IPv6 readyNote: This archive passes through spamassassin. Every mail marked with the subject "*****SPAM*****" has exceed a certain threshold of spam-like behaviour.

Re: [Users] vpn to lucent brick 201 goes down unpredictably

From: Sam Sgro (sam_at_freeswan.org)
Date: Thu May 30 2002 - 22:45:16 CEST


-----BEGIN PGP SIGNED MESSAGE-----

On Thu, 30 May 2002, Joe Roberts wrote:

> May 30 15:01:38 stu Pluto[21179]: "del" #26: OAKLEY_DES_CBC is not
> supported. Attribute OAKLEY_ENCRYPTION_ALGORITHM
> May 30 15:01:38 stu Pluto[21179]: "del" #26: no acceptable Oakley Transform
>
> Am I correct in thinking that my machine (stu) now sees the Lucent Brick 201
> box as only offering DES? I have the person responsible for the Lucent
> Brick device looking at the configuration and checking to see if they can
> completely turn off support for DES (at least for the connection to me).

Yes, you're on the right track - the FreeS/WAN box is receiving a request
to use single DES, which it won't support. I'd highly recommend that they
turn off support for single DES completely - if they need convincing, let
them look at doc/politics.html#desnotsecure.

Sam Sgro
sam_at_freeswan.org

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: noconv
Comment: For the matching public key, finger the Reply-To: address.

iQCVAwUBPPaPYEOSC4btEQUtAQGrVgP+IQN7ysGPDJlBTEXkxYq0lt7arqaXCPsM
JlKeJF8Cu/ct6xP2ds1MrXuAp2AFQFpWcZGGrzeYOBvo6KHdVgXoP8huxtwKnzqz
1ko/vvK1zusgLUpTQ1X29UvdCVWcL6cye1TKq16IAQ9L62jRgheDgqP7vDys2VcF
8D9MjonyVmY=
=g1tf
-----END PGP SIGNATURE-----

_______________________________________________
Users mailing list
Users_at_lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users



This archive was generated by hypermail 2.1.3 : Mon Jul 29 2002 - 05:20:08 CEST