Koozali.org: home of the SME Server

IPSEC 5.6 U4

Greg

IPSEC 5.6 U4
« on: August 14, 2003, 09:52:43 PM »
I set up two new servers, one on a DSL and one on a T1 but I can't get Freeswan to connect between them. I have never been able to make 5.6 work. I have 5.5 running fine between 3 production servers.
I must be doing something wrong.

Local networks
Network Subnet mask Number of hosts Router
192.168.3.0 255.255.255.0 256

IPSEC VPNs setup:
Remote ID Remote Host Remote Internal IP Remote Internal Subnet Mask
64.83.34.68 64.83.34.68 192.168.3.1 255.255.255.0

[root@SME561 root]# ifconfig
eth0 Link encap:Ethernet HWaddr 00:E0:29:54:B1:D9
inet addr:192.168.2.1 Bcast:192.168.2.255 Mask:255.255.255.0
EtherTalk Phase 2 addr:65280/178
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:6443 errors:0 dropped:0 overruns:0 frame:0
TX packets:170 errors:0 dropped:0 overruns:0 carrier:0
collisions:0
RX bytes:666926 (651.2 Kb) TX bytes:17535 (17.1 Kb)

eth1 Link encap:Ethernet HWaddr 00:E0:29:54:AD:F6
inet addr:66.149.149.218 Bcast:66.149.149.223 Mask:255.255.255.248
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:1986 errors:0 dropped:0 overruns:0 frame:0
TX packets:782 errors:0 dropped:0 overruns:0 carrier:0
collisions:0
RX bytes:208914 (204.0 Kb) TX bytes:196842 (192.2 Kb)


ipsec0 Link encap:Ethernet HWaddr 00:E0:29:54:AD:F6
inet addr:66.149.149.218 Mask:255.255.255.248
UP RUNNING NOARP MTU:16260 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:25 errors:0 dropped:0 overruns:0 carrier:0
collisions:0
RX bytes:0 (0.0 b) TX bytes:5450 (5.3 Kb)

[root@SME561 root]# ipsec eroute
0 66.149.149.218/32 -> 64.83.34.68/32 => %trap
0 66.149.149.218/32 -> 192.168.3.0/24 => %trap
0 192.168.2.0/24 -> 64.83.34.68/32 => %trap
0 192.168.2.0/24 -> 192.168.3.0/24 => %trap



Local networks
Network Subnet mask Number of hosts Router
192.168.2.0 255.255.255.0 256


IPSEC VPNs setup:
Remote ID Remote Host Remote Internal IP Remote Internal Subnet Mask
66.149.149.218 66.149.149.218 192.168.2.1 255.255.255.0


[root@SME562 root]# ifconfig
eth0 Link encap:Ethernet HWaddr 00:06:29:05:F4:10
inet addr:192.168.3.1 Bcast:192.168.3.255 Mask:255.255.255.0
EtherTalk Phase 2 addr:65280/37
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:2500 errors:0 dropped:0 overruns:0 frame:0
TX packets:90 errors:0 dropped:0 overruns:0 carrier:0
collisions:0
RX bytes:251707 (245.8 Kb) TX bytes:9283 (9.0 Kb)

eth1 Link encap:Ethernet HWaddr 00:E0:29:54:B4:39
inet addr:64.83.34.68 Bcast:64.83.34.71 Mask:255.255.255.248
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:625 errors:0 dropped:0 overruns:0 frame:0
TX packets:580 errors:0 dropped:0 overruns:0 carrier:0
collisions:0
RX bytes:92555 (90.3 Kb) TX bytes:97194 (94.9 Kb)

ipsec0 Link encap:Ethernet HWaddr 00:E0:29:54:B4:39
inet addr:64.83.34.68 Mask:255.255.255.248
UP RUNNING NOARP MTU:16260 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:19 errors:0 dropped:21 overruns:0 carrier:0
collisions:0
RX bytes:0 (0.0 b) TX bytes:4142 (4.0 Kb)

[root@test562 root]# ipsec eroute

2 64.83.34.68/32 -> 66.149.149.218/32 => %hold
17 64.83.34.68/32 -> 192.168.2.0/24 => %hold
0 192.168.3.0/24 -> 66.149.149.218/32 => %trap
0 192.168.3.0/24 -> 192.168.2.0/24 => %trap