Koozali.org: home of the SME Server

Freeswan I know its been beat to death

SalaTar

Freeswan I know its been beat to death
« on: July 29, 2002, 03:06:01 AM »
I have a fresh install of 2 sme 5.5 boxs, both on dedicated static ips.
Tring to VPN them together for the last 3 days......

I have moved, remaped, and fixed as I have read the dev forums.
Every time I do I lose conection between boxs to get to server man or ssl.
 I cannot find info on how to disable compression in key file.


snippet from secure log


Jul 28 09:34:43 sme ipsec__plutorun: Starting Pluto subsystem...
Jul 28 09:34:43 sme Pluto[1553]: Starting Pluto (FreeS/WAN Version 1.97)
Jul 28 09:34:49 sme Pluto[1553]: listening for IKE messages
Jul 28 09:34:49 sme Pluto[1553]: adding interface ipsec0/eth1 208.180.163.16
Jul 28 09:34:49 sme Pluto[1553]: loading secrets from "/etc/ipsec.secrets"
Jul 28 09:35:18 sme Pluto[1553]: packet from 65.100.204.163:500: initial Main Mode message received on 208.180.163.16:500 but no connection has been authorized
Jul 28 09:35:58 sme last message repeated 2 times

Could somone please point me in right direction?

SalaTar

Re: Freeswan I know its been beat to death
« Reply #1 on: July 29, 2002, 03:48:49 AM »
The "no connection has been authorized" means that there is no connection
description in Linux FreeS/WAN's internal database that can be used to
link your ipsec interface with that peer.

Steve Bush

Re: Freeswan I know its been beat to death
« Reply #2 on: July 29, 2002, 07:31:20 AM »
/etc/ipsec.conf

change in conn %default group
compress=no

Michael Smith

Re: Freeswan I know its been beat to death
« Reply #3 on: July 29, 2002, 10:13:21 AM »
Yep, beat to death is right ... but a lot of the ongoing issues for folks who don't go the ServiceLink route remain open.  I have one VPN going just fine, but I'm wrestling with NetBIOS & fileshare access issues.  Don't want to break a working VPN that's doing actual production work, and currently don't have access to a test VPN.  *sigh*  Anybody out there update FreeS/WAN to the latest (1.98b) and did it resolve any issues?

Gerald

Re: Freeswan I know its been beat to death
« Reply #4 on: July 31, 2002, 10:46:20 PM »
I had two vpn connections working just fine under 5.1.2 upgraded to 5.5 and serveral things happened.
1. The security key in both servers disappeared. It now appears to be blank.
2.  I can nolonger establish any connection. The settings that worked before now appear to be broken.
Any ideas would be welcome. TIA