[Openswan Users] Linux IPsec client

Paul Wouters paul at xelerance.com
Tue Sep 26 16:29:57 EDT 2006


On Tue, 26 Sep 2006, Xunhua Wang wrote:

> Sep 26 14:32:27 localhost pluto[3418]: "roadwarrior"[306] 68.235.168.219
> #333: crl update for "C=US, ST=Virginia, L=Harrisonburg, O=JMU, OU=CS,
> CN=Crypto CA" is overdue since Jun 04 01:53:24 UTC 2006

If strictmode is set to yes, this will cause the connection to fail.

> Sep 26 14:32:27 localhost pluto[3418]: "roadwarrior"[307] 68.235.168.219
> #333: cannot respond to IPsec SA request because no connection is known for
> 134.126.20.79[C=US, ST=Virginia, L=Harrisonburg, O=JMU, OU=CS, CN=IPsec VPN
> Server 02]:17/1701...68.235.168.219[C=US, ST=Virginia, L=Harrisonburg,
> O=JMU, OU=CS, CN=Steve Wang]:17/1701===192.168.1.3/32

Is 192.168.1.0/24 part of virtual_private? do you have nat_traversal=yes?

Did your certificates load properly? Check with ipsec auto --listall

Paul


More information about the Users mailing list