[strongSwan] [NET] waiting for data on sockets And nothing more

Дмитрий К. dkspace at mail.ru
Fri Apr 25 14:59:41 CEST 2014


 Good day.

i have The problem with strongswan version strongSwan U5.1.3/K3.13.10-200.fc20.i686+PAE
and fedora 20 Linux SeGW.Lab 3.13.10-200.fc20.i686+PAE #1 SMP Mon Apr 14 20:47:16 UTC 2014 i686 i686 i386 GNU/Linux
start is ok
[root at SeGW ~]# strongswan restart
Stopping strongSwan IPsec...
Starting strongSwan 5.1.3 IPsec [starter]...
!! Your strongswan.conf contains manual plugin load options for charon.
!! This is recommended for experts only, see
!! http://wiki.strongswan.org/projects/strongswan/wiki/PluginLoad
tail -f /var/log/charon.log
[NET] waiting for data on sockets
.....
Apr 25 16:53:02 03[CFG] mediated_by=(null)
Apr 25 16:53:02 03[CFG] me_peerid=(null)
Apr 25 16:53:02 03[CFG] keyexchange=ikev2
Apr 25 16:53:02 03[CFG] adding virtual IP address pool 11.21.0.56/32
Apr 25 16:53:02 03[CFG] added configuration 'rw'
Apr 25 16:53:02 15[JOB] started worker thread 15
Apr 25 16:53:02 14[JOB] started worker thread 14
Apr 25 16:53:02 04[JOB] watcher got notification, rebuilding
Apr 25 16:53:02 13[LIB] created thread 13 [1457]
Apr 25 16:53:02 04[JOB] watching 9 for reading
Apr 25 16:53:02 13[JOB] started worker thread 13
Apr 25 16:53:02 04[JOB] watching 15 for reading
Apr 25 16:53:02 04[JOB] watching 16 for reading
Apr 25 16:53:02 04[JOB] watcher going to select()
and nothing more happens

but there is incoming init message but without any log message about it in tail -f /var/log/charon.log  and w/o responce 
16:39:14.817931 IP 44.44.44.13.isakmp > 44.44.44.14.isakmp: isakmp: parent_sa ik ev2_init[I]
16:39:15.821943 IP 44.44.44.13.isakmp > 44.44.44.14.isakmp: isakmp: parent_sa ik ev2_init[I]
16:39:17.822117 IP 44.44.44.13.isakmp > 44.44.44.14.isakmp: isakmp: parent_sa ik ev2_init[I]
16:39:21.826051 IP 44.44.44.13.isakmp > 44.44.44.14.isakmp: isakmp: parent_sa ik ev2_init[I]
16:39:27.826263 IP 44.44.44.13.isakmp > 44.44.44.14.isakmp: isakmp: parent_sa ik ev2_init[I]
iptables disabled and selinux disabled also.
how to check or 

-- 
Dmitriy K
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.strongswan.org/pipermail/users/attachments/20140425/b92c84a6/attachment.html>


More information about the Users mailing list