D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

[LUG] VPN using ipsec and openswan

 


I've got two FC3 machines in seperate places (both running all the latest
updates), which I'm trying to configure an openswan vpn between them. One of them starts openswan/ipsec cleanly and the other doesn't. As far as I can see, both machines have identical configs on them.


Versions of appropriate things are:
kernel-2.6.11-1.35_FC3
ipsec-tools-0.5-2.fc3
openswan-2.1.5-2.FC3.1

The log entries for starting ipsec on the box that isn't working:
Jul 4 09:03:59 box2 ipsec: Starting Openswan IPsec U2.1.5/K2.6.11-1.35_FC3...
Jul 4 09:03:59 box2 ipsec: insmod /lib/modules/2.6.11-1.35_FC3/kernel/net/ipv4/ah4.ko
Jul 4 09:03:59 box2 ipsec: insmod /lib/modules/2.6.11-1.35_FC3/kernel/net/ipv4/esp4.ko
Jul 4 09:03:59 box2 ipsec: insmod /lib/modules/2.6.11-1.35_FC3/kernel/net/ipv4/ipcomp.ko
Jul 4 09:03:59 box2 ipsec: /usr/lib/ipsec/_startklips: KLIPS ipsec0 on eth0
192.168.1.2/255.255.255.0 broadcast 192.168.1.255
Jul 4 09:03:59 box2 ipsec_setup: KLIPS ipsec0 on eth0 192.168.1.2/255.255.255.0broadcast 192.168.1.255
Jul 4 09:03:59 box2 ipsec: /usr/lib/ipsec/_plutorun: Starting Pluto subsystem...
Jul 4 09:03:59 box2 ipsec_setup: Starting Pluto subsystem...
Jul 4 09:03:59 box2 ipsec_setup: ...Openswan IPsec started
Jul 4 09:03:59 box2 racoon: INFO: unsupported PF_KEY message REGISTER
Jul 4 09:03:59 box2 last message repeated 2 times
Jul 4 09:03:59 box2 ipsec: Starting IPsec: succeeded
Jul 4 09:04:10 box2 ipsec: Stopping Openswan IPsec...
Jul 4 09:04:10 box2 ipsec_setup: ...Openswan IPsec stopped
Jul 4 09:04:10 box2 setup: Shutting down IPsec: succeeded


I think it's something to do with:
racoon: INFO: unsupported PF_KEY message REGISTER

But I'm rather stumped as where to go from here..

Cheers,
Alex.


-- The Mailing List for the Devon & Cornwall LUG Mail majordomo@xxxxxxxxxxxxx with "unsubscribe list" in the message body to unsubscribe. FAQ: www.dcglug.org.uk/linux_adm/list-faq.html