ich versuche gerade mein WLAN mit ipsec so abzusichern, dass ich mich mit meinem Notebook als Roadwarrior zu meinem Debian-Rechner verbinde, auf dem openswan läuft, der mich dann weiter in mein lokales LAN verbindet.
Dazu habe ich Folgendes in der ipsec.conf meines Debian-Rechners stehen:
Code: Alles auswählen
version 2.0 # conforms to second version of ipsec.conf specification
# basic configuration
config setup
conn testconnection
auto=add
authby=secret
left=%any
right=192.168.1.1
pfs=yes
keyingtries=0
conn testconnection-net
auto=add
authby=secret
left=%any
right=192.168.1.1
rightsubnet=10.0.0.0/8
rightnexthop=10.0.0.3
pfs=yes
keyingtries=0
include /etc/ipsec.d/examples/no_oe.conf
Code: Alles auswählen
conn testconnection
left=%any
right=192.168.1.1
presharedkey="passwort"
auto=start
pfs=yes
conn testconnection-net
left=%any
right=192.168.1.1
rightsubnet=10.0.0.0/8
rightnexthop=10.0.0.3
presharedkey="passwort"
auto=start
pfs=yes
In /var/log/auth.log ist jedoch folgende Zeile zu sehen:
Sep 27 17:58:56 debian pluto[6218]: "testconnection"[1] 192.168.1.2 #2: ERROR: netlink response for Add SA esp.edc9005a@192.168.1.1 included errno 2: No such file or directory
Ich kann aber leider mit dieser Meldung nichts anfangen, was bedeutet dieser Fehler?
Hier noch die gesamten ipsec-relevanten Einträge aus /var/log/auth.log
Code: Alles auswählen
Sep 27 17:58:24 debian ipsec__plutorun: Starting Pluto subsystem...
Sep 27 17:58:24 debian pluto[6218]: Starting Pluto (Openswan Version 2.1.3 X.509-1.4.8-1 PLUTO_USES_KEYRR)
Sep 27 17:58:24 debian pluto[6218]: including NAT-Traversal patch (Version 0.6c) [disabled]
Sep 27 17:58:24 debian pluto[6218]: Using Linux 2.6 IPsec interface code
Sep 27 17:58:25 debian pluto[6218]: Changing to directory '/etc/ipsec.d/cacerts'
Sep 27 17:58:25 debian pluto[6218]: Warning: empty directory
Sep 27 17:58:25 debian pluto[6218]: Changing to directory '/etc/ipsec.d/crls'
Sep 27 17:58:25 debian pluto[6218]: Warning: empty directory
Sep 27 17:58:27 debian pluto[6218]: added connection description "testconnection-net"
Sep 27 17:58:28 debian pluto[6218]: added connection description "testconnection"
Sep 27 17:58:29 debian pluto[6218]: listening for IKE messages
Sep 27 17:58:29 debian pluto[6218]: adding interface wlan0/wlan0 192.168.1.1
Sep 27 17:58:29 debian pluto[6218]: adding interface eth0/eth0 10.0.0.11
Sep 27 17:58:29 debian pluto[6218]: adding interface lo/lo 127.0.0.1
Sep 27 17:58:29 debian pluto[6218]: loading secrets from "/etc/ipsec.secrets"
Sep 27 17:58:55 debian pluto[6218]: packet from 192.168.1.2:500: ignoring Vendor ID payload [MS NT5 ISAKMPOAKLEY 00000002]
Sep 27 17:58:55 debian pluto[6218]: packet from 192.168.1.2:500: ignoring Vendor ID payload [FRAGMENTATION]
Sep 27 17:58:55 debian pluto[6218]: packet from 192.168.1.2:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n] meth=106, but already using method 0
Sep 27 17:58:55 debian pluto[6218]: "testconnection-net"[1] 192.168.1.2 #1: responding to Main Mode from unknown peer 192.168.1.2
Sep 27 17:58:55 debian pluto[6218]: "testconnection-net"[1] 192.168.1.2 #1: transition from state (null) to state STATE_MAIN_R1
Sep 27 17:58:56 debian pluto[6218]: "testconnection-net"[1] 192.168.1.2 #1: transition from state STATE_MAIN_R1 to state STATE_MAIN_R2
Sep 27 17:58:56 debian pluto[6218]: "testconnection-net"[1] 192.168.1.2 #1: Peer ID is ID_IPV4_ADDR: '192.168.1.2'
Sep 27 17:58:56 debian pluto[6218]: "testconnection-net"[1] 192.168.1.2 #1: transition from state STATE_MAIN_R2 to state STATE_MAIN_R3
Sep 27 17:58:56 debian pluto[6218]: "testconnection-net"[1] 192.168.1.2 #1: sent MR3, ISAKMP SA established
Sep 27 17:58:56 debian pluto[6218]: "testconnection"[1] 192.168.1.2 #2: responding to Quick Mode
Sep 27 17:58:56 debian pluto[6218]: "testconnection"[1] 192.168.1.2 #2: ERROR: netlink response for Add SA esp.edc9005a@192.168.1.1 included errno 2: No such file or directory
Sep 27 17:58:56 debian pluto[6218]: "testconnection"[1] 192.168.1.2: deleting connection "testconnection" instance with peer 192.168.1.2 {isakmp=#0/ipsec=#0}
Sep 27 17:58:57 debian pluto[6218]: "testconnection-net"[1] 192.168.1.2 #1: Quick Mode I1 message is unacceptable because it uses a previously used Message ID 0x0881c6d3 (perhaps this is a duplicated packet)
Sep 27 17:59:27 debian last message repeated 4 times