Need help with FreeSwan on SuSE 8.2

From: Slav Inger (slavinger_at_yahoo.com)
Date: 03/25/04


Date: 25 Mar 2004 13:27:39 -0800

Hello,

Trying to get IPSec to work on 8.2 using FreeSwan 1.99_0.9.34-77.
"authby" is "secret", identical secrets with correct IP addresses on
both machines, "interfaces" is explicitly set to "ipsec0=eth0". No
errors during startup or in the logs. 'ipsec ikeping' also pings just
fine. Ipsec0 is up and 'route' for ipsec0 is the same as for eth0. I
even tried switching IP addresses around for "left" and "right" in
/etc/ipsec.conf on one host, and it made no difference.

With both machines running IPSec daemons, tcpdump and ethereal show
unencrypted traffic on both ipsec0 and eth0 interfaces.

Any suggestions?

Thanks.



Relevant Pages

  • Need help with FreeSwan on SuSE 8.2
    ... Trying to get IPSec to work on 8.2 using FreeSwan 1.99_0.9.34-77. ... identical secrets with correct IP addresses on ... With both machines running IPSec daemons, ... unencrypted traffic on both ipsec0 and eth0 interfaces. ...
    (comp.os.linux.networking)
  • Re: Should I install Certificate Authority to solve these problems ?
    ... You can use IPsec with or without certs from your PKI. ... negotiations to your AD machines or those trusting the ... > In the item 1 below, the tool in use is a HP server management tool (type ... >>> Management is pushing to get Certificate Authority ...
    (microsoft.public.win2000.security)
  • Help! ipsec not talking IKE
    ... I'm trying to get ipsec working. ... host-to-host setup, with a PSK going as a test/proof of concept. ... machines are on the same subnet, but to avoid interfering with what's ...
    (comp.os.linux.security)
  • Re: IPSEC config
    ... spdadd 10.20.30.0/24 172.28.56.0/23 any -P out ipsec ... 15:24:18.927721 sunburn> acesfbsd: icmp: echo request ... fxp0: flags=8943mtu ... Then I have two machines on these nets that have routing pointing to ...
    (FreeBSD-Security)
  • Re: I have a few dumb questions
    ... on my DC and other machines in the domain, ... but if I disable IPSec on the DC and then on the other machines in the ... I forced a policy refresh, ... apparently missing a step even though I can visually verify that IPSec ...
    (microsoft.public.cert.exam.mcsa)