Project

General

Profile

Bug #430

Cannot configure IPSec SA without local id for Roadwarrior configurations

Added by Paul K over 9 years ago. Updated over 9 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
-
Category:
IPsec
Target version:
Start date:
03/15/2010
Due date:
% Done:

0%

Estimated time:
Affected Version:
2.0
Affected Architecture:

Description

Right now there is no way to leave 'Local Network' blank when configuring IPsec Phase 2. This results in the racoon.conf file that always has local_id set

sainfo local_id anonymous {...}

For Roadwarrior configurations local_id cannot be defined and so SA config should look like this

sainfo anonymous {...}

TIA

Associated revisions

Revision 63017a73 (diff)
Added by Ermal Luçi over 9 years ago

Ticket #430. Give a none option to allow for roadwarriors configs.

History

#1 Updated by Chris Buechler over 9 years ago

what version?

#2 Updated by Paul K over 9 years ago

Ah sorry, 2.0. I am running 20100304 snapshot.

#3 Updated by Chris Buechler over 9 years ago

  • Category set to IPsec
  • Target version set to 2.0
  • Affected Version set to 2.0

#4 Updated by Ermal Luçi over 9 years ago

  • Status changed from New to Feedback

Please test the committed changes.
I am not sure this is enough though try it on your side an we will see.

#5 Updated by Paul K over 9 years ago

Ermal, thanks for the quick fix.

I tested this with March 19th snap. It does produce correct SA configuration now

sainfo anonymous {...}

and road warriors can connect fine.

The only thing I noticed: if I check 'Provide a list of accessible networks to clients' flag in 'mode-cfg' section it uses configuration from phase-2 setup page -> 'Local Network' to generate config file and if I selected 'None' in the local network section racoon config file will have this entry:

split_network include 0.0.0.0/0;

I am not sure if this is a problem or not because I don't really use that option just thought I will mention it here.

#6 Updated by Chris Buechler over 9 years ago

  • Status changed from Feedback to Resolved

Also available in: Atom PDF