[Openswan Users] Ipsec\L2tpd tunneling problems
eugevesco at hotmail.com
Wed Sep 24 12:35:15 EDT 2008
Hi all, some news about my problem about Ipsec\L2tpd connection.First of all I realized my router filter all the ping-tries, and so that's the reason it fail.Then I established the L2tpd connection from my roadwarrior to the server, assigning to the client an IP address of the gateway's LAN, and
everything work.I mean, if i ping the virtual address of the warrior inside the lan from an host within the lan, my roadwarrior reply to the requests.Now, the real problem: I'm still not able to establish the L2tp connection OVER the IPsec tunnel.I mean: I can establish the host-to-host IPsec tunnel easily (this is what /etc/init.d/ipsec status told me), but after this
I'm not able to establish the L2tpd connection.
Whe I lunch the xl2tpd daemon on my roadwarrior, I can only see ESP packets to the server without any reply from this last one, and plus
no packets reach the server. It looks like the packets are not able to reach the server, and so they go missed.I tryed Linux and WinXP client, following Jacco's pages, but with no luck.The labs where I'm testing this thesis work is equipped with a block of public IP addresses, which is 188.8.131.52/24, and 184.108.40.206-220.127.116.11-18.104.22.168 are
the 3 free IP addressess of the LAN, a.b.c.51 and a.b.c.52 will be assigned to my roadwarriors.
Here are my conf files
ip range = 22.214.171.124 - 126.96.36.199 local ip = 188.8.131.52 length bit = yes require chap = yes refuse pap = yes require authentication = yes hostname = server_diei ; * Report this as our hostnameppp debug = yes ; * Turn on PPP debuggingpppoptfile= /etc/ppp/options.l2tpd.lns ; * ppp options file
config setupinterfaces=%defaultroutevirtual_private=%v4:192.168.0.0/16,%v4:10.1.0.0/16klipsdebug=noneplutodebug=none conn %defaultesp=3des-md5conn provaleft=184.108.40.206leftnexthop=220.127.116.11right=%anyrightsubnet=vhost:%no,%privpfs=norightprotoport=17/%anyleftprotoport=17/1701authby=secrettype=tunnelauto=start#Disable Opportunistic Encryptioninclude /etc/ipsec.d/examples/no_oe.confI do hope somebody can help me.Thank you all in advance.
Stanco della solita finestra? Personalizza la tua Hotmail!
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Users