Chinaunix
标题:
openswan启动后直接关闭网络接口
[打印本页]
作者:
zenglingping
时间:
2009-12-11 11:44
标题:
openswan启动后直接关闭网络接口
在测试环境中,当我设置好配置文件后,启动ipsec(openswan),所有网络接口自动被shutdown,不知为何?
有人说是OE,但我没有启用OE。
Dec 10 11:49:11 chgw pluto[4768]: "clear#202.12.27.33/32" 0.0.0.0: deleting connection "clear#202.12.27.33/32" instance with peer 0.0.0.0 {isakmp=#0/ipsec=#0}
Dec 10 11:49:11 chgw pluto[4768]: "clear#198.41.0.4/32" 0.0.0.0: deleting connection "clear#198.41.0.4/32" instance with peer 0.0.0.0 {isakmp=#0/ipsec=#0}
Dec 10 11:49:11 chgw pluto[4768]: "clear#198.32.64.12/32" 0.0.0.0: deleting connection "clear#198.32.64.12/32" instance with peer 0.0.0.0 {isakmp=#0/ipsec=#0}
Dec 10 11:49:11 chgw pluto[4768]: "clear#193.0.14.129/32" 0.0.0.0: deleting connection "clear#193.0.14.129/32" instance with peer 0.0.0.0 {isakmp=#0/ipsec=#0}
Dec 10 11:49:11 chgw pluto[4768]: "clear#192.228.79.201/32" 0.0.0.0: deleting connection "clear#192.228.79.201/32" instance with peer 0.0.0.0 {isakmp=#0/ipsec=#0}
Dec 10 11:49:11 chgw pluto[4768]: "clear#192.203.230.10/32" 0.0.0.0: deleting connection "clear#192.203.230.10/32" instance with peer 0.0.0.0 {isakmp=#0/ipsec=#0}
Dec 10 11:49:11 chgw pluto[4768]: "clear#192.112.36.4/32" 0.0.0.0: deleting connection "clear#192.112.36.4/32" instance with peer 0.0.0.0 {isakmp=#0/ipsec=#0}
Dec 10 11:49:11 chgw pluto[4768]: "clear#192.58.128.30/32" 0.0.0.0: deleting connection "clear#192.58.128.30/32" instance with peer 0.0.0.0 {isakmp=#0/ipsec=#0}
Dec 10 11:49:11 chgw pluto[4768]: "clear#192.36.148.17/32" 0.0.0.0: deleting connection "clear#192.36.148.17/32" instance with peer 0.0.0.0 {isakmp=#0/ipsec=#0}
Dec 10 11:49:11 chgw pluto[4768]: "clear#192.33.4.12/32" 0.0.0.0: deleting connection "clear#192.33.4.12/32" instance with peer 0.0.0.0 {isakmp=#0/ipsec=#0}
Dec 10 11:49:11 chgw pluto[4768]: "clear#192.5.5.241/32" 0.0.0.0: deleting connection "clear#192.5.5.241/32" instance with peer 0.0.0.0 {isakmp=#0/ipsec=#0}
Dec 10 11:49:11 chgw pluto[4768]: "clear#128.63.2.53/32" 0.0.0.0: deleting connection "clear#128.63.2.53/32" instance with peer 0.0.0.0 {isakmp=#0/ipsec=#0}
Dec 10 11:49:11 chgw pluto[4768]: "clear#128.8.10.90/32" 0.0.0.0: deleting connection "clear#128.8.10.90/32" instance with peer 0.0.0.0 {isakmp=#0/ipsec=#0}
Dec 10 11:49:11 chgw pluto[4768]: "clear": deleting connection
Dec 10 11:49:11 chgw pluto[4768]: "clear-or-private": deleting connection
Dec 10 11:49:11 chgw pluto[4768]: "block": deleting connection
Dec 10 11:49:11 chgw pluto[4768]: "packetdefault": deleting connection
Dec 10 11:49:11 chgw pluto[4768]: shutting down interface lo/lo ::1:500
Dec 10 11:49:11 chgw pluto[4768]: shutting down interface lo/lo 127.0.0.1:4500
Dec 10 11:49:11 chgw pluto[4768]: shutting down interface lo/lo 127.0.0.1:500
Dec 10 11:49:11 chgw pluto[4768]: shutting down interface eth1/eth1 125.12.10.22:4500
Dec 10 11:49:11 chgw pluto[4768]: shutting down interface eth1/eth1 125.12.10.22:500
Dec 10 11:49:11 chgw pluto[4768]: shutting down interface eth0/eth0 192.168.40.254:4500
Dec 10 11:49:11 chgw pluto[4768]: shutting down interface eth0/eth0 192.168.40.254:500
Dec 10 11:49:12 chgw pluto[4768]: ADNS process terminated by signal 105
Dec 10 11:50:00 chgw sshd[5300]: Accepted password for root from 116.6.76.51 port 49919 ssh2
Dec 10 11:50:00 chgw sshd[5300]: pam_unix(sshd:session): session opened for user root by (uid=0)
复制代码
作者:
kns1024wh
时间:
2009-12-11 23:00
标题:
回复 #1 zenglingping 的帖子
不见配置文件呀
放上来分析
作者:
zenglingping
时间:
2009-12-12 10:56
标题:
回复 #2 kns1024wh 的帖子
配置文件参考如下:
# cat /etc/ipsec.conf
# /etc/ipsec.conf - Openswan IPsec configuration file
#
# Manual: ipsec.conf.5
#
# Please place your own config files in /etc/ipsec.d/ ending in .conf
version 2.0 # conforms to second version of ipsec.conf specification
# basic configuration
config setup
# Debug-logging controls: "none" for (almost) none, "all" for lots.
# klipsdebug=none
# plutodebug="control parsing"
nat_traversal=yes
include /etc/ipsec.d/*.conf
conn net-to-net
right=192.168.3.110
rightsubnet=172.16.16.0/24
rightid=@right01
# RSA 2192 bits right01 Fri Dec 11 19:17:56 2009
rightrsasigkey=0sAQOOeh9pmtAtelwLZj9FLjTZELUyUB0jI6LDV3bVeFv8j02/V271wSBK7nSJJvwvKBwaqfAwwIjMRjzR2Fhj8iAjNDF8kPSo24wWzjuM/mLNT/sXz4zLOk5cYyiyv4qpB0P//Z2tVsyZCRWv6nHMwJuetjpGpwdA5SE0gj87/t6kJVe35c8uAZYLXRX86lKx///2XUVBB+p9TnrO1noNgTEoE/bDnWg+h6cqo/8DmDXkfvk3trC+kuXp2o5/N0kAoX76biV/tRoGZ4zf9hOkxm0FPUo0Et+f5k8+ce2KyqPn6pt6rvJqn6A9qzZS5DtAvWcI9w1bjAaeh51SK1w4k0bKbBv2F+wt4Wnv9IDBUU32jT5F
rightnexthop=%defaultroute
left=192.168.3.120
leftsubnet=10.10.10.0/24
leftid=@left01
# RSA 2192 bits left01 Fri Dec 11 19:19:51 2009
leftrsasigkey=0sAQONLWrWTYoHV2Z7QyQwtMG5CqhK9h+mdgHIh1/o0MXRfTTzoZv5bS3EeZgMbCeQwX7hkMvSaJfJEZUsEAolr+ZTE9QV6xqNGX7+AgqnDDI2DCQIe1el7hl7XTgoAppSC7TOlb3D3L0oI5LCR8UkzEOqevGo0HH1oUeBePt3kINWyZlbecSP+mxy+32NnOR+T6pnKuan038xYF2T3ahvU2Cceds6zkerWMsYyP+Ye3VDIEof8+RjO5CgM4Z3JJLatnd0xo7sGY+bfsviBqB5FQq/ghfrw5QkqCWOb93bx8a1P5TRokQgQrI3igTSmNkICkmQFQtnrXkcnlUtVGPwfYiONWe/T8FclrOXtYRZhvaoFBZ7
leftnexthop=%defaultroute
auto=add
复制代码
或许是由于CentOS 版本的问题,我后来使用CentOS 5.0则没有此问题,出现以上问题的是CentOS 5.4 X86的版本。
作者:
zenglingping
时间:
2009-12-15 18:00
估计是版本的问题,结贴。
作者:
kns1024wh
时间:
2009-12-15 22:41
原帖由
zenglingping
于 2009-12-15 18:00 发表
估计是版本的问题,结贴。
多测试 就会有结果的
欢迎光临 Chinaunix (http://bbs.chinaunix.net/)
Powered by Discuz! X3.2