On Wed, 2011-06-29 at 21:55 +0200, Laurent CARON wrote:
> On Wed, Jun 29, 2011 at 12:34:02PM -0700, Tom Eastep wrote:
> > It very much looks like you are using different OpenSwan configurations
> > as well as different Shorewall configurations. Are you restarting
> > OpenSWan as well as Shorewall?
> 
> Yep,
> 

> 
> > I know of at least one Shorewall user who uses OpenSwan extensively with
> > multiple default routes; he has reported no issues such as yours.
> 
> Tom, I'm sorry to insist but I did the following which leads to make me
> think shorewall is doing domething (most probably because of my
> config?).
> 
> Having a single default route:
> Shorewall stopped or started openswan works fine
> 
> Having a multiple default route (set up by shorewall)
> Shorewall stopped, the tunnel connection is fine
> Shorewall started, i can't reach the remote end

Well, Shorewall, by itself, is not causing the IPSEC configuration to
change totally. Please try switching Shorewall configurations *without*
restarting OpenSwan.

-Tom
-- 
Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,         \ died peacefully in his sleep. Not screaming like
Washington, USA     \ all of the passengers in his car
http://shorewall.net \________________________________________________

Attachment: signature.asc
Description: This is a digitally signed message part

------------------------------------------------------------------------------
All of the data generated in your IT infrastructure is seriously valuable.
Why? It contains a definitive record of application performance, security 
threats, fraudulent activity, and more. Splunk takes this data and makes 
sense of it. IT sense. And common sense.
http://p.sf.net/sfu/splunk-d2d-c2
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to