[Openswan Users] Cannot get NETKEY working on openwrt ERROR: netlink XFRM_MSG_NEWPOLICY

Weedy weedy2887 at gmail.com
Sun Mar 8 05:29:12 EDT 2009


I have been try for the past 2 weeks to debug this but I am at a stand
still with this current problem. I will attach the full syslogs but the
important parts (I think) are the following 2 lines.

Openwrt - Linux Openswan U2.4.13/K2.6.28.7 (netkey)
pluto[6262]: "pom" #4: ERROR: netlink response for Add SA
esp.623130a2 at 1.2.3.4 included errno 2: No such file or directory

Gentoo - Linux Openswan U2.4.13/K2.6.28-gentoo-r2 (netkey)
pluto[12367]: "cbarone" #5: ERROR: netlink XFRM_MSG_NEWPOLICY response
for flow tun.10000 at 4.3.2.1 included errno 17: File exists

I have tried to sync the kernel config as best as possible for all IPsec
related options but to no avail, any hints would be much appreciated.
(Between the gentoo box and a centos test box it works fine, so I know I
have the configs working and the kernel setup properly)

Thank you.


conn pom
     leftsubnet=172.31.27.0/24
     leftsourceip=172.31.27.1
     right=4.3.2.1
     #ike=aes256-sha1-modp2048
     rightsubnet=172.16.11.0/24
     rightid="/C=US/ST=New York/L=Syosset/O=POM/OU=Main Office/CN=POM"

conn cbarone
     leftsubnet=172.16.11.0/24
     leftsourceip=172.16.11.1
     right=1.2.3.4
     #ike=aes256-sha1-modp2048
     rightsubnet=172.31.27.0/24
     rightid="/C=US/ST=New York/L=Bayside/O=POM/OU=POM/CN=CBARONE"

openwrt modules: aes_generic af_key ah4 arc4 authenc cbc deflate
des_generic ecb esp4 hmac ipcomp ipt_ah md5 sha1_generic xfrm4_mode_beet
xfrm4_mode_transport xfrm4_mode_tunnel xfrm4_tunnel xfrm_ipcomp
xfrm_user xt_esp
-------------- next part --------------
An embedded and charset-unspecified text was scrubbed...
Name: router-crap
Url: http://lists.openswan.org/pipermail/users/attachments/20090308/cef27a70/attachment.pl 
-------------- next part --------------
An embedded and charset-unspecified text was scrubbed...
Name: gentoo-crap
Url: http://lists.openswan.org/pipermail/users/attachments/20090308/cef27a70/attachment-0001.pl 


More information about the Users mailing list