[Swan] FW: IPSec VPN configuration issues. AVX instrucions not detetced / stuck on DDNS phase 2

Sean Smith ssmith at nanb.nb.ca
Wed Feb 19 20:12:29 EET 2014


 

Hi all. I recently have been rebuilding a new Centos server to replace
an

existing one. 

 

I use this server as a backup device and then push my backups to a

remote spot via the IPSec VPN tunnel.

 

It has been working. However, my newly built box using the same

configuration file will not connect.

 

My IPSec verify is below.

 

-------

 

Verifying installed system and configuration files

 

Version check and ipsec on-path                       [OK]

Libreswan 3.7 (netkey) on 3.12.7-200.fc19.x86_64

Checking for IPsec support in kernel                  [OK]

NETKEY: Testing XFRM related proc values

         ICMP default/send_redirects                  [OK]

         ICMP default/accept_redirects                [OK]

         XFRM larval drop                             [OK]

Pluto ipsec.conf syntax                               [OK]

Hardware random device                                [N/A]

Two or more interfaces found, checking IP forwarding    [OK]

Checking rp_filter                                    [OK]

Checking that pluto is running                        [OK]

Pluto listening for IKE on udp 500                   [OK]

Pluto listening for IKE/NAT-T on udp 4500            [OK]

Pluto ipsec.secret syntax                            [OK]

Checking NAT and MASQUERADEing                        [TEST INCOMPLETE]

Checking 'ip' command                                 [OK]

Checking 'iptables' command                           [OK]

Checking 'prelink' command does not interfere with FIPS    [PRESENT]

Checking for obsolete ipsec.conf options              [OK]

Opportunistic Encryption                              [DISABLED]

--------

 

 

 

Also, in the secure and messages files I can see that Phase 1 completes,

but it seems to get stuck on EVENT_PENDING_DDNS. It does queue up

EVENT_PENDING_PHASE2 but never gets by the DDNS.

 

 

 

Any suggestions are greatl appreciated.

 

 

 

Feb 19 09:45:31 localhost pluto[8835]: | * processed 0 messages from

cryptographic helpers

Feb 19 09:45:31 localhost pluto[8835]: | next event EVENT_PENDING_DDNS

in 59 seconds

Feb 19 09:45:31 localhost pluto[8835]: | next event EVENT_PENDING_DDNS

in 59 seconds

Feb 19 09:45:31 localhost pluto[8835]: |

Feb 19 09:45:31 localhost pluto[8835]: | *received whack message

Feb 19 09:45:31 localhost pluto[8835]: initiating all conns with

alias='aliantVPN'

Feb 19 09:45:31 localhost pluto[8835]: | * processed 0 messages from

cryptographic helpers

Feb 19 09:45:31 localhost pluto[8835]: | next event EVENT_PENDING_DDNS

in 59 seconds

Feb 19 09:45:31 localhost pluto[8835]: | next event EVENT_PENDING_DDNS

in 59 seconds

Feb 19 09:45:31 localhost pluto[8835]: | reaped addconn helper child

 



------------------

Nurses Association of New Brunswick 
Association des infirmières et infirmiers du Nouveau-Brunswick

165 Regent Street / 165, rue Regent
Fredericton, N.B. / Fredericton, N.-B.
E3B 7B4
Tel. /. Tél.: 506-458-8731
www.nanb.nb.ca / www.aiinb.nb.ca

This email message (including any attachments, if any) is confidential and may be privileged. Any unauthorized distribution or disclosure is prohibited. If you have received this e-mail in error, please notify us and delete it and any attachments from your computer systems and records.

Ce courriel (y compris les pièces jointes) est confidentiel et peut être protégé. La distribution ou la divulgation non autorisée de ce courriel est interdite. Si vous avez reçu ce courriel par erreur, veuillez nous en aviser et supprimer ce courriel, ainsi que les pièces jointes, de votre système informatique et de vos dossiers.


19/2/2014

------------------




-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.libreswan.org/pipermail/swan/attachments/20140219/387f451c/attachment.html>


More information about the Swan mailing list