ipsec problem: shunt SA of DROP or no eroute: dropping.

ipsec problem: shunt SA of DROP or no eroute: dropping.

Post by Vict » Thu, 27 Jun 2002 09:43:36



Hi, there

I'm a newbie on ipsec. When I setup a VPN connection and ping for
test, I always get these errors:
-------------------------------------------------------------------------
Jun 25 15:44:02 penp2 kernel: klips_debug:ipsec_findroute:
208.164.186.1->192.168.1.22
Jun 25 15:44:02 penp2 kernel: klips_debug:rj_match: * See if we match
exactly as a host destination

....

Jun 25 15:44:02 penp2 kernel: klips_debug:ipsec_tunnel_start_xmit:
shunt SA of DROP or no eroute: dropping.
-------------------------------------------------------------------------

Here is part of my ipsec barf:
-------------------------------------------------------------------------
+ _________________________ proc/net/ipsec_eroute
+ sort +3 /proc/net/ipsec_eroute
0          192.168.0.0/24     -> 192.168.1.0/24     => %trap
+ _________________________ proc/net/ipsec_spi
+ cat /proc/net/ipsec_spi
+ _________________________ proc/net/ipsec_spigrp
+ cat /proc/net/ipsec_spigrp
+ _________________________ netstart-rn
+ netstat -nr
Kernel IP routing table
Destination     Gateway         Genmask         Flags   MSS Window
irtt Iface
192.168.1.0     208.164.186.2   255.255.255.0   UG       40 0        
0 ipsec0
192.168.0.0     0.0.0.0         255.255.255.0   U        40 0        
0 eth0
208.164.186.0   0.0.0.0         255.255.255.0   U        40 0        
0 eth1
208.164.186.0   0.0.0.0         255.255.255.0   U        40 0        
0 ipsec0
127.0.0.0       0.0.0.0         255.0.0.0       U        40 0        
0 lo
0.0.0.0         192.168.0.1     0.0.0.0         UG       40 0        
0 eth0

...

+ _________________________ ipsec/status
+ ipsec auto --status
000 interface ipsec0/eth1 208.164.186.1
000
000 "vpn": 192.168.0.0/24===208.164.186.1...208.164.186.2===192.168.1.0/24
000 "vpn":   ike_life: 3600s; ipsec_life: 28800s; rekey_margin: 540s;
rekey_fuzz: 100%; keyingtries: 1
000 "vpn":   policy: RSASIG+ENCRYPT+TUNNEL+PFS+DISABLEARRIVALCHECK;
interface: eth1; trap erouted
000 "vpn":   newest ISAKMP SA: #0; newest IPsec SA: #0; eroute owner:
#0
000
+ _________________________ ifconfig-a
-------------------------------------------------------------------------

can anyone tell me how to solve this problem?

Thanks a lot

Victor

 
 
 

1. DCD Drops, then DTR Drops, Want to Increase Delay (SLIP)

I'm having an occasional problem on my SLIP connection that causes DCD
(incoming) to drop out momentarily.

When this happens, Linux drops DTR in response, and the connection
gets broken.  Generally it happens only once in several hours, though
sometimes it will happen several times in a row over a space of an
hour before it will settle down.

What I would like to do is increase the delay between the time Linux
detects lost DCD and the time it drops DTR ... would like to increase
it to around a second or so.

If someone could direct me to the portion of the code that monitors
DCD and drops DTR, I can take care of the rest.  But I've looked all
through /usr/src/linux/ ..... (I forget the rest of the path to
serial.c), grepped on things like DCD and DTR in as much of the rest
of the source as I can find, and don't see where it's happening.

Linux version is 0.99.15, Slackware 1.1.2, using agetty in inittab to
open up the serial ports (for some reason I was not able to get getty
or getty_ps to do what I needed, probably just a config or RTFM
problem, but in any case agetty works fine).

Any assistance or pointers gratefully accepted.

 . . . . . ep

2. Samaba/Dial-on-demand

3. CAP: DROP: DDP datagrams: dropped, no route.

4. Help on DLX Linux Instration!

5. IPSec Masq with IPTables on 2.4.3 - Connection Drops

6. What to put on a 386 Notebook?

7. Problem with computer network dropping connection

8. xtraceroute installation issues

9. DNS server problem: named drop out

10. Irritating problem with Drag and Drop in SO5

11. Problem detecting CD drop

12. NIS+ problems after network drop

13. : packet drop problem (FE ?)