Re: SSHSentinel with dhcprelay (Was Re: [Users] dhcprelay version 0.3 released)

From: John A. Sullivan III (john.sullivan_at_nexusmgmt.com)
Date: Tue Aug 20 2002 - 12:30:33 CEST


Thanks but why does it say that the connection record mandrake test
expired it rather than the dhcp tunnel connection record? I know that
when I set my dhcp tunnel lilfe too short, I did see a message about the
SA expiring. Thanks - John

Mario Strasser wrote:

>Hi,
>
>On Tuesday 20 August 2002 11:46, John A. Sullivan III wrote:
>
>
>>[skip]
>>Could someone please explain the log entry that reads, "
>>"mandraketest-vmware"[1] 192.168.7.22 #1: deleting connection "dhcp"
>>instance with peer 192.168.7.22 "? Thanks - John
>>
>>
>The problem was that the dhcp tunnel was too short-lived and thus
>was deleted by FreeS/WAN before the dhcp negotiation could be finished.
>(Log entry: Aug 19 15:13:59 mandraketest pluto[6528]:
>"dhcp"[2] 192.168.7.22 #2: IPsec SA expired (--dontrekey))
>If this happens, increasing the the key lifetime to about 40 to 50 seconds
>may help.
>
>Regards
>Mario
>
>
>Content Security by MailMarshal
>
>

-- 
John A. Sullivan III
Group Technology Director
Nexus Management
+1 207-985-7880
john.sullivan_at_nexusmgmt.com

_______________________________________________ Users mailing list Users_at_lists.freeswan.org http://lists.freeswan.org/mailman/listinfo/users



This archive was generated by hypermail 2.1.4 : Wed Aug 21 2002 - 13:20:07 CEST