From: "Konstantin V. Gavrilenko" <mlists@arhont.com>
To: racoon@kame.net, linux-kernel@vger.kernel.org
Subject: racoon and usbnet nic = no IPSEC
Date: Tue, 08 Mar 2005 19:09:26 +0000 [thread overview]
Message-ID: <422DF866.4050801@arhont.com> (raw)
Hi guys,
just thought I'd share my experience of last several days.
Had to change the external nic on the gateway box from standard pci device, to a
usb nic. turned the machine on, everything goes as planned, but no ipsec tunnels
go up.
Spent couple of days solving the f*^&king problem, tried different kernels
(2.6.9-2.6.11) and ipsec-tools versions, thought I was going mental.
Only to to find out that my USB Netgear FA-120 would not "work with ipsec".
for some reason, kernel can no create SAs.
Even if you set the tunnels manually, it is still a no go.
The logs are full of:
2005-03-07 15:17:20: ERROR: phase2 negotiation failed due to time up waiting for
phase1. ESP xxx.xxx.xxx.bbb->xxx.xxx.xxx.aaa
2005-03-07 15:17:20: INFO: delete phase 2 handler.
2005-03-07 15:17:24: ERROR: can't start the quick mode, there is no valid
ISAKMP-SA, 530bc0362f36f1ed:9673792c0daa890f
Anyone has any suggestions of why this was happening?
I can post more info if developers are interested.
--
Respectfully,
Konstantin V. Gavrilenko
Arhont Ltd - Information Security
web: http://www.arhont.com
http://www.wi-foo.com
e-mail: k.gavrilenko@arhont.com
tel: +44 (0) 870 44 31337
fax: +44 (0) 117 969 0141
PGP: Key ID - 0x4F3608F7
PGP: Server - keyserver.pgp.com
reply other threads:[~2005-03-08 19:18 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=422DF866.4050801@arhont.com \
--to=mlists@arhont.com \
--cc=kos@arhont.com \
--cc=linux-kernel@vger.kernel.org \
--cc=racoon@kame.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.