LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 03-23-2016, 12:56 AM   #1
lokesharo
LQ Newbie
 
Registered: Mar 2016
Posts: 1

Rep: Reputation: Disabled
libreswan - IPSec not getting established


I am trying to establish IPSec SA by giving run time commands to Pluto but it fails in negotiation phase by not exchanging the certificates.

Command User on server and client side :
ipsec whack --name hello --host 192.168.54.220 --client 192.168.54.1/32 --cert Server --ca CA_auth --sendcert yes --to --host 192.168.54.221 --client 192.168.54.1/32 --cert Client --ca CA_auth --sendcert yes --rsasig --tunnel

Server and Client are the nicknames of the digital certificates in the server/client ipsec database.

[root@localhost ipsec.d]# ipsec whack --initiate --name hello
002 "hello" #1: initiating Main Mode
104 "hello" #1: STATE_MAIN_I1: initiate
003 "hello" #1: received Vendor ID payload [Dead Peer Detection]
003 "hello" #1: received Vendor ID payload [RFC 3947]
002 "hello" #1: enabling possible NAT-traversal with method RFC 3947 (NAT-Traversal)
002 "hello" #1: transition from state STATE_MAIN_I1 to state STATE_MAIN_I2
106 "hello" #1: STATE_MAIN_I2: sent MI2, expecting MR2
003 "hello" #1: NAT-Traversal: Result using RFC 3947 (NAT-Traversal): no NAT detected
002 "hello" #1: I am sending my cert
002 "hello" #1: I am sending a certificate request
002 "hello" #1: Not sending INITIAL_CONTACT
002 "hello" #1: transition from state STATE_MAIN_I2 to state STATE_MAIN_I3
108 "hello" #1: STATE_MAIN_I3: sent MI3, expecting MR3
003 "hello" #1: ignoring informational payload INVALID_ID_INFORMATION, msgid=00000000, length=12
003 "hello" #1: received and ignored informational message for unknown state
003 "hello" #1: discarding duplicate packet; already STATE_MAIN_I3
010 "hello" #1: STATE_MAIN_I3: retransmission; will wait 20s for response
003 "hello" #1: ignoring informational payload INVALID_ID_INFORMATION, msgid=00000000, length=12
003 "hello" #1: received and ignored informational message for unknown state

Looks like I am missing some parameter while initiating the ipsec SA.
 
Old 03-23-2016, 02:10 PM   #2
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941
I'm suspicious of those INVALID_ID_INFORMATION responses. I don't know IPSec well enough to diagnose this, but I'd be looking at the logs on the other side as well as this one. It superficially looks to me like this client sent a certificate but that the other side didn't like it. I don't expect the response message to be an "informational payload" to be "ignored," but ... I do know that the IPSec stack (Raccoon and all its other rabid furry-friends) is an infernal state-machine from hell.

Also noticed on the web:
I see references to people asking for a state-diagram of the IPSec connection negotiations, but I never yet found that anyone found one.

Anyway: IPSec is evil ook. OpenVPN is not.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Red Hat Enterprise Linux 6.8 Now in Beta, Libreswan Replaces Openswan LXer Syndicated Linux News 0 03-15-2016 07:54 PM
[SOLVED] Libreswan connection issue Nataliya_K Linux - Networking 2 10-20-2015 02:37 PM
openswan - include statement in ipsec.conf & ipsec.secrets readmore Linux - Security 0 10-16-2014 07:44 AM
vpn-ipsec : Failed to parse config setup portion of ipsec.conf hari85 Linux - Newbie 1 07-17-2010 08:12 PM
Established connections? n00b1shzyx Linux - Newbie 8 03-01-2009 02:57 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 03:16 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration