J ai installe Super Freeswan 2.04 avec suport du protocole X509.
L installation se passe sans problemes et avec un fichier ipsec.conf vide tout semble OK qd je fais un verify:
Code :
- Checking your system to see if IPsec got installed and started correctly:
- Version check and ipsec on-path [OK]
- Linux FreeS/WAN 2.04
- Checking for KLIPS support in kernel [OK]
- Checking for RSA private key (/etc/ipsec.secrets) [OK]
- Checking that pluto is running [OK]
- Checking IPchains port 500 hole (10.186.96.233 on eth0) [OK]
- Checking IPchains port 500 hole (10.186.96.233 on eth1) [OK]
- Two or more interfaces found, checking IP forwarding [OK]
- Checking NAT and MASQUERADEing [N/A]
- Opportunistic Encryption DNS checks:
- Looking for TXT in forward map: vpn3 [MISSING]
- Does the machine have at least one non-private address? [FAILED]
|
Par contre des que je configure ipsec.conf:
Code :
- version 2.0 # conforms to second version of ipsec.conf specification
- # basic configuration
- config setup
- # Debug-logging controls: "none" for (almost) none, "all" for lots.
- # klipsdebug=all
- # plutodebug=dns
- interfaces=%defaultroute
- uniqueids=yes
- plutodebug=all
- plutowait=no
- plutoload=%search
- plutostart=%search
- syslog=syslog.info
- conn %default
- keyingtries=1
- compress=yes
- authby=rsasig
- # Add connections here.
- conn road_linux_gw
- left=%defaultroute
- leftsubnet=10.186.96.0/24
- leftcert=vpn03.eukorail.co.kr.pem
- leftrsasigkay=%cert
- right=%any
- rightnexthop=%defaultroute
- rightrsasigkey=%cert
- pfs=yes
- auto=add
- conn road_001
- left=%defaultroute
- leftsubnet=10.186.96.0/24
- leftcert=vpn03.eukorail.co.kr.pem
- leftrsasigkey=%cert
- right=%any
- rightrsasigkey=%cert
- rightsubnet=192.168.1.0/24
- pfs=yes
- auto=add
|
J ai le message
Code :
- ipsec_setup: 9etc/ipsec.conf, line 32) unknow parameter name "plutoload" -- 'restart' aborted
|
Alors que des que je commente la ligne plutoload, pluto demarre sans probleme.
Vous avez deja eu ce genre de pb?
PS: Je tourne sur une Red Hat 7.2 Kernel 2.4.7-10
Message édité par renaud-twingo le 22-03-2004 à 06:31:58