LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 03-22-2009, 10:49 PM   #1
aixarat
LQ Newbie
 
Registered: Sep 2004
Location: Morelia México
Distribution: OpenSuSE11/Ubuntu Hardy/RH/Etc..
Posts: 14

Rep: Reputation: 0
SSH on an IPsec tunnel with Openswan freezes


Hello all,

After a lot of hard work, we were able to create an IPsec tunnel between a Linux box (Ubuntu Hardy) and a Stonegate firewall.

However, our celebration was short-lived: we can ssh through the tunnel, but once we have a working shell, it freezes after some 8 commands. It seems to be data-volume-related, since a Top command freezes it immediately.

Here's my Openswan config:
Code:
conn tresm-knx
	auth=esp
	auto=start
	authby=secret
	type=tunnel
	keyexchange=ike
	pfs=no
	left=ubuntu.public.ip.address
	leftsubnet=192.168.131.0/24
	right=stonegate.public.ip.address
	rightsubnet=10.154.200.0/24
	keyingtries=0
Nothing fancy, you see. The box has Shorewall 4, but it behaves the same with or without it (have tried several times)

Is there a setting I am missing that allows for a fluid data stream? Or the other way around, something I have is preventing the data from flowing?

I have the Stonegate side set to no compression, however I do not know if Openswan, in absence of a declared setting, takes a default configuration that may be conflicting with the tunnel's operation.

All and any help with this issue is greatly appreciated.
 
Old 03-24-2009, 12:01 PM   #2
tuliojm
LQ Newbie
 
Registered: Mar 2008
Location: Curitiba
Posts: 18

Rep: Reputation: 2
Hello,

do you check the log file for anything strage?
Maybe you could do some tests with the mtu values (let it equal in both sides). Decrease it and verify if something change.

Regards,

Tulio Munhoz
 
Old 03-25-2009, 03:18 AM   #3
aixarat
LQ Newbie
 
Registered: Sep 2004
Location: Morelia México
Distribution: OpenSuSE11/Ubuntu Hardy/RH/Etc..
Posts: 14

Original Poster
Rep: Reputation: 0
Solved. It was weird.

As it happens, the DSL connection (pppoe) needs to be started after shorewall is started. Getting this backwards generates all sort of errors, from which we first noticed the shell freezing.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Openswan IPSEC issue prashanlk Linux - Networking 0 01-09-2008 04:00 AM
IPSEC openswan prashanlk Linux - Networking 1 12-28-2007 11:47 AM
Openswan IPSEC server prashanlk Linux - Networking 3 12-11-2007 11:13 PM
OpenSWAN - IPSec tunnel drops dieduster Linux - Networking 0 12-17-2006 11:07 AM
IPSec OpenSWAN probs zmeda Linux - Networking 0 07-12-2006 06:39 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 04:48 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration