[Openswan Users] NAT and MASQUERADEing [TEST INCOMPLETE]

Richard Overstreet bubbles455 at bellsouth.net
Sat Jul 20 22:04:28 UTC 2013


Hello All,

I've been trying to get openswan working for several days. I have hit a
wall with the error.

richard at richard-X220:~/Software/ike$ sudo ipsec verify
Checking if IPsec got installed and started correctly:

Version check and ipsec on-path                       [OK]
Openswan U2.6.39/K3.2.0-49-generic (netkey)
See `ipsec --copyright' for copyright information.
Checking for IPsec support in kernel                  [OK]
  NETKEY: Testing XFRM related proc values
          ICMP default/send_redirects                  [OK]
          ICMP default/accept_redirects                [OK]
          XFRM larval drop                             [OK]
Hardware random device check                          [N/A]
Two or more interfaces found, checking IP forwarding    [OK]
Checking rp_filter                                    [ENABLED]
  /proc/sys/net/ipv4/conf/all/rp_filter                [ENABLED]
Checking that pluto is running                        [OK]
  Pluto listening for IKE on udp 500                   [OK]
  Pluto listening for IKE on tcp 500                   [NOT IMPLEMENTED]
  Pluto listening for IKE/NAT-T on udp 4500            [OK]
  Pluto listening for IKE/NAT-T on tcp 4500            [NOT IMPLEMENTED]
  Pluto listening for IKE on tcp 10000 (cisco)         [NOT IMPLEMENTED]
Checking NAT and MASQUERADEing                        [TEST INCOMPLETE]
Checking 'ip' command                                 [OK]
Checking 'iptables' command                           [OK]

ipsec verify: encountered errors

Not sure what error ipsec is getting now except for possibly the check
on NAT and MASQUERADEing. Anyone encounter this problem before. The
service still will not start.

richard at richard-X220:~/Software/ike$ sudo service ipsec start
Segmentation fault (core dumped)
failed to start openswan IKE daemon - the following error occured:

richard at richard-X220:~/Software/ike$





More information about the Users mailing list