[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

(usagi-users 02412) IPsec 2.5.70-bk9 and FreeS/WAN 1.99 with algopatches 0.8.1rc2 (in)compatible encryption methods



Hi again,

because I got no success, I've tried different encryption methods than 3DES. And *suddenly* it began to work.

One side  : 2.5.70-bk9
Other side: FreeS/WAN 1.99 with algopatches 0.8.1rc2

Result:

AES
---
AES-128: working

AES-192: not working
AES-256: not working

FreeS/WAN:
112 "freeswan-racoon-tunnel" #14: STATE_QUICK_I1: initiate
003 "freeswan-racoon-tunnel" #14: ESP transform ESP_AES passed key_len=32 > 16
032 "freeswan-racoon-tunnel" #14: STATE_QUICK_I1: internal error



3DES ---- Not working, no message


Blowfish -------- blowfish-128: working

Other key lengths: not working NO_PROPOSAL_CHOSEN


Other algorithms: not tested at the moment


I'm very wondering why 3DES is incompatible in IPsec-SA modus, while working in IKE.


Can someone confirm and/or extend this compatibility test?

TIA,
	Peter
--
Dr. Peter Bieringer                     http://www.bieringer.de/pb/
GPG/PGP Key 0x958F422D               mailto: pb at bieringer dot de
Deep Space 6 Co-Founder and Core Member  http://www.deepspace6.net/