[vpn-help] Regression in Linux shrew 2.1.7 -> OpenBSD 4.8+ roadwarrior VPN

Kevin VPN kvpn at live.com
Sun Sep 11 19:07:00 CDT 2011


On 09/10/2011 03:17 AM, Zak Elep wrote:
> Problem:
>
> Linux shrew 2.1.7 (as available in Ubuntu 11.10 Oneiric) could not complete
> phase1 negotiation to an OpenBSD 4.8/4.9 VPN gateway; it times out.
 > ...
 > 11/09/10 15:06:41 -> : send IKE packet 10.141.71.41:500 ->
 > 210.213.136.182:500 ( 344 bytes )
 > 11/09/10 15:06:41 DB : phase1 resend event scheduled ( ref count = 2 )
 > 11/09/10 15:06:51 -> : resend 1 phase1 packet(s) 10.141.71.41:500 ->
 > xxx.xxx.xxx.xxx:500
 > 11/09/10 15:07:01 -> : resend 1 phase1 packet(s) 10.141.71.41:500 ->
 > xxx.xxx.xxx.xxx:500
 > 11/09/10 15:07:11 -> : resend 1 phase1 packet(s) 10.141.71.41:500 ->
 > xxx.xxx.xxx.xxx:500
 > 11/09/10 15:07:21 ii : resend limit exceeded for phase1 exchange

Hi Zak,

 From the iked.log you provided, it seems that the gateway is not 
responding the the Shrew client's request.  Is there any chance you can 
view the log on the OpenBSD gateway to see what it says about the 
incoming request?

You could also run a packet capture on your Ubuntu box's outgoing 
interface to see if the request is even being sent out.



More information about the vpn-help mailing list