Wałczyłem z tymi FAILEDami od rana u poradziłem sobie tak jak napisałeś, za pomocą
Kod: Zaznacz cały
echo 0 > /proc/sys/net/ipv4/conf/default/send_redirects
echo 0 > /proc/sys/net/ipv4/conf/default/accept_redirects
Zdruzgotał mnie fakt ze wpisy:
Kod: Zaznacz cały
echo 0 > /proc/sys/net/ipv4/conf/all/send_redirects
echo 0 > /proc/sys/net/ipv4/conf/all/accept_redirects
echo 0 > /proc/sys/net/ipv4/conf/eth0/send_redirects
echo 0 > /proc/sys/net/ipv4/conf/eth0/accept_redirects
Nie działały, ale to tak na marginesie.
Niestety nie rozwiązało to mojego problemu gdyż dalej połączenie się nie tworzy.
Gdy w pliku ipsec.conf
Kod: Zaznacz cały
# basic configuration
config setup
nat_traversal=yes
virtual_private=%v4:10.0.0.0/8,%v4:192.168.0.0/16,%4:172.16.0.0/12
interfaces=%defaultroute
conn sample
# Left security gateway, subnet behind it, nexthop toward right.
compress=yes
keyingtries=1
disablearrivalcheck=no
leftrsasigkey=%cert
rightrsasigkey=%cert
authby=rsasig
conn roadwarrior-net
leftsubnet=192.168.0.0/24
also=roadwarrior
conn roadwarrior
left=192.168.0.168
leftcert=server.pem
right=192.168.0.149
rightsubnet=192.168.0.0/24
[b]auto=start[/b]
pfs=yes
conn block
auto=ignore
conn private
auto=ignore
conn private-or-clear
auto=ignore
conn clear-or-private
auto=ignore
conn clear
auto=ignore
conn packetdefault
auto=ignore
wstawiłem polecenie
auto=start aby połączenie było nawiązywane automatycznie okazało się, że odcina mi do dostęp do internetu.
auth.log
Kod: Zaznacz cały
Apr 12 19:00:40 ifrit-VirtualBox ipsec__plutorun: Starting Pluto subsystem...
Apr 12 19:00:40 ifrit-VirtualBox pluto[3137]: Starting Pluto (Openswan
Version 2.6.28; Vendor ID OEQ{O\177nez{CQ) pid:3137
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: SAref support
[disabled]: Protocol not available
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: SAbind support
[disabled]: Protocol not available
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: Setting NAT-Traversal
port-4500 floating to on
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: port floating
activation criteria nat_t=1/port_float=1
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: NAT-Traversal support
[enabled]
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: fixup for bad
virtual_private entry '%4:172.16.0.0/12', please fix your
virtual_private line!
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: fixup for bad
virtual_private entry '%4:172.16.0.0/12', please fix your
virtual_private line!
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: using /dev/urandom as
source of random entropy
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: ike_alg_register_enc():
Activating OAKLEY_TWOFISH_CBC_SSH: Ok (ret=0)
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: ike_alg_register_enc():
Activating OAKLEY_TWOFISH_CBC: Ok (ret=0)
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: ike_alg_register_enc():
Activating OAKLEY_SERPENT_CBC: Ok (ret=0)
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: ike_alg_register_enc():
Activating OAKLEY_AES_CBC: Ok (ret=0)
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: ike_alg_register_enc():
Activating OAKLEY_BLOWFISH_CBC: Ok (ret=0)
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: ike_alg_register_hash():
Activating OAKLEY_SHA2_512: Ok (ret=0)
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: ike_alg_register_hash():
Activating OAKLEY_SHA2_256: Ok (ret=0)
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: starting up 1
cryptographic helpers
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: started helper pid=3140 (fd:7)
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: Kernel interface auto-pick
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: Using Linux 2.6 IPsec
interface code on 2.6.38-8-generic (experimental code)
Apr 12 19:00:41 ifrit-VirtualBox pluto[3140]: using /dev/urandom as
source of random entropy
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: ike_alg_register_enc():
Activating aes_ccm_8: Ok (ret=0)
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: ike_alg_add(): ERROR:
Algorithm already exists
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: ike_alg_register_enc():
Activating aes_ccm_12: FAILED (ret=-17)
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: ike_alg_add(): ERROR:
Algorithm already exists
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: ike_alg_register_enc():
Activating aes_ccm_16: FAILED (ret=-17)
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: ike_alg_add(): ERROR:
Algorithm already exists
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: ike_alg_register_enc():
Activating aes_gcm_8: FAILED (ret=-17)
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: ike_alg_add(): ERROR:
Algorithm already exists
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: ike_alg_register_enc():
Activating aes_gcm_12: FAILED (ret=-17)
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: ike_alg_add(): ERROR:
Algorithm already exists
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: ike_alg_register_enc():
Activating aes_gcm_16: FAILED (ret=-17)
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: Changed path to
directory '/etc/ipsec.d/cacerts'
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: loaded CA cert file
'cacert.pem' (3253 bytes)
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: Changed path to
directory '/etc/ipsec.d/aacerts'
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: Changed path to
directory '/etc/ipsec.d/ocspcerts'
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: Changing to directory
'/etc/ipsec.d/crls'
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: loaded crl file
'crl.pem' (467 bytes)
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: loading certificate from
server.pem
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: loaded host cert file
'/etc/ipsec.d/certs/server.pem' (3147 bytes)
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: added connection
description "roadwarrior-net"
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: loading certificate from
server.pem
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: loaded host cert file
'/etc/ipsec.d/certs/server.pem' (3147 bytes)
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: added connection
description "roadwarrior"
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: listening for IKE messages
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: NAT-Traversal: Trying
new style NAT-T
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: NAT-Traversal:
ESPINUDP(1) setup failed for new style NAT-T family IPv4 (errno=19)
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: NAT-Traversal: Trying
old style NAT-T
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: adding interface
eth0/eth0 192.168.0.149:500
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: adding interface
eth0/eth0 192.168.0.149:4500
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: adding interface lo/lo
127.0.0.1:500
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: adding interface lo/lo
127.0.0.1:4500
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: adding interface lo/lo ::1:500
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: loading secrets from
"/etc/ipsec.secrets"
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: loaded private key
file '/etc/ipsec.d/private/server.key' (963 bytes)
Apr 12 19:00:41 ifrit-VirtualBox pluto[3137]: loaded private key for
keyid: PPK_RSA:AwEAAcbay
nie mam takiego katalogu ani folderu:P