[ previous ] [ next ] [ threads ]
 From:  Vincent Fleuranceau <vincent at bikost dot com>
 To:  Chris Buechler <cbuechler at gmail dot com>
 Cc:  m0n0wall dash dev at lists dot m0n0 dot ch
 Subject:  Re: [m0n0wall-dev] 1.2b1 IPsec SA issues
 Date:  Mon, 27 Sep 2004 09:03:29 +0200
> The duplicate SA issue is happening to me almost exactly every 2
> hours today (give or take a few minutes).  Always src IP PIX, dst IP 
> m0n0wall public IP, single SA in the other direction.  Deleting all 
> the SA's for that connection makes it come back within a couple 
> seconds.

I've found several (similar) entries in your log that make me think that
both racoon and PIX do not use *exactly* the same settings:

    pfs group mismatched: my:2 peer:0

It would be interesting to get the PIX's log, too.

-- Vincent