Your Sentinel peer does not declare its 10.0.2.0/24 subnet during
quick mode. Therefore the negotiation fails:
laptop-test1-any" 192.168.2.121 #3: cannot respond to IPsec SA request
because no connection is known for 10.0.1.0/24===192.168.2.166...192.168.2.121
Regards
Andreas
fan jiao wrote:
>
> Greetings,
>
> I have the following topo:
>
> 10.0.1.0===171.68.2.166...%any===10.0.2.0
> freeswan sentinel
>
> The client says main mode failed, while
> freeswan complains about ""laptop-test1-any"
> 192.168.2.121 #1: Quick Mode I1 message is
> unacceptable because it uses a previously used Message
> ID 0x74602d55 (perhaps this is a duplicated packet)".
>
> Attached please find the barf.
>
> =====
> Cheers,
>
> Fan
>
======================================================================
Andreas Steffen e-mail: andreas.steffen_at_zhwin.ch
Zuercher Hochschule Winterthur home: http://www.zhwin.ch/~sna/
CH-8401 Winterthur (Switzerland) phone: +41 76 340 25 56
===============================================================[ZHW]==
_______________________________________________
Users mailing list
Users_at_lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users
This archive was generated by hypermail 2.1.3 : Mon Jul 29 2002 - 05:19:51 CEST