[Openswan Users] Openswan ipv6 tunnels

Paul Whelan wheelo_01 at hotmail.com
Fri Mar 28 07:20:55 EDT 2008


I've been trying for some time to set up Openswan 2.4.9 (with NETKEY) with IPv6 without success. Basically when I try bring up an IPv6 tunnel I get no errors, just pluto trying to initiate the ISAKMP message which doesn't succeed , it just retransmits the initialise messages every 20 seconds. On further inspection I found that the 2nd Openswan GW is receiving the ISAKMP message but when it tries to reply it gets a "ICMP6, destination unreachable[|icmp6]" message. 

My IPv6 routes and ips are correct and my kernel has the appropriate options installed. I have set up a IPv6 IPSEC tunnel using setkey to manually add SAs & SPs, I was able to ping across the tunnel and could see the ESP packets using tcpdump from each direction.

My ipsec.conf file seems to be correct, as it doesn't give any errors when starting Openswan and is included below.

Does IPv6 work on 2.4.9, or is there some ipv6 patch i need that is mentioned in some forums?

Thanks in advance
Paul Whelan

version 2.0     # conforms to second version of ipsec.conf specification

# basic configuration

config setup

# Add connections here
conn %default

conn sa-ipv6-tunnel

#Disable Opportunistic Encryption
include /etc/ipsec.d/examples/no_oe.conf

In a rush?  Get real-time answers with Windows Live Messenger.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.openswan.org/pipermail/users/attachments/20080328/9827ef4f/attachment.html 

More information about the Users mailing list