[Openswan Users] Tunnel proliferation

nwh nwh at tiscali.fr
Thu Jan 19 22:16:01 CET 2006


Hi !
I am really sorry to ask for help again but... something bothers me, now 
that my IPsec connection (transport mode) works (I made tests with ping 
and tcpdump). It looks like one of the two computers does it all, and 
the other one doesn't do anything but errors.
After a few hours, with only this connection, the first computer tells 
(after a "ipsec setup --status") :
    IPsec running  - pluto pid: 536
    pluto pid 536
    293 tunnels up
Where as the other has plenty of errors in his "ipsec batch" and 
"/etc/var/syslog" :
    Jan 19 22:25:03 localhost ipsec__plutorun: restarting IPsec after 
pause...
    Jan 19 22:25:14 localhost ipsec_setup: ...Openswan IPsec stopped
    Jan 19 22:25:14 localhost ipsec_setup: Stopping Openswan IPsec...
    Jan 19 22:25:14 localhost ipsec_setup: Removing orphaned 
/var/run/pluto.pid:
    Jan 19 22:25:14 localhost ipsec_setup: KLIPS ipsec0 on eth0 
172.30.0.60/255.255.0.0 broadcast 172.30.255.255
    Jan 19 22:25:15 localhost ipsec_setup: ...Openswan IPsec started
    Jan 19 22:25:15 localhost ipsec_setup: Restarting Openswan IPsec 
U2.2.0/K2.4.27-2-386...
    Jan 19 22:25:17 localhost ipsec__plutorun: 104 "essai" #1: 
STATE_MAIN_I1: initiate
    Jan 19 22:25:17 localhost ipsec__plutorun: ...could not start conn 
"essai"
    Jan 19 22:26:14 localhost ipsec__plutorun: /usr/lib/ipsec/_plutorun: 
line 1:   458 Segmentation fault      /usr/lib/ipsec/pluto             
--nofork     --secretsfile /etc/ipsec.secrets --ipsecdir /etc/ipsec.d 
--uniqueids
    Jan 19 22:26:14 localhost ipsec__plutorun: !pluto failure!:  exited 
with error status 139 (signal 11)
    Jan 19 22:26:14 localhost ipsec__plutorun: restarting IPsec after 
pause...
I'm not really sure this is fully natural... And I fear that the 
increasing number of tunnels make my server lack of memory in the end... 
:-(
Does someone know anything about this ?
Thanks a lot for your help !

Guillaume MICHAUD


More information about the Users mailing list