Project

General

Profile

Actions

Bug #1116

closed

IPsec error, racoon won't start with more than one phase 2

Added by David Szpunar almost 14 years ago. Updated almost 14 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
-
Category:
IPsec
Target version:
Start date:
12/18/2010
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
2.0
Affected Architecture:

Description

Mobile IPsec connection with more than one Phase 2 connections create an invalid /var/etc/racoon.conf file that prevents the racoon service from starting. May apply to other Phase 1's other than Mobile, but I didn't test. Dec. 18th (current) builds for i386 (not confirmed on other architectures) and past few days to a week or so (unsure exactly when it started, could be a bit longer) have the problem at least. Logs, racoon.conf, and <ipsec> tag from config.xml examples from machine with error are all at http://forum.pfsense.org/index.php/topic,31255.0.html.

Confirmed that deleting all but one Phase 2 tunnel allows racoon to start and VPN works normally. However the multiple-phase-2 version of the config was working fine in the past; upgrading to a newer snapshot broke it, without any additional configuration changes (to the IPsec area) being made.

Actions

Also available in: Atom PDF