[ previous ] [ next ] [ threads ]
 
 From:  mark wolfe <markw at wolfenet dot org>
 To:  m0n0wall at lists dot m0n0 dot ch
 Subject:  ipsec and timestep permit gateway
 Date:  22 May 2003 21:26:12 -0700
Is there any documentation/howto on connecting the racoon ipsec to a
timestep permit gateway?   I've made progress, but it's not passing
traffic.  Here's the log output so far.   Thanks

May 22 23:03:10 racoon: INFO: isakmp.c:1684:isakmp_post_acquire():
IPsec-SA request for 159.71.152.3 queued due to no phase1 found. 

May 22 23:03:10 racoon: INFO: isakmp.c:798:isakmp_ph1begin_i(): initiate
new phase 1 negotiation: aaa.aaa.aaa.aaa[500]<=>bbb.bbb.bbb.bbb[500] 

May 22 23:03:10 racoon: INFO: isakmp.c:803:isakmp_ph1begin_i(): begin
Aggressive mode. May 22 23:03:10 racoon: WARNING:
ipsec_doi.c:3059:ipsecdoi_checkid1(): ID value mismatched. 

May 22 23:03:11 racoon: NOTIFY: oakley.c:2040:oakley_skeyid(): couldn't
find the proper pskey, try to get one by the peer's address. 

May 22 23:03:11 racoon: INFO: isakmp.c:2412:log_ph1established():
ISAKMP-SA established aaa.aaa.aaa.aaa[500]-bbb.bbb.bbb.bbb[500]
spi:01c33665f96ea110:b877a19839047e06 

May 22 23:03:11 racoon: INFO: isakmp.c:942:isakmp_ph2begin_i(): initiate
new phase 2 negotiation: aaa.aaa.aaa.aaa[0]<=>bbb.bbb.bbb.bbb[0] 

May 22 23:03:12 racoon: WARNING:isakmp_inf.c:1273:isakmp_check_notify():
ignore RESPONDER-LIFETIME notification. 

May 22 23:03:13 racoon: INFO: pfkey.c:1110:pk_recvupdate(): IPsec-SA
established: ESP/Tunnel bbb.bbb.bbb.bbb->aaa.aaa.aaa.aaa
spi=227905149(0xd958e7d) 

May 22 23:03:13 racoon: INFO: pfkey.c:1322:pk_recvadd(): IPsec-SA
established: ESP/Tunnel aaa.aaa.aaa.aaa->bbb.bbb.bbb.bbb
spi=3854443782(0xe5be2506)



-- 
Mark Wolfe                                   http://www.wolfenet.org
gpg fingerprint = 42B6 EFEB 5414 AA18 01B7  64AC EF46 F7E6 82F6 8C71
"I will make no bargains with terrorist hardware."
- Peter da Silva
signature.asc (0.2 KB, application/pgp-signature)