So I have IPSec working from redhat to redhat, and from redhat to
windows, but when I set up redhat (xx.xx) to hp (yy.yy), I get a SA
connection, but I cannot ping. Also, the log shows me "anonymous sainfo
selected" even though I have the SA defined.
A second question, re: redhat to windows (ww.ww). I'm able to get a
successful connection as long as I ping from the windows side first, but
then I lose the connection after 10 minutes of inactivity, and can only
re-establish it if I ping from the windows side. Then I'm good for
another 10 minutes or so. Does anyone know how to stop this timeout?
setkey -DP
128.181.yy.yy[any] 128.181.xx.xx[32] any
in prio def ipsec
esp/transport//require
created: Mar 1 09:09:55 2010 lastused:
lifetime: 0(s) validtime: 0(s)
spid=41304 seq=25 pid=20119
refcnt=1
128.181.yy.yy[any] 128.181.xx.xx[any] any
in prio def ipsec
esp/transport//require
ah/transport//require
created: Mar 1 09:10:06 2010 lastused: Mar 1 09:14:33 2010
lifetime: 0(s) validtime: 0(s)
spid=41328 seq=24 pid=20119
refcnt=2
128.181.xx.xx[any] 128.181.yy.yy[32] any
out prio def ipsec
esp/transport//require
created: Mar 1 09:09:55 2010 lastused:
lifetime: 0(s) validtime: 0(s)
spid=41297 seq=21 pid=20119
refcnt=1
128.181.xx.xx[any] 128.181.yy.yy[any] any
out prio def ipsec
esp/transport//require
ah/transport//require
created: Mar 1 09:10:06 2010 lastused: Mar 1 09:11:35 2010
lifetime: 0(s) validtime: 0(s)
spid=41321 seq=20 pid=20119
refcnt=2
128.181.yy.yy[any] 128.181.xx.xx[32] any
fwd prio def ipsec
esp/transport//require
created: Mar 1 09:09:55 2010 lastused:
lifetime: 0(s) validtime: 0(s)
spid=41314 seq=17 pid=20119
refcnt=1
128.181.yy.yy[any] 128.181.xx.xx[any] any
fwd prio def ipsec
esp/transport//require
ah/transport//require
created: Mar 1 09:10:06 2010 lastused:
lifetime: 0(s) validtime: 0(s)
spid=41338 seq=16 pid=20119
refcnt=1
(per-socket policy)
in none
created: Mar 1 09:10:07 2010 lastused: Mar 1 09:11:14 2010
lifetime: 0(s) validtime: 0(s)
spid=41363 seq=9 pid=20119
refcnt=1
(per-socket policy)
out none
created: Mar 1 09:10:07 2010 lastused: Mar 1 09:11:55 2010