[Openswan Users] Weird tunnel issue

Jason J. W. Williams jasonjwwilliams at gmail.com
Wed Oct 22 17:00:11 EDT 2014


We've had a weird issue where the tunnel had been up for several days
and then suddenly refused to route packets over the tunnel (couldn't
ping). The tunnel according to "ipsec auto --status" was up. The other
side is a Fortigate 200B and it also agreed the tunnel was up. But it
refused to send traffic over the tunnel. Tried toggling the tunnel
down and then up from both ends, and while the tunnel re-established
still couldn't route. Only thing that corrected it was rebooting the
box running the OpenSWAN client.

Client is an Ubuntu 14.04.1 x64 box:
# ipsec --version
Linux Openswan U2.6.38/K3.13.0-37-generic (netkey)

ipsec.conf: https://gist.github.com/williamsjj/4dc00138e62697aec602
tunnel config: https://gist.github.com/williamsjj/910adcc5a071fc130b30

Any help is greatly appreciated.


More information about the Users mailing list