All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Konstantin V. Gavrilenko" <mlists@arhont.com>
To: racoon@kame.net, linux-kernel@vger.kernel.org
Subject: racoon and usbnet nic = no IPSEC
Date: Tue, 08 Mar 2005 19:09:26 +0000	[thread overview]
Message-ID: <422DF866.4050801@arhont.com> (raw)

Hi guys,

just thought I'd share my experience of last several days.

Had to change the external nic on the gateway box from standard pci device, to a 
usb nic. turned the machine on, everything goes as planned, but no ipsec tunnels 
go up.


Spent couple of days solving the f*^&king problem, tried different kernels 
(2.6.9-2.6.11) and ipsec-tools versions, thought I was going mental.

Only to to find out that my USB Netgear FA-120 would not "work with ipsec".


for some reason, kernel can no create SAs.
Even if you set the tunnels manually, it is still a no go.


The logs are full of:

2005-03-07 15:17:20: ERROR: phase2 negotiation failed due to time up waiting for 
phase1. ESP xxx.xxx.xxx.bbb->xxx.xxx.xxx.aaa
2005-03-07 15:17:20: INFO: delete phase 2 handler.
2005-03-07 15:17:24: ERROR: can't start the quick mode, there is no valid 
ISAKMP-SA, 530bc0362f36f1ed:9673792c0daa890f



Anyone has any suggestions of why this was happening?

I can post more info if developers are interested.


-- 
Respectfully,
Konstantin V. Gavrilenko

Arhont Ltd - Information Security

web:    http://www.arhont.com
	http://www.wi-foo.com
e-mail: k.gavrilenko@arhont.com

tel: +44 (0) 870 44 31337
fax: +44 (0) 117 969 0141

PGP: Key ID - 0x4F3608F7
PGP: Server - keyserver.pgp.com

                 reply	other threads:[~2005-03-08 19:18 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=422DF866.4050801@arhont.com \
    --to=mlists@arhont.com \
    --cc=kos@arhont.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=racoon@kame.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.