Steven Surdock wrote:I too have the same problem. I have a Lan 2 Lan tunnel with pfsync, carp, sasync and it works flawlessly with another OpenBSD system as the peer. I tried to enable OpenBSD to PIX tunnel (PIX 501, OS: 6.3(5)) I defined "quick auth hmac-sha enc aes", when I do that I get phase 1 completed. ipsec.conf ike esp from 172.30.75.0/24 to 192.168.137.0/24 \ local 10.200.3.7 peer 10.200.3.1 \ main auth hmac-sha1 enc aes \ quick auth hmac-sha enc aes \ srcid 10.200.3.7 psk "F00F00Bar" snippet from PIX firewall: crypto ipsec transform-set IPSEC_SET esp-aes-256 esp-sha-hmac crypto map VPN_MAP 1 ipsec-isakmp crypto map VPN_MAP 1 match address VPN_ACL crypto map VPN_MAP 1 set peer 10.200.3.7 crypto map VPN_MAP 1 set transform-set IPSEC_SET crypto map VPN_MAP interface outside isakmp enable outside isakmp key ******** address 10.200.3.7 netmask 255.255.255.255 no-xauth isakmp identity address isakmp policy 1 authentication pre-share isakmp policy 1 encryption aes-256 isakmp policy 1 hash sha isakmp policy 1 group 2 isakmp policy 1 lifetime 1800 pixfirewall# sh crypto isakmp sa Total : 1 Embryonic : 0 dst src state pending created 10.200.3.1 10.200.3.7 QM_IDLE 0 0 But phase 2 does not established at all for some reason! Does anybody need any more logs? Thanks Prabhu -
| Rafael J. Wysocki | Re: [rft] s2ram wakeup moves to .c, could fix few machines |
| Jeff Garzik | [PATCH 4/9] irq-remove: driver non-trivial |
| Greg KH | [patch 02/73] dm: table detect io beyond device |
| S.Çağlar | Rescheduling interrupts |
git: | |
| Dongsheng Song | Does GIT has vc keywords like CVS/Subversion? |
| Dan Farina | backup or mirror a repository |
| Karl | [StGit PATCH 01/15] Split git.merge into two functions |
| Shawn O. Pearce | Re: [PATCH resend] make "git push" update origin and mirrors, "git push --mirror" ... |
| Brooks Davis | Re: When will ZFS become stable? |
| Unga | ERROR! Can't stop Rx DMA |
| Duncan Young | zfs and glabel |
| Ulrich Spoerlein | OpenBSD finds 33 year old bug in yacc(1) |
| Amarendra Godbole | Anyone from this list at BlackHat or DefCon? And a query... |
| Matt | IBM ServeRaid 5i - installer unable to find disks |
| Ray Percival | Re: Richard Stallman... |
| Bibby | Max clients of OpenSSH |
| Resetting the bios password for Toshiba Laptop | 1 minute ago | Hardware |
| Problem booting a barebone kernel in VMWare | 3 hours ago | Linux kernel |
| IP layer send packet | 7 hours ago | Linux kernel |
| PID to ELF image full path | 9 hours ago | Linux kernel |
| SMDK2410 LCD Framebuffer driver | 13 hours ago | Linux kernel |
| types of kernel | 1 day ago | Linux kernel |
| magical mounts | 2 days ago | Linux kernel |
| Problem in scim in Fedora 9 | 2 days ago | Linux general |
| The new Western Digital power saving drives | 2 days ago | Hardware |
| Battery Maximizer Software | 3 days ago | Linux kernel |
