[Openswan Users] Problem with openswan and l2tpd

Denis Beltramo denis.beltramo at gmail.com
Fri Feb 15 02:59:56 EST 2008


I think the is a configuration' s problem of l2tpnd because when try the
connect while l2tpnd negotiation go if I check tunnel status say:
/etc/init.d/ipsec status: 1 tunnels up

This is ipsec.conf
version 2.0

config setup
        interfaces=%defaultroute
        nat_traversal=yes
        virtual_private=%v4:10.0.0.0/8,%v4:172.16.0.0/12,%v4:192.168.0.0/16

conn %default
        keyingtries=3
        compress=no
        disablearrivalcheck=no
        authby=rsasig
        leftrsasigkey=%cert
        rightrsasigkey=%cert
        keyexchange=ike
        ikelifetime=240m
        keylife=60m
conn roadwarrior
        left=%defaultroute
        leftcert=pubblica.pem
        leftsubnet=192.168.1.0/24
        type=tunnel
        right=%any
        auto=add
        pfs=yes
        leftnexthop=%defaultroute
        rightnexthop=%defaultroute

conn roadwarrior-l2tp
        type=transport
        left=%defaultroute
        leftcert=pubblica.pem
        leftprotoport=17/0
        rightprotoport=17/1701
        right=%any
        pfs=no
        auto=add


This is l2tpnd.conf:
;
[global]
; listen-addr = 192.168.1.98

[lns default]
ip range = 192.168.1.128-192.168.1.254
local ip = 192.168.1.99
require chap = yes
refuse pap = yes
require authentication = yes
name = LinuxVPNserver
ppp debug = yes


pppoptfile = /etc/ppp/options.l2tpd
length bit = yes

This is options.l2tpnd

ipcp-accept-local
ipcp-accept-remote
# dns server
ms-dns 213.144.64.1
ms-dns 213.144.66.1
# wins server
#ms-wins 192.168.1.2
#ms-wins 192.168.1.4
#
noccp
auth
crtscts
idle 1800
mtu 1410
mru 1410
debug
defaultroute
lock
proxyarp
connect-delay 5000
require-pap
require-chap
require-mschap
require-mschap-v2
noccp
nobsdcomp
logfile /var/log/l2tpd.log



Thanks, sorry for my english.


denis
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.openswan.org/pipermail/users/attachments/20080215/055cfe96/attachment.html 


More information about the Users mailing list