[Openswan Users] dpdaction=clean Ineffective.

Agent Smith news8080 at yahoo.com
Thu Jan 19 18:26:27 CET 2006



take a look at the following def.

conn    L2TPM
        type=tunnel
        authby=rsasig
        dpdaction=clear
        left=x.x.x.x
        leftid=@vpn.company.domain
        leftrsasigkey=%cert
        leftcert=servercert10.pem
        leftprotoport=17/1701
        right=%any
        rightsubnet=vhost:%all
        rightprotoport=17/1701
        rightrsasigkey=%cert

I connect over L2TP fine, everything works but after I
disconnect, I still have the eroute showing up in the
'ipsec eroute' output. 

shouldn't the dpdaction=clear suppose to delete the
eroute? where do I configure the dpd timeout?

I tried deleting eroute manually but that looked like
it deleted it since it doesn't show up in 'ipsec
eroute' but when I do 'ipsec auto --status' the
following shows

000 x.x.x.x/32:1701 -0-> 68.84.121.12/32:1701 => %hold
0    %acquire-pfkey
000 x.x.x.x./32:1701 -0-> 68.84.121.12/32:1701 =>
%hold 0    %acquire-pfkey
000 x.x.x.x/32:1701 -0-> 68.84.121.12/32:1701 => %hold
0    %acquire-pfkey


anyone?

__________________________________________________
Do You Yahoo!?
Tired of spam?  Yahoo! Mail has the best spam protection around 
http://mail.yahoo.com 


More information about the Users mailing list