(racoon 917) SPD Expires (problem using generate_policy on)
"John Doe" <[email protected]> Thu, 10 Mar 2005 02:51:02 -0500 (EST)
| Newsgroups | gmane.network.ipv6.kame.racoon |
|---|---|
| Message-ID | <[email protected]> |
Hi, I seem to have all the luck and have come across another problem using the racoon IPSEC that comes with FreeBSD5.3. The problem goes like this: I have two machines communicating through a tunnel between a FreeBSD server and a WindowsXP machine. Everything works properly and renegotiation of SA's occurs without a problem. When using the option "generate_policy on" however, after some time racoon notifies that the SPD has expired and deletes the entry in the database. At this point communication fails as WinXP continues sending packets encrypted with IPSEC, FreeBSD is able to decrypt them however responds with a normal unencrypted IP packet. From what I have been able to pick up from searching aroung on the web: ""A bit more investigation reveals that the SA is re-established but the SPD entries at the remote get dropped. This would explain the half duplex communication I am seeing with tcpdump (ping repsonses get back as far as the FreeBSD machine and the lack of SPD means the machine can't route the packet back through the tunnel). What happens is that when the SA gets stale, but before it expires, racoon creates a new SA. But since there is an existing entry in the SPD, a new one is cannot made. When the old SA times out, the its accompanying SPD entry is killed, leaving no SPD entry at all."" Does anyone know of a solution to this or if there is already a fix? Any help much appreciated. Regards Rekkie _______________________________________________ Join Excite! - http://www.excite.com The most personalized portal on the Web!