[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
problems with rc.vpn write: Invalid argument
- To: misc_(_at_)_openbsd_(_dot_)_org
- Subject: problems with rc.vpn write: Invalid argument
- From: Johnathan Norman <jnorman_(_at_)_alertlogic_(_dot_)_net>
- Date: Thu, 16 Jan 2003 16:02:33 -0600
ok ..trying to setup tunnel between to gateways...one is 69.7.160.250
that has 10.0.0.0 behind it...and the other is 66.134.21.142 that has
192.168.1.0 behind it...
the first 2 lines of each config return this error
write: Invalid argument
the config for .142 is as follows:
bash-2.05b# ./rc.vpn.sh
/sbin/ipsecadm new esp -src 66.134.21.142 -dst 69.7.160.250 -forcetunnel
-spi 1000 -enc 3des -auth sha1 -keyfile /etc/esp-enc-key -authkeyfile
/etc/esp-auth-key
/sbin/ipsecadm new esp -src 69.7.160.250 -dst 66.134.21.142 -forcetunnel
-spi 1001 -enc 3des -auth sha1 -keyfile /etc/esp-enc-key -authkeyfile
/etc/esp-auth-key
/sbin/ipsecadm flow -proto esp -src 66.134.21.142 -dst 69.7.160.250
-addr 66.134.21.142 255.255.255.255 69.7.160.250 255.255.255.255 -out
-require
/sbin/ipsecadm flow -proto esp -src 66.134.21.142 -dst 69.7.160.250
-addr 69.7.160.250 255.255.255.255 66.134.21.142 255.255.255.255 -in
-require
/sbin/ipsecadm flow -proto esp -src 66.134.21.142 -dst 69.7.160.250
-addr 192.168.1.0 255.255.255.0 10.0.0.0 255.255.255.0 -out -require
/sbin/ipsecadm flow -proto esp -src 66.134.21.142 -dst 69.7.160.250 -in
-require -addr 10.0.0.0 255.255.255.0 192.168.1.0 255.255.255.0
/sbin/ipsecadm flow -proto esp -dst 69.7.160.250 -out -require -src
66.134.21.142 -addr 66.134.21.142 255.255.255.255 10.0.0.0 255.255.255.0
/sbin/ipsecadm flow -proto esp -dst 69.7.160.250 -in -require -src
66.134.21.142 -addr 10.0.0.0 255.255.255.0 66.134.21.142 255.255.255.255
/sbin/ipsecadm flow -proto esp -dst 69.7.160.250 -out -require -src
66.134.21.142 -addr 192.168.1.0 255.255.255.0 69.7.160.250 255.255.255.255
/sbin/ipsecadm flow -proto esp -dst 69.7.160.250 -in -require -src
66.134.21.142 -addr 69.7.160.250 255.255.255.255 192.168.1.0 255.255.255.0
and .250
bash-2.05b# ./rc.vpn.sh
/sbin/ipsecadm new esp -src 69.7.160.250 -dst 66.134.21.142 -forcetunnel
-spi 1000 -enc 3des -auth sha1 -keyfile /etc/esp-enc-key -authkeyfile
/etc/esp-auth-key
/sbin/ipsecadm new esp -src 66.134.21.142 -dst 69.7.160.250 -forcetunnel
-spi 1001 -enc 3des -auth sha1 -keyfile /etc/esp-enc-key -authkeyfile
/etc/esp-auth-key
/sbin/ipsecadm flow -proto esp -src 69.7.160.250 -dst 66.134.21.142
-addr 69.7.160.250 255.255.255.255 66.134.21.142 255.255.255.255 -out
-require
/sbin/ipsecadm flow -proto esp -src 69.7.160.250 -dst 66.134.21.142
-addr 66.134.21.142 255.255.255.255 69.7.160.250 255.255.255.255 -in
-require
/sbin/ipsecadm flow -proto esp -src 69.7.160.250 -dst 66.134.21.142
-addr 10.0.0.0 255.255.255.0 192.168.1.0 255.255.255.0 -out -require
/sbin/ipsecadm flow -proto esp -src 69.7.160.250 -dst 66.134.21.142 -in
-require -addr 192.168.1.0 255.255.255.0 10.0.0.0 255.255.255.0
/sbin/ipsecadm flow -proto esp -dst 66.134.21.142 -out -require -src
69.7.160.250 -addr 69.7.160.250 255.255.255.255 192.168.1.0 255.255.255.0
/sbin/ipsecadm flow -proto esp -dst 66.134.21.142 -in -require -src
69.7.160.250 -addr 192.168.1.0 255.255.255.0 69.7.160.250 255.255.255.255
/sbin/ipsecadm flow -proto esp -dst 66.134.21.142 -out -require -src
69.7.160.250 -addr 10.0.0.0 255.255.255.0 66.134.21.142 255.255.255.255
/sbin/ipsecadm flow -proto esp -dst 66.134.21.142 -in -require -src
69.7.160.250 -addr 66.134.21.142 255.255.255.255 10.0.0.0 255.255.255.0
whats wrong with the config? As far as i know everything is enabled in
the kernel (ip forwarding , esp and ah)
JOhnathan
Visit your host, monkey.org