LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 09-03-2008, 11:55 PM   #1
karlson
LQ Newbie
 
Registered: Aug 2005
Posts: 3

Rep: Reputation: 0
OpenSwan, racoon running on one box - how ?


Hello,

the problem: The box has 2 NIC's with 2 different IP addresses. I have racoon running in tunnel mode using IPsec (or at least i hope it is ) on eth0. When started - racoon listens on eth0 port 500. I configured OpenSwan to run on eth1 (Roadwarrior server) - unfortunately when started, openswan starts to listen on localhost, eth0 and eth1 ports 500, so racoon dies. When trying to restart racoon it says address already in use. I truly believe there is a way to forbid OpenSwan taking all 3 addresses. Both eth0 and eth1 has an external addresses

Any suggestions are welcome

my ipsec.conf

Code:
config setup
        
        nat_traversal=no
        nhelpers=0

        interfaces="ipsec0=eth1"
        klipsdebug=none
        plutodebug=none
   #    overridemtu=1410
        virtual_private=%v4:10.0.0.0/8,%v4:172.16.0.0/12,%v4:192.168.0.0/16,%v4:!192.168.1.0/24



# Add connections here

conn %default
    keyingtries=3
    compress=no
    disablearrivalcheck=no
    keyexchange=ike
    ikelifetime=240m
    keylife=60m

conn roadwarrior-net
    leftsubnet=192.168.1.0/24
    also=roadwarrior

conn roadwarrior-all
    leftsubnet=0.0.0.0/0
    also=roadwarrior

conn roadwarrior-l2tp
    leftprotoport=17/0
    rightprotoport=17/1701
    also=roadwarrior

conn roadwarrior-l2tp-updatedwin
    leftprotoport=17/1701
    rightprotoport=17/1701
    also=roadwarrior

conn roadwarrior
    authby=secret
    pfs=no
    type=tunnel
    left=my_eth1_ip
    right=%any
    rightsubnet=vhost:%no,%priv
    auto=add

# sample VPN connections, see /etc/ipsec.d/examples/

#Disable Opportunistic Encryption
include /etc/ipsec/ipsec.d/examples/no_oe.conf
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Running Openswan for IPSEC VPN agentc0re Slackware 1 05-13-2008 11:13 AM
racoon and certificates dimsum2 Linux - Security 2 05-11-2008 08:13 AM
how to know if my nic is up a running in my etch box htamayo Debian 3 03-01-2008 09:09 AM
problem with racoon nitinkhanna Linux - Security 0 10-28-2004 05:28 AM
So I got my box running smoothly... chingasman Linux - General 3 01-31-2003 01:53 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 04:12 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration