[Openswan Users] DIsable NETKEY
paul at xelerance.com
Tue Mar 25 11:49:00 EDT 2008
On Tue, 25 Mar 2008, Hammad wrote:
> How do i disable Netkey?
> because of Netkey; its not binding to an interface out of multiple.
> [root at flexigw ~]# service ipsec restart
> ipsec_setup: Stopping Openswan IPsec...
> ipsec_setup: Starting Openswan IPsec U2.5.17/K126.96.36.199-xenU...
With openswan 2.5.x, you can add to config setup:
> *ipsec_setup: WARNING: interfaces= is ignored when using the NETKEY stack*
> *.. and even when IPSec and ISAKMP are established; while trying with #
> ipsec auto --up connection
> # service ipsec status
> give only;
> IPsec running - pluto pid: 29493
> pluto pid 29493
> *No tunnels up*
ip xfrm policy
ip xfrm state
ipsec auto --status
before concluding things are not up.
> I think its in fact not bound to ANY Interface; thats why it behaving like
NETKEY does not need that.
Building and integrating Virtual Private Networks with Openswan:
More information about the Users