[Openswan Users] openswan-2.6.24rc1 NATed MacOS Kernel crash

Sven Schiwek ml-openswan at svenux.de
Sun Oct 25 11:19:28 EDT 2009


Hi,

attached you'll find a kernel crash (Kernel 2.6.30.9). It appears when  
a NATed MacOS wants to connect to Openswan with xl2tpd. After the  
crash the Openswan-system is unreachable and I must do a cold restart.  
Has some one else this problem?
Unfortunately I have no Windows machine so I can't reproduce this with  
a MS Client, sorry.

My ipsec config:
----8<----
version	2.0

config setup
	interfaces="ipsec0=eth0 ipsec1=eth0:3"
	virtual_private= 
%v4 
: 
10.0.0.0 
/ 
8 
, 
%v4 
: 
172.16.0.0 
/ 
12 
, 
%v4 
: 
192.168.0.0 
/24,%v4:192.168.1.0/24,%v4:192.168.11.0/24,%v4:192.168.12.0/24
	nat_traversal=yes
         plutowait=yes
         nhelpers=0
         klipsdebug=none
         plutodebug=none
         uniqueids=yes

conn XL2TP
         compress=no
         authby=secret
         pfs=no
	ikelifetime=12h
	keylife=12h
	rekey=no
         left=xxx.xxx.xxx.xxx
         leftprotoport=17/1701
         right=%any
         rightprotoport=17/%any
         rightsubnet=vhost:%priv,%no
         auto=add
	dpddelay=30
	dpdtimeout=120
	dpdaction=clear

conn block
     auto=ignore

conn private
     auto=ignore

conn private-or-clear
     auto=ignore

conn clear-or-private
     auto=ignore

conn clear
     auto=ignore

conn packetdefault
     auto=ignore
---->8----

Thanks
Sven


-------------- next part --------------
A non-text attachment was scrubbed...
Name: ipsec.out
Type: application/octet-stream
Size: 6964 bytes
Desc: not available
Url : http://lists.openswan.org/pipermail/users/attachments/20091025/9c3a287c/attachment.obj 
-------------- next part --------------





More information about the Users mailing list