IPv6 readyNote: This archive passes through spamassassin. Every mail marked with the subject "*****SPAM*****" has exceed a certain threshold of spam-like behaviour.

Re: [Users] freeswan says SA established, but softpk keeps retransmitting ISAKMP OAK MM *

From: Andreas Steffen (andreas.steffen_at_strongsec.com)
Date: Sun Mar 17 2002 - 12:11:37 CET


Doug Wilson wrote:
>
> I'm now able to import my 1024 bit key into softpk. When I try to
> initiate the connection however, I see the following behavior.
> Strangely, it looks to me like FreeS/WAN thinks the connection has been
> established, but softpk doesn't (freeswan says "sent MR3, ISAKMP SA
> established."). Maybe softpk fails because it sends
> NOTIFY:STATUS_INITIAL_CONTACT and never gets an answer from freeswan
> since freeswan says
> ignoring informational payload, type IPSEC_INITIAL_CONTACT?
>
> ########softpk log:
> 15:56:17.071 My Connections\Alex FSWAN - SENDING>>>> ISAKMP OAK MM *(ID,
> CERT, CERT_REQ, SIG, NOTIFY:STATUS_INITIAL_CONTACT)
> 15:56:32.624 My Connections\Alex FSWAN - message not received!
> Retransmitting!

> ###########end softpk log
>
> #####what I believe are the relevant parts of the FreeS/WAN log (with
> Mar 16 11:20:09 deunan Pluto[4287]: | sending 1556 bytes for retransmit
> in response to duplicate through eth0 to 209.70.116.116:500:

The last message FreeS/WAN sends has a size of 1556 bytes.
This means that this UDP datagram is going to be fragmented.
Either you have a firewall in between which is discarding the IP fragment
or it is Soft-PK itself that dumps it. I deposited a bug report with
SafeNet more than a year ago, saying that Soft-PK cannot handle IP fragments
in reverse order (Linux sends the second fragment first and the main fragment
with the UDP header afterwards). So it seems that SafeNet still has not
solved this bug.

As a workaround I'm using certificates of a size less than 1000 bytes
and try to keep the distinguished names as short as possible. With
this I can avoid the fragmentation issue and Soft-PK has been working
correctly ever since.

> -----------------------------------------------------------
> Doug Wilson
> Project Director - Information Systems
> Virtual Technology Corporation
> 703-658-7050
> dwilson_at_virtc.com

Regards

Andreas

======================================================================
Andreas Steffen e-mail: andreas.steffen_at_strongsec.com
strongSec GmbH phone: +41 76 340 25 56
Alter Zürichweg 20 home: http://www.strongsec.com
CH-8952 Schlieren (Switzerland)
==========================================[strong internet security]==
_______________________________________________
Users mailing list
Users_at_lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users



This archive was generated by hypermail 2.1.3 : Mon Jul 29 2002 - 05:19:44 CEST