[Openswan Users] Phase I completed,but Phase II error

李正光 xjklee at gmail.com
Fri Nov 2 06:54:30 EDT 2007


The attached file is ipsec log without klipsdebug and plutodebug. It can
work when I ping 10.2.111.2, an ipsec server ip.
The interesting thing is If I turn on klipsdebug and plutodebug, it seems it
cannot work because I see no any log as follows:
"84 bytes from 10.2.111.2: icmp_seq=0 ttl=253 time=50.0 ms"
Why?

Thanks!



2007/11/1, Paul Wouters <paul at xelerance.com>:
>
> On Thu, 1 Nov 2007, ??? wrote:
>
> > I have installed iproute2 package in my kernel, but the execute result
> is
> > still the same as before.
>
> So do you no longer have "client route" errors in the logs? You only
> provided the kernel logs, not the userland logs. Can you show a
> successful IPsec SA established with plutodebug= and klipsdebug=
> disabled?
>
> > The ping has something wrong. Please reference the
> > attached log file, and give me some suggestions!
>
> I don't see anything that looks wrong, but I hardly ever need to look
> at kernel debugs, since most problems are userland problems.
>
> Paul
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.openswan.org/pipermail/users/attachments/20071102/84b1ed5b/attachment.html 
-------------- next part --------------
An embedded and charset-unspecified text was scrubbed...
Name: ipsec_log_no_kilp&pluto.txt
Url: http://lists.openswan.org/pipermail/users/attachments/20071102/84b1ed5b/attachment.txt 


More information about the Users mailing list