[Vpn-help] Shrew v. 2.1.4 Openswan 2.4.6.1

Matthew Grooms mgrooms at shrew.net
Thu Nov 20 15:56:57 CST 2008


Stefan Bauer wrote:
> 
> Hi Matthew,
> 
> thank you for your response. It seems that the NAT-Box at Roadwarrior
> site is doing something nasty. Please see below the openswan logs:
> 
> klips_debug:ipsec_rcv: suspected ESPinUDP packet (NAT-Traversal) [1].
> klips_debug:   IP: ihl:20 ver:4 tos:0 tlen:340 id:53077 frag_off:0
> ttl:54 proto:17 (UDP) chk:39239 saddr:85.181.187.62:500 daddr:10.8.0.1:500
> klips_debug:ipsec_rcv: IKE packet - not handled here
> klips_debug:ipsec_rcv: suspected ESPinUDP packet (NAT-Traversal) [1].
> klips_debug:   IP: ihl:20 ver:4 tos:0 tlen:265 id:53333 frag_off:0
> ttl:54 proto:17 (UDP) chk:39058 saddr:85.181.187.62:500 daddr:10.8.0.1:500
> klips_debug:ipsec_rcv: IKE packet - not handled here
> klips_debug:ipsec_rcv: suspected ESPinUDP packet (NAT-Traversal) [2].
> klips_debug:   IP: ihl:20 ver:4 tos:0 tlen:1668 id:53589 frag_off:0
> ttl:54 proto:17 (UDP) chk:37399 saddr:85.181.187.62:4500
> daddr:10.8.0.1:4500
> klips_debug:ipsec_rcv: IKE packet - not handled here
> 
> Any ideas about that?
> 

Hmmm, not a lot to work with here. It looks like the only information 
being logged is related to packet reception. I would venture to guess 
that the log level is set too low to be of any use in identifying or 
resolving the problem.

Hope this helps,

-Matthew



More information about the vpn-help mailing list