[Comm] вопрос по ipsec2

Vitaly Gorshkov =?iso-8859-1?q?vita55555_=CE=C1_mail=2Eru?=
Вт Дек 13 13:59:09 MSK 2005


Dec 13 13:50:07 vpn_test setup: ipsec config succeeded
Dec 13 13:50:07 vpn_test ipsec_setup: Stopping Openswan IPsec...
Dec 13 13:50:09 vpn_test kernel: IPSEC EVENT: KLIPS device ipsec1 shut down.
Dec 13 13:50:09 vpn_test kernel: klips_info:pfkey_cleanup: shutting down PF_KEY domain sockets.
Dec 13 13:50:09 vpn_test kernel: klips_info:cleanup_module: ipsec module unloaded.
Dec 13 13:50:09 vpn_test ipsec_setup: ...Openswan IPsec stopped
Dec 13 13:50:09 vpn_test setup: ipsec setup succeeded
Dec 13 13:50:11 vpn_test ipsec_setup: Starting Openswan IPsec 1.0.9...
Dec 13 13:50:13 vpn_test ipsec_setup: Using /lib/modules/2.4.26-std-up-alt6/kernel/net/ipsec/ipsec.o
Dec 13 13:50:13 vpn_test kernel: klips_info:ipsec_init: KLIPS startup, Openswan IPsec stack 1.0.6
Dec 13 13:50:13 vpn_test kernel: klips_info:ipsec_alg_init: KLIPS alg v=0.8.1-0 (EALG_MAX=255, AALG_MAX=15)
Dec 13 13:50:13 vpn_test kernel: klips_info:ipsec_alg_init: calling ipsec_alg_static_init()
Dec 13 13:50:13 vpn_test ipsec_setup: KLIPS debug `none'
Dec 13 13:50:14 vpn_test ipsec_setup: KLIPS ipsec1 on eth0
xx.xx.xx.xx/255.255.255.248 broadcast xx.x.xx.xx
Dec 13 13:50:15 vpn_test ipsec_setup: ...Openswan IPsec started
Dec 13 13:50:15 vpn_test setup: ipsec setup succeeded
Dec 13 13:50:18 vpn_test ipsec__plutorun: 003 "ru-p3": route-client command exited with status 7
Dec 13 13:50:18 vpn_test ipsec__plutorun: 025 "ru-p3": could not route
Dec 13 13:50:18 vpn_test ipsec__plutorun: ...could not route conn "ru-p3"

config setup
        interfaces="ipsec1=eth0"
        klipsdebug=none
        plutodebug=none

        plutoload=%search
        plutostart=%search

        ##syslog=daemon.err
        ##uniqueids=yes


conn %default
        keyingtries=0
        disablearrivalcheck=no
        auth=esp
        authby=rsasig
        compress=yes
        pfs=yes

        ah=hmac-md5-96
        esp=3des-md5-96
        ike=3des-md5-modp1536,3des-md5-modp1024,3des-sha-modp1536,3des-sha-modp1024
        keylife=20m
        ikelifetime=60m

conn ru-p3
        auth=esp
        esp=3des-md5
        ##ike=3des-md5-modp1536,3des-md5-modp1024,3des-sha-modp1536,3des-sha-modp1024
        type=tunnel
        authby=secret
        left=хх.хх.хх.хх
        leftnexthop=хх.хх.хх.хх
        leftsubnet=192.168.2.0/24
        right=хх.хх.х.х
        rightnexthop=х.х.х.х
        rightsubnet=192.168.1.0/24
        spi=0x300
        #auto=add
        auto=start


>Dec 13 13:50:18 vpn_test ipsec__plutorun: 025 "ru-p3": could not route
В чем может быть дело?



-- 
С уважением,
 Vitaly                          mailto:vita55555 на mail.ru
icq: 138491970





Подробная информация о списке рассылки community