[strongSwan] Problem using Strong Swan on high-end Freescale Board (p4080)

Varvara Andrei-B21317 B21317 at freescale.com
Mon Jul 4 16:04:10 CEST 2011


Hello

I hope you are kind to help me with a problem found when using Strong Swan 4.5.0/4.5.1

I have built the Strong Swan testing environment(the virtual machines SUN, MOON, ALICE, BOB) and successfully tested a IKEv2 transaction doing IPSec between moon and sun. The configuration used is the ikev2/net2net-psk a little bit modified but validated by the testing. I find the Strong Swan amazing and I thank you for that.

Next step was to modify the setup in order to replace MOON with a Freescale p4080 board. Did this too and tested with
ping to see if I can communicate with the SUN on 192.168.0.2 and with ALICE on 10.1.0.10 Worked as expected.

I have configured the Freescale p4080 board as I configured the MOON in the test that was successful.
The encountered problem is that when running ipsec start on board no error appears, but when I initiate the net-net connection from SUN virtual machine, the board receives isakmp but afterwards replies to SUN telling that udp port 500 is unreachable, like nobody listens on that port. Anyway a netstat -upl command on the board says that charon is listening on udp port 500 as it should.

If you have any idea why it's behaving like this please let me know. I am interested only in charon demon.
Some useful debugging is added in the attachment and I hope it will help you better understand the context.

Thank you very much and have a nice day.

Andrei VARVARA
Software Engineer
Freescale Semiconductor Romania S.R.L
45, Tudor Vladimirescu Street
Tati Business Center
Bucharest 050881, Romania
www.freescale.com<http://www.freescale.com/>
e-mail: andrei.varvara at freescale.com<mailto:andrei.varvara at freescale.com>
 ===================================================
This e-mail, and any associated attachments have been classified as:
[ ] Public
[x] Freescale Semiconductor Internal Use Only
[ ] Freescale Semiconductor Confidential Proprietary

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.strongswan.org/pipermail/users/attachments/20110704/cadc2e5c/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: debugging.docx
Type: application/vnd.openxmlformats-officedocument.wordprocessingml.document
Size: 17688 bytes
Desc: debugging.docx
URL: <http://lists.strongswan.org/pipermail/users/attachments/20110704/cadc2e5c/attachment.docx>


More information about the Users mailing list