[Openswan Users] OpenSwan in UML

Paul Wouters paul at xelerance.com
Wed Oct 25 00:09:45 EDT 2006


On Wed, 25 Oct 2006, Jax wrote:

> I trying to setup a simple L2TP/IPsec server in User Mode Linux. I
> follow the Openswan book but don't have much time to setup this. It
> would be a PSK based solution which looks really simple but I still
> can't get far in a week :(
> I just wondering someone did actually made an uml image with this

You need this in UML? I know Michael just updated the umlswanroot
uml image that is used for the testing infrastructure in the last
weeks. Are you using the latest one? ftp://ftp.openswan.org/openswan/umlrootfs/

> Kernel: 2.6.18.1-bb2 and the whole system up-to-date (there wasn't any
> problem with the install) however there is some serious problem with
> pluto and it's generate 100% cpu usage:

That's odd. I've never seen that happen on openswan 2.4.6. I wonder
what it could be.

> ipsec__plutorun: ...could not start conn "west-east"
> ipsec__plutorun: !pluto failure!:  exited with error status 1
> ipsec__plutorun: restarting IPsec after pause...
> ipsec__plutorun: whack: Pluto is not running (no "/var/run/pluto/pluto.ctl")

Looks like pluto it crashing. You can try setting 'plutorestartoncrash=no'
and 'dumpdir=/tmp' in the config setup section and then you get a core and
we can see why that is happening.

> Btw my first setup was worst. I made it in FC4 and everything work until
> I restarted the machine, after that I got strange messages when ipsec
> started:
>
> "Resource temporary unavailable" or something like this, I can't even
> ping the remote host.

That's actually much better. you just forgot to include /etc/ipsec.d/examples/no_oe.conf
in /etc/ipsec.conf

If you just need testing with virtual servers, using FC5 or FC6 with XEN is
much easier. Unless you really want or need to setup UML testcases.

Paul
-- 
Building and integrating Virtual Private Networks with Openswan:
http://www.amazon.com/gp/product/1904811256/104-3099591-2946327?n=283155


More information about the Users mailing list