Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 15 Jul 2002 15:28:08 -0700
From:      Nicholas Esborn <nick@netdot.net>
To:        freebsd-security@freebsd.org
Subject:   Racoon problems with 4.6-STABLE
Message-ID:  <20020715222808.GE14733@netdot.net>

next in thread | raw e-mail | index | archive | help
Hello,

I'm having problems with racoon since upgrading from 4.5-S to 4.6-S.

I had to kill routed, it was causing the routing table to be updated many
times per second and flooding my racoon logs.  This behavior seems to be
new after the upgrade.

A worse problem, however, is that racoon doesn't seem to add all the SAD
entries it negotiates to the kernel.  The result is messages like:

Jul 15 15:22:23 port /kernel: IPv4 AH input: no key association found for spi 207489362
Jul 15 15:22:35 port /kernel: IPv4 AH input: no key association found for spi 129435238
Jul 15 15:22:36 port /kernel: IPv4 AH input: no key association found for spi 129435238

These associations should have been added by racoon.

Is anyone willing to lend a hand?  I could use some suggestions as to where
to look/what data to capture to find the problem.

Thanks!

-nick

-- 
Nicholas Esborn
Unix Systems Administrator
nick@netdot.net

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20020715222808.GE14733>