Discussion:
[Openswan Users] Query about "interfaces" with NETKEY
Nick Howitt
2009-10-16 13:51:13 UTC
Permalink
Hi,

Reading the ipsec.conf manual, it says that with NETKEY it says
interfaces=%none must be used. I've been using interfaces=%defaultroute
up to now with no problems. When I changed it to %none and restarted
ipsec, i got the following errors in /var/log/messages:

Oct 16 14:37:46 server ipsec__plutorun: 022 connection must specify host
IP address for our side
Oct 16 14:37:46 server ipsec__plutorun: 037 attempt to load incomplete
connection
Oct 16 14:37:46 server ipsec__plutorun: 022 connection must specify host
IP address for our side
Oct 16 14:37:46 server ipsec__plutorun: 037 attempt to load incomplete
connection

and in /var/log/secure:

Oct 16 14:38:49 server pluto[7423]: connection must specify host IP
address for our side
Oct 16 14:38:49 server pluto[7423]: attempt to load incomplete connection

and my tunnels failed to come up.

In my conns I use left=%defaultroute.

Am I correct in assuming the manual is incorrect and
interfaces=%defaultroute is valid with NETKEY?

Regards,

Nick
Paul Wouters
2009-10-16 16:55:41 UTC
Permalink
Post by Nick Howitt
Reading the ipsec.conf manual, it says that with NETKEY it says
interfaces=%none must be used. I've been using interfaces=%defaultroute
up to now with no problems. When I changed it to %none and restarted
Oct 16 14:37:46 server ipsec__plutorun: 022 connection must specify host
IP address for our side
Oct 16 14:37:46 server ipsec__plutorun: 037 attempt to load incomplete
connection
Oct 16 14:37:46 server ipsec__plutorun: 022 connection must specify host
IP address for our side
Oct 16 14:37:46 server ipsec__plutorun: 037 attempt to load incomplete
connection
Am I correct in assuming the manual is incorrect and
interfaces=%defaultroute is valid with NETKEY?
Yes you are, though I would have expected %none to work as well. Perhaps
Tuomo can shed some light on this?

Paul
Tuomo Soini
2009-10-17 07:18:44 UTC
Permalink
Post by Paul Wouters
Yes you are, though I would have expected %none to work as well. Perhaps
Tuomo can shed some light on this?
With interfaces=%none you can't use %defaultroute in config afaik. But I
haven't really tested that.
--
Tuomo Soini <***@foobar.fi>
Foobar Linux services
+358 40 5240030
Foobar Oy <http://foobar.fi/>
Loading...