LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices

Reply
 
Search this Thread
Old 12-13-2011, 11:18 AM   #1
skate
Member
 
Registered: Aug 2003
Location: Bulgaria
Distribution: OpenSuse 10.3, Debian 4.0r3 "Etch", FreeBSD 7.1, Ubuntu
Posts: 210

Rep: Reputation: 30
Unhappy ipsec Help Plase :/


Hello Folks, I am trying to get the right configuration for ipsec tunnel but I have some problems and I need your help and advice to get it up and running:

The OS is Ubuntu Server 11
OpenSwan - ipsec

Thats the configuration:

http://i39.tinypic.com/mwwmqe.jpg

Thats my ipsec.conf configuration:


conn some1
auth=esp
authby=secret
auto=add
# enc=aes-256
esp=aes256-sha1
ike=aes256-sha1-modp1024
ikelifetime=28800s
keyexchange=ike
keyingtries=0
keylife=28800s
rekeymargin=3s
rekeyfuzz=100%
dpdaction=restart_by_peer
dpddelay=9
dpdtimeout=30
x-l2tpd=no
left=95.43.208.254
leftsubnet=192.168.45.10/32
leftsourceip=192.168.45.10
leftid=@s1
leftnexthop=%defaultroute
pfs=yes
right=82.103.104.129
rightsubnet=82.103.104.165/32
rightsourceip=82.103.104.165
type=tunnel

config setup
interfaces=%defaultroute
nat_traversal=yes
oe=off
protostack=netkey


I am not sure if its the right configuration because I get the following in the log:


Dec 13 18:56:06 s1 pluto[29891]: "some1" #2: initiating Main Mode to replace #1
Dec 13 18:56:06 s1 pluto[29891]: "some1" #2: received Vendor ID payload [Dead Peer Detection]
Dec 13 18:56:06 s1 pluto[29891]: "some1" #2: transition from state STATE_MAIN_I1 to state STATE_MAIN_I2
Dec 13 18:56:06 s1 pluto[29891]: "some1" #2: STATE_MAIN_I2: sent MI2, expecting MR2
Dec 13 18:56:06 s1 pluto[29891]: "some1" #2: transition from state STATE_MAIN_I2 to state STATE_MAIN_I3
Dec 13 18:56:06 s1 pluto[29891]: "some1" #2: STATE_MAIN_I3: sent MI3, expecting MR3
Dec 13 18:56:16 s1 pluto[29891]: "some1" #2: discarding duplicate packet; already STATE_MAIN_I3

Any help will be appreciated, Thank you.
 
Old 12-14-2011, 10:27 AM   #2
amilo
Member
 
Registered: Oct 2011
Location: Nederland
Distribution: Debian, Centos, Ubuntu
Posts: 62

Rep: Reputation: Disabled
Where is the conf file at the other side of the tunnel?
 
Old 12-14-2011, 11:34 AM   #3
skate
Member
 
Registered: Aug 2003
Location: Bulgaria
Distribution: OpenSuse 10.3, Debian 4.0r3 "Etch", FreeBSD 7.1, Ubuntu
Posts: 210

Original Poster
Rep: Reputation: 30
Quote:
config begin

##########################
# Phase 1
listen {
isakmp 82.103.104.129 [500];
}
remote XX.XX.XX.XX {
exchange_mode main;
proposal {
encryption_algorithm aes 256;
hash_algorithm sha1;
authentication_method pre_shared_key;
dh_group 2;
lifetime time 86400 sec;
}
}

# Phase 2
sainfo address 82.103.104.165 any address XX.XX.XX.XX any {
encryption_algorithm aes 256;
authentication_algorithm hmac_sha1;
compression_algorithm deflate;
lifetime time 28800 sec;
pfs_group 2;
}

###########################

racoon as far as I know.
 
  


Reply

Tags
ipsec, openswan, tunnel, vpn


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
vpn-ipsec : Failed to parse config setup portion of ipsec.conf hari85 Linux - Newbie 1 07-17-2010 08:12 PM
posting just to post- plase ignore this newbie-thanks redfed6 Linux - Newbie 6 05-25-2008 05:37 AM
problem about installation.plase help. pangyatou Linux - Enterprise 1 02-01-2007 05:25 PM
Kernel Question Plase Help Rustylinux Suse/Novell 3 12-07-2006 10:30 PM


All times are GMT -5. The time now is 09:21 AM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration