Networking Forums

Networking Forums > Computer Networking > Linux Networking > IPSEC tunnel fails with "pfkey UPDATE failed: Invalid argument"

Reply
Thread Tools Display Modes

IPSEC tunnel fails with "pfkey UPDATE failed: Invalid argument"

 
 
George
Guest
Posts: n/a

 
      09-29-2005, 02:46 AM

Hi,

May someone please tell me why the IPSEC tunnel I try to make fails as
follows:

racoon -F -f /etc/racoon/racoon.cfg
Foreground mode.
2005-09-28 22:34:39: INFO: @(#)ipsec-tools 0.6.beta1
(http://ipsec-tools.sourceforge.net)
2005-09-28 22:34:39: INFO: @(#)This product linked OpenSSL 0.9.7d 17 Mar
2004 (http://www.openssl.org/)
2005-09-28 22:34:40: INFO: 69.70.21.106[500] used as isakmp port (fd=5)
2005-09-28 22:34:40: INFO: 69.70.21.106[500] used for NAT-T
2005-09-28 22:34:40: INFO: IPsec-SA request for 64.235.194.78 queued due to
no phase1 found.
2005-09-28 22:34:40: INFO: initiate new phase 1 negotiation: 69.70.21.10
[500]<=>64.235.194.78[500]
2005-09-28 22:34:40: INFO: begin Identity Protection mode.
2005-09-28 22:34:45: INFO: ISAKMP-SA established 69.70.21.10
[500]-64.235.194.78[500] spi:e095758065e98bfa:1b2c7ac9b51a6ffe
2005-09-28 22:34:46: INFO: initiate new phase 2 negotiation: 69.70.21.10
[0]<=>64.235.194.78[0]
2005-09-28 22:34:47: ERROR: pfkey UPDATE failed: Invalid argument
2005-09-28 22:34:47: ERROR: pfkey ADD failed: Invalid argument
2005-09-28 22:35:16: ERROR: 64.235.194.78 give up to get IPsec-SA due to
time up to wait.
2005-09-28 22:35:16: INFO: IPsec-SA expired: ESP/Tunnel
64.235.194.78->69.70.21.106 spi=230932054(0xdc3be56)


What that means and how should I correct the problem? All necessary options
for IPSEC are in the kernel (2.6.13) that I use. I also run NAT firewall on
that box, but it should not affect things. What means pfkey UPDATE failed?

Any help appreciated,
George.
 
Reply With Quote
 
 
 
 
George
Guest
Posts: n/a

 
      09-29-2005, 02:40 PM
Ok, I found it: I compiled ipsec-tools package against headers from 2.4
release kernel and executed them on a computer running 2.6 release of
kernel. A recompile against 2.6 kernel tree fixed the problem.

George
 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
"Schema update failed: duplicate OID." Error running adprep BW Windows Networking 0 06-18-2007 09:20 PM
Continuation of "Arrrgh! rsync "chroot failed" error message!" kenney@lucent.com Linux Networking 3 08-10-2006 08:35 AM
Local forwarding with "iptables" gives "invalid arguments" newsfuzzy@geekmail.de Linux Networking 0 07-19-2006 02:47 PM
Help! Ipsec-tools/Racoon link through NAT .. "ip route" fails Sundial Services Linux Networking 12 11-28-2004 06:33 PM
iptables - "invalid argument" error ? martin02 Linux Networking 4 10-05-2003 08:47 PM



1 2 3 4 5 6 7 8 9 10 11