[x] Welcome to LinuxSolved.com Linux help forums, here we are a community of Linux users helping each other. It is helpful to both ie. new linux users as well experienced one. We always have our experts to help you and ofcourse members help each other, so you can ask for help any time by Registering.: Click to Register

Welcome, Guest. Please login or register.
Did you miss your activation email?


Login with username, password and session length

Linux Forums - Linux Help,Advice & support community:LinuxSolved.com  |  Forum  |  Linux in General  |  Linux Kernel  |  Topic: vpn with ipsec -error
The LinuxSolved.com GNU/Linux User Communit - Forum
Welcome to LinuxCommunity You have just arrived to a friendly linux community which is helping Linux Users from Years.. You can be its part if you have not already joined it. Registration is FREE and is gateway to unlimited help and support to all your linux related needs. If you are an GNU/Linux supporter then you have come to the right place.
Pages: [1]
  Print  
Author Topic: vpn with ipsec -error  (Read 1089 times)
0 Members and 1 Guest are viewing this topic.
govind
New Member

Offline Offline

Posts: 2


View Profile
« on: July 01, 2006, 12:23:10 AM »

I Tried vpn using  ipsec protocol thn i got eroors like this
 
First tried wit nat traversal=yes option in ipsec.conf: thn i got this error
 
Jul  1 04:31:19 (none) ipsec__plutorun: 003 NAT-Traversal: ESPINUDP(1) not supported by kernel for family IPv4
Jul  1 04:31:19 (none) ipsec__plutorun: 003 NAT-Traversal: ESPINUDP(2) not supported by kernel for family IPv4
 
So i tried without  NAT  setting in my router.
 
IPSEC.conf
---------
config setup
        interfaces=%defaultroute
        klipsdebug=none
        plutodebug=none
conn %default
        keyingtries=1
        compress=yes
        disablearrivalcheck=no
        authby=rsasig
        leftrsasigkey=%cert
        rightrsasigkey=%cert
conn roadwarrior-net
        leftsubnet=192.168.1.0/24
        also=roadwarrior
conn roadwarrior
        left=%defaultroute
        leftcert=hostcert.pem
        right=%any
        rightcert=CLIENTcert.pem
        auto=start
        pfs=yes
conn block
    auto=ignore
conn private
      auto=ignore
conn private-or-clear
      auto=ignore
conn clear-or-private
      auto=ignore
conn clear
      auto=ignore
conn packetdefault
     auto=ignore
 
 
thn I got this error when start ipsec service
 
Jul  1 21:25:05 (none) pluto[5358]: listening for IKE messages
Jul  1 21:25:05 (none) pluto[5358]: adding interface ipsec0/ppp1000 222.228.172.225:500
Jul  1 21:25:05 (none) pluto[5358]: loading secrets from "/etc/ipsec.secrets"
Jul  1 21:25:05 (none) pluto[5358]:   loaded private key file '/etc/ipsec.d/private/hostkey.pem' (887 bytes)
Jul  1 21:25:05 (none) pluto[5358]: "roadwarrior": cannot route template policy of RSASIG+ENCRYPT+COMPRESS+TUNNEL+PFS
Jul  1 21:25:05 (none) pluto[5358]: "roadwarrior-net": cannot route template policy of RSASIG+ENCRYPT+COMPRESS+TUNNEL+PFS
Jul  1 21:25:06 (none) pluto[5358]: "roadwarrior": cannot initiate connection without knowing peer IP address (kind=CK_TEMPLATE)
Jul  1 21:25:06 (none) pluto[5358]: "roadwarrior-net": cannot initiate connection without knowing peer IP address (kind=CK_TEMPLATE)

what wil be the error would be, i can't find where the error has rised.
 
How to fix this error,
"roadwarrior-net": cannot initiate connection without knowing peer IP address (kind=CK_TEMPLATE)

help me please...

govind.
Logged
Ricky
LST CareTaker
Specially Skilled
*****
Offline Offline

Gender: Male
Posts: 2205


View Profile
« Reply #1 on: July 01, 2006, 02:04:37 AM »

You have to keep nat traversal = yes .
You need some patch. Someone suggested following but I am not sure if this is the right one.
open-source.arkoon.net/kernel.php#pkthand

I found a detailed instruction , you may see
http://66.102.7.104/search?q=cache:-4EFrfmIr4gJ:ipsec.math.ucla.edu/services/ipsec-linux.html+NAT-Traversal+patch&hl=en&gl=in&ct=clnk&cd=10&client=firefox-a
Logged
govind
New Member

Offline Offline

Posts: 2


View Profile
« Reply #2 on: July 02, 2006, 11:03:47 PM »

hi Ricky,

Thkx for ur nice reply.

My router is a small device with linux OS (monta vista linux)
so we can't install any new software on tht.
i chked up openssl and ipsec modules are installed.

so i want a solution wit out NAT also ok.

Jul 1 21:25:05 (none) pluto[5358]: "roadwarrior": cannot route template policy of RSASIG+ENCRYPT+COMPRESS+TUNNEL+PFS
Jul 1 21:25:05 (none) pluto[5358]: "roadwarrior-net": cannot route template policy of RSASIG+ENCRYPT+COMPRESS+TUNNEL+PFS
Jul 1 21:25:06 (none) pluto[5358]: "roadwarrior": cannot initiate connection without knowing peer IP address (kind=CK_TEMPLATE)
Jul 1 21:25:06 (none) pluto[5358]: "roadwarrior-net": cannot initiate connection without knowing peer IP address (kind=CK_TEMPLATE)


let me know any answer regarding this error.

thkx in advance.

bye
govind
Logged
Linux Forums - Linux Help,Advice & support community:LinuxSolved.com
   

 Logged
Pages: [1]
  Print  
 
Jump to:  

Related Topics
Subject Started by Replies Views Last post
up2date error Miscellaneous sathish 1 1342 Last post April 07, 2004, 03:59:42 PM
by sathish
sendmail - error 553 Linux Servers Support stephen 0 1712 Last post July 27, 2004, 11:49:05 AM
by stephen
squid error Linux Servers Support moon2day 3 1034 Last post August 01, 2004, 10:17:03 AM
by Ricky
SM Error Linux Servers Support mfaisalkh 0 783 Last post August 09, 2004, 04:32:02 AM
by mfaisalkh
DNS - rndc error Linux Servers Support sathish 1 1075 Last post October 12, 2004, 04:27:04 AM
by Ricky
Welcome, Guest. Please login or register.
Did you miss your activation email?
November 22, 2008, 07:09:54 PM

Login with username, password and session length
Navigation
Recent Discussions
[Today at 02:29:08 PM]

[November 20, 2008, 11:30:52 PM]

[November 19, 2008, 07:52:41 PM]

[November 19, 2008, 07:52:36 PM]

[November 17, 2008, 10:42:59 AM]

[November 16, 2008, 12:49:47 AM]

[November 16, 2008, 12:48:58 AM]

[November 15, 2008, 08:29:02 AM]

[November 15, 2008, 08:24:41 AM]

[November 14, 2008, 05:11:50 AM]
Members
Total Members: 6229
Latest: razon_nnn
Stats
Total Posts: 8270
Total Topics: 2254
Online Today: 14
Online Ever: 111
(June 28, 2007, 06:47:29 AM)
Users Online
Users: 0
Guests: 12
Total: 12
Privacy Policy| Powered by SMF 1.1.4 | SMF © 2006-2007, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Theme & TinyPortal v0.9.8 © Bloc