Sponsored Content
Full Discussion: Openswan with Cisco ASA
Special Forums IP Networking Openswan with Cisco ASA Post 302924142 by ivancd on Thursday 6th of November 2014 01:12:35 PM
Old 11-06-2014
Openswan with Cisco ASA

Hi all,
I need this as soon as possible to solve it or at least to find out what is the problem.

I have configured IPSec tunnels with Openswan and Cisco ASA, i have established a connection and the ping was fine, but after some time there is request time out from both sites. I don't have ASA access but its default IPSec configuration,this is the openswan conf parameters.

Code:
#Define your IKE policy
            authby=secret
            keyingtries=0
            pfs=no
            ike=3des-sha1;modp1024
            ikelifetime="28800"
    
            dpddelay=0
            dpdtimeout=0
            dpdaction=clear
    
    #Define IPSec Policy
    
            phase2=esp
            phase2alg=3des-sha1
            ikev2=no
            keyexchange=ike
            rekey=no
            forceencaps=no
            keylife="28800"

I have found this in the "/var/log/seccure" logs
Code:
    received Delete SA(0x937bbc29) payload: deleting IPSEC State #5
    received and ignored informational message
    received Delete SA(0x55f62168) payload: deleting IPSEC State #8
    received and ignored informational message



Also i like to put some more logging/debuging so i can have more info but can't find any good example or doc. on how to.

And i have the following doc. on Phase 1 and 2

Code:
Encryption Algorithm     3DES
    Hash Algorithm           SHA1
    Authentication method    Preshare
    Diffie Hellman Group     Group 2
    Lifetime (Key)           28800
    Use NAT traversal        No
    Use PFS                  No
    Encapsulation            ESP
    Encryption Algorithm     3DES
    Hash Algorithm           SHA1
    Lifetime (Key)           28800


Any solution or hints or some parameters that I'm missing ?
Moderator's Comments:
Mod Comment Please use code tags next time for your code and data, not QUOTE Thanks
 

4 More Discussions You Might Find Interesting

1. IP Networking

How to establish site to site vpn - Linux machine and cisco asa?

Hi, I am trying to establish vpn between my linux server and cisco asa at client side. I installed openswan on my cent os. Linux Server eth0 - 182.2.29.10 Gateway - 182.2.29.1 eth1 - 192.9.200.75 I have simple IPtables Like WAN="eth0" LAN="eth1" (0 Replies)
Discussion started by: ashokvpp
0 Replies

2. IP Networking

How to stack Cisco 2960-S and Cisco 2960X?

Is there an easy way to stack Cisco 2960-S and Cisco 2960X switches? If you have no idea, follow this: 1. Stacking is not supported on switches running the LAN Lite image. All switches in the stack must be running the LAN Base image. 2. In a mixed stack of Catalyst 2960-X and Catalyst 2960-S... (0 Replies)
Discussion started by: Ayaerlee
0 Replies

3. IP Networking

VPN IPSec Openswan

Hi all, I have installed Openswan and configured IPSec and works perfect, but for some unknown reasons it stop working. I see that the tunnels are up and established. The route to the destination are added. Everything by the book seems to be ok. But somehow when i start to ping the other side (... (4 Replies)
Discussion started by: ivancd
4 Replies

4. IP Networking

Cisco 3750 Switch ASA VPN Routing

Hi,I want connect my ASA 5510 firewall to a 3750 switch with RIP routing. Unfortunately,I am having issues passing the VPN subnet through rip to the 3750.I don't understand how the routing table is populated on the ASA. Any suggestions? (0 Replies)
Discussion started by: Ayaerlee
0 Replies
ipsec_config_delete(1M) 												   ipsec_config_delete(1M)

NAME
ipsec_config_delete - delete configuration records from the HP-UX IPSec configuration database and delete certificate files SYNOPSIS
object_name ip_addr object_name object_name object_name object_name DESCRIPTION
The command deletes configuration records from the configuration database and certificate data. If HP-UX IPSec is active and running, the data (IPsec policy, authentication record or bypass list entry) is also deleted from the runtime policy database. If you delete IPsec policies that have active Security Associations (SAs), HP-UX IPSec removes the SAs from the Security Association Database (SADB) and sends a delete notification to the remote system. If HP-UX IPSec removes an IKE policy, the associated IPSec SAs can remain active, but no IKE control messages can be sent. The command deletes the certificate for the local system and the related private key file from the directory. It does not delete certifi- cates for CAs or Certificate Revocation Lists (CRLs). To delete these objects, you must manually delete the files in the directory. You can use the command to display the file names with the subject names for the CA certificate files and the issuer names for the CRL files. You cannot delete the configuration object. Options and Operands The command recognizes the following options and operands: object_name Specifies the name of the object you are deleting. Do not use this argument when deleting a configuration object. You cannot delete the host, IKEv1, or IKEv2 policies. ip_addr Specifies the IP address of the entry in the bypass list you are deleting. EXAMPLES
The following command deletes the host IPsec policy named AUTHOR
was developed by HP. FILES
configuration database. default profile file. SEE ALSO
ipsec_admin(1M), ipsec_config(1M), ipsec_config_add(1M), ipsec_config_batch(1M), ipsec_config_export(1M), ipsec_config_show(1M), ipsec_migrate(1M), ipsec_policy(1M), ipsec_report(1M). HP-UX IPSec Software Required ipsec_config_delete(1M)
All times are GMT -4. The time now is 02:37 AM.
Unix & Linux Forums Content Copyright 1993-2022. All Rights Reserved.
Privacy Policy