[Openswan Users] BM 3.8 proposals

Paul Wouters paul at xelerance.com
Fri Oct 20 15:42:27 EDT 2006


On Fri, 20 Oct 2006, Tobias Hadem wrote:

> i try to make a connection between a Openswan U2.2.0/K2.6.8-3-386 (native) and
> a Novell Bordermanager 3.8.

Both (openswan and kernel) are very old and should be upgraded.

> The IKE.LOG (which is nearly the same as the auth.log on linux) shows the
> following:
>
> 10-20-2006 1:57:11 pm Warn :Proposal mismatch  PHASE 1  HASH Algorithm
> mismatch  mine : SHA  his : MD5   dst : 194.213.50.98  src : 195.39.44.34

add ike=sha1 and esp=sha1
(or do it fully, ike=3des-sha1 and esp=3des-sha1)

> It looks like they have different thoughts of their proposals. My ipsec.conf:

no. openswan proposes more then one, and the remote stops talking after it
did not like the first proposal.

Paul
-- 
Building and integrating Virtual Private Networks with Openswan:
http://www.amazon.com/gp/product/1904811256/104-3099591-2946327?n=283155


More information about the Users mailing list