[Avila] IPsec with racoon on Avila

Daniel Gregorek danielgregorek at adtelecom.es
Wed Jul 16 12:33:47 EDT 2008


Hi Avila users,

i want to ask if anybody can announce some experience using the
'racoon' tool with BSP 0.7.1 on the Avila board. I want to setup an esp
protected tunnel between two nodes. The policies, which connections
should be encapsulated have been defined via 'setkey'.

When a package arrives that should go through the tunnel, it is
possible to see that racoon does some modification to the security
association database:

[root at avila ipsec]# setkey -D
172.16.0.2 172.16.0.1 
	esp mode=tunnel spi=0(0x00000000) reqid=0(0x00000000)
	seq=0x00000000 replay=0 flags=0x00000000 state=larval 
	created: Jul 16 17:28:31 2008	current: Jul 16 17:28:37
	2008 diff: 6(s)	hard: 30(s)	soft: 0(s)
	last:                     	hard: 0(s)	soft: 0(s)
	current: 0(bytes)	hard: 0(bytes)	soft: 0(bytes)
	allocated: 0	hard: 0	soft: 0
	sadb_seq=0 pid=3738 refcnt=0

But afterwards there happens nothing and this modification seems rather
uncomplete to me. I was expecting some isakmp messages on the network,
but there are none. Also port 500 is closed. Maybe someone knows how to
use racoon on this platform?

Regards,
Daniel

PS: racoon.conf is attached

-- 
AD Telecom, S.L.
c/ Cami de la Pelleria 12, Pol. Ind. Bonavista
08915 Badalona, (Barcelona) Spain
www.adtelecom.es
-------------- next part --------------
A non-text attachment was scrubbed...
Name: racoon.conf
Type: application/octet-stream
Size: 531 bytes
Desc: not available
Url : http://lists.gateworks.com/pipermail/avila/attachments/20080716/78e70e83/attachment.obj 


More information about the Avila mailing list