[Openswan Users] Openswan 2.6.38 and Windows XP breaking everything!

Bart Swedrowski bart at timedout.org
Thu May 10 04:57:15 EDT 2012


It’s been a while seems I last looked at the problem but I still
haven’t had luck in solving it.  I tried multiple versions of OpenSWAN
and at all times outcome is the same.  I.e everything is working fine
until I have Windows XP coming into the play.  Once that happens, if
I’ve eg. Mac OS X box and Windows XP box behind single firewall, once
Windows XP connects and disconnects it leaves following policy entry:

> src 5.6.7.8/32 dst 1.2.3.4/32 proto udp sport 1701
>        dir out priority 2080 ptype main
>        tmpl src 0.0.0.0 dst 0.0.0.0
>                proto esp reqid 16397 mode transport

This sadly causes all other (then this specific Windows XP system)
hosts not to be able to connect back to the VPN.

The last message that I’m seeing in auth.log is:

May 10 08:50:56 vpn01 pluto[18089]: rekeying existing instance
"l2tp-psk"[4] 5.6.7.8, due to acquire
May 10 08:50:56 vpn01 pluto[18089]: initiate on demand from
1.2.3.4:1701 to 5.6.7.8:59982 proto=17 state: fos_start because:
acquire

And then after about 20 seconds connection try drops with connection
not being established.

I’d extremely appreciate any form of help or hints as to how I could
potentially progress this issue.


More information about the Users mailing list