Re: IPSEC help

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: john decot <johndecot@...>
Cc: <freebsd-security@...>
Date: Monday, November 19, 2007 - 5:38 am

On Sat, Nov 17, 2007 at 01:06:32AM -0800, john decot wrote:

Hi.

> As per suggestion, The following are the logs generated by racoon :

[....]

Some people should learn that an RFC has been published for NAT-T :-)

[....]

Ok, your racoon found "an acceptable proposal", even if DB's lifetime
is really shorter than peer's one.

That means you're in CLAIN or OBEY checkmode. Those modes are well
known to generate as much problems as they solve, you should really
consider using exact or at least strict checkmode, and fix your
lifetime in your configuration (on the side you want, but have the
same lifetime on both peers).

[....]

[....]

May be an INITIAL-CONTACT sent a bit too early, or may also be a
negociation related INFORMATIONAL message.
Could you do a network capture of a negociation, and have a look at
that message in a tool like wireshark, to have more details ?

[....]

[....]
[....]
[....]
[....]

Really looks like the peer did not like the answer we sent, so did not
respond to it (or sent an informational which has not been handled).

Fix your lifetimes, switch to strict checkmode, fix any other
negociation parameter which may generate an error now you're in strict
checkmode, and if that still don't work, have a look at the
INFORMATIONAL message sent by your peer, and/or have a look at any log
on your peer.

Yvan.

--
NETASQ
http://www.netasq.com
_______________________________________________
freebsd-security@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
ports/128698: [vuxml] new entry for Dovecot 1.1.4-1.1.5, Eygene Ryabinkin, (Sat Nov 8, 10:03 am)
RE: CVE-2008-4609, olli hauer, (Tue Sep 8, 4:58 pm)
OCF, Raja FreeBSD, (Thu Sep 20, 5:49 am)
Re: OPIE Challenge sequence, Ivan Grover, (Tue Jul 8, 9:41 am)
Re: IPSEC help, john decot, (Sat Nov 17, 5:06 am)
Re: OPIE Challenge sequence, Dag-Erling Smørgrav, (Tue Jul 8, 11:37 am)
Re: OPIE Challenge sequence, Ivan Grover, (Wed Jul 9, 2:55 am)
Re: OPIE Challenge sequence, Dag-Erling Smørgrav, (Wed Jul 9, 4:29 am)
Re: OPIE Challenge sequence, Jason Stone, (Tue Jul 8, 3:27 pm)
Re: OPIE Challenge sequence, Ivan Grover, (Wed Jul 9, 4:18 am)
Re: IPSEC help, Shoichi Sakane, (Thu Nov 29, 9:56 pm)
Re: IPSEC help, VANHULLEBUS Yvan, (Mon Nov 19, 5:38 am)
Re: IPSEC help, john decot, (Tue Nov 20, 6:57 am)
Re: IPSEC help, VANHULLEBUS Yvan, (Tue Nov 20, 8:34 am)
Re: IPSEC help, john decot, (Tue Nov 20, 12:46 pm)
Re: IPSEC help, VANHULLEBUS Yvan, (Tue Nov 20, 12:56 pm)
Re: IPSEC help, john decot, (Thu Nov 22, 11:08 am)
Re: IPSEC help, Bjoern Engels, (Tue Nov 20, 7:08 am)
Re: OCF, Mohacsi Janos, (Fri Sep 21, 5:30 am)
Re: OCF, Eygene Ryabinkin, (Fri Sep 21, 11:58 am)