Networking Forums

Networking Forums > Computer Networking > Linux Networking > Openswan and pix 515E

Reply
Thread Tools Display Modes

Openswan and pix 515E

 
 
doff
Guest
Posts: n/a

 
      01-19-2006, 04:30 AM
Dear all,

I have tried to set-up an ipsec tunnel between an openswan 1.0.2 and a
Cisco PIX 515.

If anyone knows something about this please tell me.

I have a big problem now because I cannot even set-up the tunnel.
PIX configuration has not been changed and my old setup is working.

The phase 1 of the VPN is ok (ISAKMP SA established) but in my
/var/log/messages I found strange things...

Here is the debug:
Sep 9 16:31:38 linux pluto[21125]: "myconn" #1: Peer ID is ID_FQDN:
'xxx.xxx.xxx.xxx'
Sep 9 16:31:38 linux pluto[21125]: "myconn" #1: issuer crl not found
Sep 9 16:31:38 linux pluto[21125]: "myconn" #1: ISAKMP SA established
Sep 9 16:31:38 linux pluto[21125]: "myconn" #2: initiating Quick Mode
PSK+ENCRYPT+TUNNEL+UP {using isakmp#1}
Sep 9 16:31:38 linux pluto[21125]: "myconn" #1: ignoring informational
payload, type NO_PROPOSAL_CHOSEN
Sep 9 16:31:38 linux pluto[21125]: "myconn" #1: ignoring informational
payload, type IPSEC_INITIAL_CONTACT
Sep 9 16:31:48 linux pluto[21125]: packet from x.x.x.x:500: not enough
room in input packet for ISAKMP Message (remain=0, sd->size=28)
Sep 9 16:31:48 linux pluto[21125]: packet from x.x.x.x:500: sending
notification PAYLOAD_MALFORMED to x.x.x.x:500


What means this message "not enough room in input packet for ISAKMP
Message" ?

If anyone has an idea..
Thanks in advance
 
Reply With Quote
 
 
 
 
doff
Guest
Posts: n/a

 
      01-19-2006, 06:27 AM
In article <MPG.1e39424dad8d4917989680@localhost>,
(E-Mail Removed) says...

I've found the pb...
The network/mask defined in the ipsec.conf differed from the
network/mask in the pix acl

Strange behavior of pluto saying "packet from x.x.x.x:500: not enough
room in input packet for ISAKMP Message (remain=0, sd->size=28)"

Maybe this solution helps.
Best regards.

 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
openswan pierre Linux Networking 0 02-27-2007 11:41 PM
openswan also= slebetman@yahoo.com Linux Networking 0 01-09-2007 08:51 AM
openswan Adam Linux Networking 2 05-23-2006 10:04 AM
OpenSwan VPN - not only ESP frames mathias@gummert.de Linux Networking 0 10-16-2005 12:43 PM
openswan vpn Luke Matthews Linux Networking 2 08-31-2004 07:32 PM



1 2 3 4 5 6 7 8 9 10 11