LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-04-2006, 09:49 AM   #1
aletorta
LQ Newbie
 
Registered: Nov 2006
Posts: 1

Rep: Reputation: 0
Ipsec setkey pfkey


Hi everybody,
I'm trying to set up an IPsec connection (Tunnel mode) between two pc which are in my LAN.
I use Ubuntu 6.10, so I have recompiled the kernel adding the the security features and networking options needed, I have installed ipsec-tools, and edited the /etc/ipsec-tools.conf in this way:

# Flush the SAD and SPD
flush;
spdflush;

# ESP SAs
add 192.168.1.101 192.168.1.100 esp 0x201 -m tunnel -E 3des-cbc \
0x7aeaca3f87d060a12f4a4487d5a5c3355920fae69a96c831 \
-A hmac-md5 0xc0291ff014dccdd03874d9e8e4cdf3e6;

add 192.168.1.100 192.168.1.101 esp 0x301 -m tunnel -E 3des-cbc \
0xf6ddb555acfd9d77b03ea3843f2653255afe8eb5573965df \
-A hmac-md5 0x96358c90783bbfa3d7b196ceabe0536b;

# Security policies
spdadd 172.16.1.0/24 172.16.2.0/24 any -P out ipsec
esp/tunnel/192.168.1.101-192.168.1.100/require;

spdadd 172.16.2.0/24 172.16.1.0/24 any -P in ipsec
esp/tunnel/192.168.1.100-192.168.1.101/require;

I try with setkey -f /etc/ipsec-tools.conf
and the system answers:
pfkey_open: Operation not permitted

Does someone know why and how to fix it?
Thank you in advance...
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
IPsec:Problem with setkey squirtle Linux - Security 28 10-30-2006 07:03 PM
IPSec eagle683 Linux - Security 5 06-10-2005 10:53 AM
IPsec cranium2004 Linux - Security 5 05-01-2005 08:21 PM
ipsec?? new user Linux - Security 5 08-18-2003 11:37 PM
ipsec pk21 Linux - Software 2 01-30-2003 06:39 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:52 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration