Questions tagged [openswan]

129 questions
4
votes
2 answers

Openswan tunnel up, but works only in one direction

I've successfully established an IPsec connection, but it works only partially. One side does not send out packets through the tunnel. It seems as if the network topology is unclear to this side. Any help is highly appreciated! Thanks!! This is the…
grasbueschel
  • 121
  • 1
  • 1
  • 5
4
votes
3 answers

FortiGate IPsec VPN: Configuring Multiple Phase 2 Connections (Multiple Subnets)

I am trying to make an IPsec connection to a FortiGate router using OpenSwan. The FortiGate sits on two distinct subnets and I need to access both of them. In the FortiGate I have defined one Phase 1 connection and one Phase 2 connection. This…
FixMaker
  • 235
  • 1
  • 4
  • 9
4
votes
2 answers

Connecting to IPSec/L2tp with OpenSwan/xl2tpd from Windows7 to Amazon EC2

I am trying to connect from my Windows7 at home to my OpenSwan/xl2tpd setup on an Ubuntu EC2 instance at Amazon. It is a connection being NATed from both the client and server ends. I was following tips from several threads for how to accomplish…
Noam Singer
  • 41
  • 1
  • 5
4
votes
0 answers

How do I configure OpenSwan to allow pure IPsec (not L2TP) connections from an iPhone?

Similar to this question, I want to configure an IPsec server on Linux which will accept connections from the iPhone. However, unlike the other question, I want to be able to test with pre-shared keys before making the jump to…
mpontillo
  • 924
  • 6
  • 23
3
votes
1 answer

Tunnel is up but I can't ping

I need to understand and resolve my issue. I know openswan works because when I connect from home network with an internal ip address of 10.0.0.97 to work's VPN, I'm able to ping but when I use the public xFinity wifi it indicates that the tunnel is…
BioRod
  • 303
  • 4
  • 13
3
votes
0 answers

OpenSwan IPSec log explanation

I am trying to understand the IPSec logs. Would be really great if someone can help me to understand the main things I look for and how to troubleshoot any ipsec issue. Would be really great of someone can help me to visualise how this IPSec tunnel…
rrene
  • 131
  • 1
3
votes
0 answers

Is there an extension of host to host ipsec to a many-many configuration?

Having a typical host to host transport mode ipsec configuration, conn appserver01-to-swift01 leftid=@appserver01.server.com left=10.133.176.246 leftrsasigkey=xxxxxxxxxxxxxxxxxxxxxxxx rightid=@swift01.server.com …
user22866
  • 151
  • 6
3
votes
0 answers

Openswan and sonicwall and encryption parameters

This error leads me to investigate my encryption parameters: 003 "sonicwall" #2: ignoring unknown Vendor ID payload [...] Can some expert please have a look at tell me what is wrong? Sonic wall (web interface): ESP: 3DES/HMAC SHA1 (IKE) IKE phase…
jcalfee314
  • 269
  • 1
  • 6
  • 14
3
votes
1 answer

Openswan Cisco ASA 9.1 -- cannot resopnd to IPsec SA request because no connection is known for

Ok, so I have a simple VPN IPSEC setup with a single Linux host that has a public IP address and a loopback interface of 172.16.255.1. On the right side I have a Cisco ASA 5505 9.1. the issue is the Cisco ASA says when debugging "PHASE 2 Completed"…
Jim
  • 988
  • 7
  • 20
  • 33
3
votes
1 answer

L2TP VPN Connection on Debian Squeeze

I need to make an L2TP VPN connection from a Debian Squeeze server. What I have is: The server IP address Shared Key My username and password Just using these 3 parameteres I can establish the VPN connection from my Mac OSX computer right from…
Lashae
  • 183
  • 1
  • 12
3
votes
3 answers

openswan multiple subnets routing issue

I am trying to setup an OpenSwan(2.6.32) on CentOS 6.5 (final) to connect the remote VPC gateway on Amazon cloud. I got the tunnel up. However, only the traffic from/to the last ip range defined in leftsubnets is routed. The first one works for a…
user2413287
  • 31
  • 1
  • 1
  • 3
3
votes
1 answer

IKE Phase 1 Aggressive Mode exchange does not complete

I've configured a 3G IP Gateway of mine to connect using IKE Phase 1 Aggressive Mode with PSK to my openswan installation running on Ubuntu server 12.04. I've configured openswan as follows: /etc/ipsec.conf: version 2.0 config setup …
Isaac Sutherland
  • 787
  • 2
  • 9
  • 17
2
votes
1 answer

OpenSwan IPsec tunnel to Azure Gateway is established but unable to connect

I am currently trying to set up a IPsec tunnel between my on-premise center and to the VPN in Azure. I am setting up OpenSwan 2.6.23 on an Ubuntu Lucid box, and my box is behind a NAT. ipsec.conf config setup nat_traversal=yes …
leeeennyy
  • 43
  • 4
2
votes
1 answer

Routing between OpenSWAN / IPSEC tunnels

I am trying to connect multiple Amazon VPCs (across regions) together using OpenSWAN and Amazon VGW's. The router instance can ping to hosts in both VPCs, and traffic is attempting to cross the router, but is getting dropped. EDIT: I see the counter…
Jason Martin
  • 5,023
  • 17
  • 24
2
votes
2 answers

ipsec: Can't authenticate: no preshared key found for

I'm using Openswan with ipsec and ipsec keeps complaining about the shared-key not being present. I'm running Ubuntu 14.04 . I'm just experimenting on a couple of internal systems since I'm new to this. Output: root@ip-10-1-1-4:/etc# ipsec auto --up…
Dustin Oprea
  • 560
  • 2
  • 8
  • 19
1
2
3
8 9