LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 06-18-2013, 12:58 AM   #1
jmajor
Member
 
Registered: Nov 2004
Location: Australia
Distribution: Fedora, Ubuntu
Posts: 55
Blog Entries: 2

Rep: Reputation: 17
openswan ping: sendmsg: Operation not permitted


I've been googling and beating my head against this all day.

I have taken a working NETKEY openvpn connection awway from an old F8 box and tried to make it work on a more recent Ubuntu 10 LTS system. When the remote end was shifted to the new IP, the session was created immediately. So far so good.

Theres a new config value on the ubuntu system 'virtual_private' I've tried with and without.

Unfortunately no traffic is passing in either direction.

pinging the remote subnet from the ipsec host gets

"ping: sendmsg: Operation not permitted"

I've checked iptables, and apparmor are not interfering.

I've used tcpudump to look for ipsec packets going at co-incident times to my ping attempts: none.

I've checked logs and tcpdump on the firewall.

strace ping .... shows the pertinent failure is sendmsg() returns -1: EPERM (operation not permitted)

To complicate matters, the system is one of two using heartbeat to share an IP address in an active / standby arrangement. Each has its own address on each interface and may have the shared address. I've already established that as the address is moved from one host to the other, openswan does not notice. The active connection eventually dies and no new connection appears. I'll deal with that via heartbeat once traffic happens though.

I noticed in the logs that it is choosing the fixed address of the server for the connection rather than the shared address, but this does not seem to prevent the connection establishing so I don't think that's the cause.

I've obviously missed something fundumental here as every attempt to use the tunnel, as intended, results in 'Nup! not sendin it!' despite the session being up and stable.

Can anyone give me some pointers as to where to look next?
Maybe how to trace deeper into sendmsg()
Maybe "Have you set that 'enabled' flag" ;-)

I've drawn a blank here and any help would be appreciated.

Thanks
John
 
  


Reply

Tags
ipsec, openswan



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
ping: sendmsg: Operation not permitted on certain websites/domains shayno90 Linux - Networking 2 11-14-2012 01:39 PM
package loss - ping: sendmsg: Operation not permitted abusebeat Linux - Networking 4 09-16-2011 06:55 PM
ping: sendmsg: operation not permitted br_sriram Linux - Networking 24 04-03-2011 11:12 AM
ping:sendmsg: operation not permitted jeejasmin Linux - Networking 7 04-03-2008 10:15 AM
ping: sendmsg: Operation not permitted kholloi Linux - Networking 0 05-02-2007 05:00 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 07:55 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration