has an unknown value: 170
Nov 25 11:41:23 fw2 pluto[17396]: "frattacis" #7: malformed payload in 
packet
Nov 25 11:41:23 fw2 pluto[17396]: "frattacis" #7: sending notification 
PAYLOAD_MALFORMED to 6.7.8.9:500
Nov 25 11:41:56 fw2 pluto[17396]: "frattacis" #6: max number of 
retransmissions (2) reached STATE_QUICK_I1.  No acceptable response to our 
first Quick Mode message: perhaps peer likes no proposal
Nov 25 11:41:56 fw2 pluto[17396]: "frattacis" #6: starting keying attempt 4 
of an unlimited number
Nov 25 11:41:56 fw2 pluto[17396]: "frattacis" #8: initiating Quick Mode 
RSASIG+ENCRYPT+TUNNEL+PFS+UP to replace #6 {using isakmp#3}
Nov 25 11:42:03 fw2 pluto[17396]: "frattacis" #9: responding to Quick Mode 
{msgid:8283b534}
Nov 25 11:42:03 fw2 pluto[17396]: ERROR: "frattacis" #9: pfkey write() of 
SADB_ADD message 11 for Add SA esp.df5f67af at 1.2.3.4 failed. Errno 22: 
Invalid argument

..the same error is present on both end-point.
My configuration is:

config setup
interfaces="ipsec0=eth0"
conn %default
authby=rsasig
conn frattacis
auto=start
pfs=yes
left=1.2.3.4
leftsubnet=192.168.1.0/24
leftnexthop=1.2.3.5
# RSA 2192 bits   fw2   Fri Nov 25 11:52:33 2005
leftrsasigkey=0sAQN0Rp....
#sede right cis
right=6.7.8.9
rightsubnet=192.168.0.0/24
rightnexthop=6.7.8.10
# RSA 2192 bits   fw1   Wed Nov  9 18:22:16 2005
rightrsasigkey=0sAQOqRzipTLH...
include /etc/ipsec.d/examples/no_oe.conf

I use openswan-2.4.0-23 on FC1.
Thanks.


------
Salvatore.

 



More information about the Users mailing list