Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 7 Sep 2001 00:38:02 +1000 (Australia/NSW)
From:      Darren Reed <avalon@cairo.anu.edu.au>
To:        anderson@centtech.com
Cc:        freebsd-security@FreeBSD.ORG
Subject:   Re: Racoon IPSEC issues
Message-ID:  <200109061438.f86Ec2Mq020422@cairo.anu.edu.au>
In-Reply-To: <3B978211.EB11940E@centtech.com> from "Eric Anderson" at Sep 06, 2001 09:02:57 AM

next in thread | previous in thread | raw e-mail | index | archive | help
In some mail from Eric Anderson, sie said:
[...]
> 2001-09-06 08:51:55: INFO: isakmp.c:965:isakmp_ph2begin_r(): responde
> new phase 2 negotiation: xx.yy.zz.60[0]<=>xx.yy.zz.128[0]
> 2001-09-06 08:51:55: ERROR: proposal.c:951:set_proposal_from_policy():
> not supported nested SA. Ignore.
> 2001-09-06 08:51:55: ERROR: proposal.c:999:set_proposal_from_policy():
> There is a difference between the in/out bound policies.

Those last messages might give you a hint.

What does your racoon.conf & setkey's look like for the tunnels which
do work and those that don't ?

Darren

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200109061438.f86Ec2Mq020422>