help with IKE/IPsec config

From: Dustin Hoff (dustin+sunmanagers_at_dustinhoff.com)
Date: 08/31/04

  • Next message: Antonio Iglesias Ibaņez: "Kde Packages for Solaris 2.6"
    Date: Tue, 31 Aug 2004 12:03:50 -0400
    To: sunmanagers@sunmanagers.org
    
    

    Hello,
    I am trying to configure S9 in.iked to communicate with racoon
    (FreeBSD) but it isn't working. On the Solaris side, I have the
    following config:

    /etc/inet/ipsecinit.conf:
    {} ipsec {encr_algs 3des encr_auth_algs sha1 sa shared }

    /etc/inet/ike/config:
    p1_lifetime_secs 14400
    p1_nonce_len 20

    {
       label "METRO WLAN"
       local_id_type ip
       local_addr 192.168.4.1
       remote_addr 192.168.4.0/24
       p1_xform { auth_method preshared oakley_group 2 auth_alg sha1 encr_alg 3des }
       ps_lifetime_secs 3600
       p2_pfs 2
    }

    /etc/inet/secret/ike.preshared
    {
       localidtype IP
       localid 192.168.4.1
       remoteidtype IP
       remoteid 192.168.4.5
       key d0a5bf693984f1cf3c88f3f30eac296ef3f381e3 (don't worry, I'll change this :-))
    }

    Sun is 192.168.4.1, BSD is 192.168.4.5, and I want all communication
    between the two to be IPsec. When I run in.iked -d I get the
    following errors:

    /usr/lib/inet/in.iked: In ssh_policy_new_connection (pm_info = 0x71c90).
    /usr/lib/inet/in.iked: Rejecting inbound phase 1: no rules.
    /usr/lib/inet/in.iked: Phase 1 negotiation error: Aborted notification.
    /usr/lib/inet/in.iked: In ssh_policy_isakmp_sa_freed. Clobbering phase1 instance

    I'm sure this is a simple fix and i think the problem is with the
    solaris config, but does anyone have any suggestions?

    Thanks in advance.

    Dustin
    _______________________________________________
    sunmanagers mailing list
    sunmanagers@sunmanagers.org
    http://www.sunmanagers.org/mailman/listinfo/sunmanagers


  • Next message: Antonio Iglesias Ibaņez: "Kde Packages for Solaris 2.6"

    Relevant Pages

    • SUMMARY: Solaris 8 Postfix SMTP Gateway and Postfix Mailserver
      ... postfix config problem. ... That you make entries in /etc/hosts for gateway and mailserver with both ... from OpenWebMail to a domain or local user on the same server it will not be ... No I know that this is not a special Solaris 8 question but I don't know if ...
      (SunManagers)
    • Solaris Express network config
      ... I just gave Solaris Expres b81 a try and have problems with the nework ... pico /etc/hostname.nge0 ... network config via dhcp. ... How can I get normal network config ...
      (SunManagers)
    • Re: Samba problem
      ... I am trying to set up Samba in a Solaris 10 system. ... Server role: ROLE_STANDALONE ... you could look for the missing files and then update your config file accordingly. ...
      (comp.unix.solaris)
    • Re: 10 GA new install. X-server cannot be started on Display :0
      ... |write "on-the-fly" the config. ... |documented by Xorg). ... supported on Solaris. ... DRI requires kernel support not yet available for the ...
      (comp.unix.solaris)
    • Re: Seeking virtual window manager suggestions
      ... Plus has a lightweight digital clock, ... Then if you have tired of fiddling with config files, ... -- http://www.blastwave.org/ for solaris pre-packaged binaries with pkg-get Organized by the author of pkg-get ...
      (comp.unix.solaris)