Howdy,

        I'm trying to get two different subnets (behind two different IP
Masq'ing LRP boxes) to talk over IPSec.  I am using a Sentinel 1.3
client on one side {"right" machine}, and am using it's diagnostics to
try to make the connection on the IPSec gateway {"left"}.  I have turned
off my packet filter on the "right" machine, and am using

ipchains -I input -j ACCEPT -p udp -s [right/32] -d [left/32] 500

on the IPSec GW machine ("left").  I am getting the following error in
auth.log on "left":

[DATE] Pluto[1840]:  packet from from [remote gw]:64484: initial Main
Mode message recieved on [IPSec gw]:500 but no connection has been
authorized

After googling, I have found that Pluto insists on matching up the
source & dest port #, which the IPMasq'ing is mangling on the "right"
machine.  Any ideas?

Thanks,
Jon

_______________________________________________
Leaf-user mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user

Reply via email to