From owner-freebsd-questions@FreeBSD.ORG Tue May 17 11:47:41 2005 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 1281316A4CE for ; Tue, 17 May 2005 11:47:41 +0000 (GMT) Received: from smarthost2.sentex.ca (smarthost2.sentex.ca [205.211.164.50]) by mx1.FreeBSD.org (Postfix) with ESMTP id 8B82F43D8E for ; Tue, 17 May 2005 11:47:40 +0000 (GMT) (envelope-from mike@sentex.net) Received: from BLUELAPIS.sentex.ca (cage.simianscience.com [64.7.134.1]) by smarthost2.sentex.ca (8.13.3/8.13.3) with SMTP id j4HBlQ1K088708; Tue, 17 May 2005 07:47:26 -0400 (EDT) (envelope-from mike@sentex.net) From: Mike Tancsa To: Daren Russell Date: Tue, 17 May 2005 07:47:33 -0400 Message-ID: References: <23gi81pattnnan1rlv8uc0dva1ken5r8cj@4ax.com> In-Reply-To: X-Mailer: Forte Agent 1.93/32.576 English (American) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: quoted-printable X-Virus-Scanned: ClamAV version 0.84, clamav-milter version 0.84e on smarthost2.sentex.ca X-Virus-Status: Clean cc: freebsd-questions@freebsd.org Subject: Re: IPSec and Racoon between 5.4 and 4.11 X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 17 May 2005 11:47:41 -0000 On Tue, 17 May 2005 09:33:40 +0100, in sentex.lists.freebsd.questions you wrote: >A basic tunnel (without any encryption) works fine. As soon as >ipsec_enable is set in rc.conf, it fails. > >setkey -D shows No SAD entries. > >If I start a ping from 192.168.1.254 -> 192.168.0.254, the receiving >machine get's an 'Invalid length of payload' error, whilst the sending >machine is getting an 'phase 2 negotiation failed due to time up waiting >for phase1. ESP 62.x.x.125->82.x.x.141' (The ip's shown are what they >should be.) I can probably transfer entire parts of the log files if >required, but at the moment, both machines are isolated. > >A further point I've discovered having left them running for a while, is >the racoon on the AMD64 keeps crashing and dumping core (although I >don't know what to do with that!). Maybe there is an issue with racoon >on 64bit? Maybe I should try re-installing with a standard i386 arch. >(Last ditch!) Yes, I would try and see if moving to i386 fixes the problem. Assuming you do have all the configs correct, there is no reason why it should not work. > >Both racoon's are 'racoon-2005-0510a' BTW. I have only just started using this version last weekend so I am not sure how good it is, but I suspect its the AMD64 thats at issue if all your configs are indeed correct. ---Mike -------------------------------------------------------- Mike Tancsa, Sentex communications http://www.sentex.net Providing Internet Access since 1994 mike@sentex.net, (http://www.tancsa.com)