[Openswan Users] pfkey write failed

Arnoud Tijssen ATijssen at Ram.nl
Mon Apr 19 07:29:18 EDT 2010


Recently our openswan generated the following error:

/usr/local/libexec/ipsec/spi: pfkey write failed (errno=28): no room in kernel SAref table.  Cannot process request.


The system had enough memory and free disk space. We`re running openswan 2.4.13. After we stopped the ipsec service and openswan wasn`t running anymore we still saw a list with more spi values than vpn`s. Some of our vpn`s were still processing datastreams, and some were unable to re-establish a connection with the peers.

What did happen here and why did we keep all of these spi values after the ipsec daemon stopped entirely?



More information about the Users mailing list