[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

(usagi-users 02403) Compatibility problems IPsec 2.5.70 against FreeS/WAN 1.99



Hi,

has anyone successful examples of configuration settings for 2.5.70 IPsec (racoon/SAD/SPD) and FreeS/WAN?

I got no success between 2 hosts, neither in tunnel nor in transport mode.

(racoon and pluto config looks like ok, the IPsec-SA was proper established, also both hosts send packets with related spi).

In transport mode, the comment of Andreas came true that in the ESP packet an IP-in-IP tunnel packet is transported (sent from the 2.5.70-ipsec host):

16:42:06.215546 [|ip]
0x0000 45 E
16:42:08.215348 [|ip]
0x0000 4500 0007 0004 40 E.....@


Looks like FreeS/WAN don't like this.

In tunnel mode, ipsec0 interface of FreeS/WAN drops all received packages by the 2.5.70-ipsec host (seen in ifconfig stat).

On 2.5.70-ipsec side I currently don't know how to debug, but I only see the ESP packet on the interface, nothing decrpyted.

Very strange at all...

Any hints available how to let FreeS/WAN communicate with 2.5.70-ipsec?

Thank you very much,
Peter


--
Dr. Peter Bieringer http://www.bieringer.de/pb/
GPG/PGP Key 0x958F422D mailto: pb at bieringer dot de
Deep Space 6 Co-Founder and Core Member http://www.deepspace6.net/