Re: [j-nsp] Host-to-Host IPSec, Openswan to Junos

2010-11-18 Thread Ben Dale
If you're only running GRE over IPSEC, try changing the local and remote proxy-ids to /32s (the GRE endpoints) and leave it at that. On 19/11/2010, at 5:48 AM, Mike Williams wrote: > Hey guys, > > Is anyone doing, or know how to do, IPSec tunnels between Openswan and Junos? > Openswan 2.4 on ke

[j-nsp] Host-to-Host IPSec, Openswan to Junos

2010-11-18 Thread Mike Williams
Hey guys, Is anyone doing, or know how to do, IPSec tunnels between Openswan and Junos? Openswan 2.4 on kernel 2.6 to Junos 10.2R3.10 on a J-series to be precise. So far I've got phase 1 to complete, but phase 2 fails like this: KMD_PM_P2_POLICY_LOOKUP_FAILURE: Policy lookup for Phase-2 [respond