OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Gregory Carvalho (GregoryC_at_stcinc.com)
Date: Wed Jan 15 2003 - 17:17:53 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    The error indicates to me that the SPI contains no valid SPD entry for
    the SADB entry.

    While all your sample numbers match, I'll change them to create the
    error (I just changed the first occurance of 192.168.9.11 to
    192.168.9.12):

    spdadd 192.168.0.0/24 0.0.0.0/0 any -P in ipsec
    esp/tunnel/192.168.9.9-192.168.9.12;

    bullet# setkey -DP
    192.168.0.0/24[any] 0.0.0.0/0[any] any
            in ipsec
            esp/tunnel/192.168.9.9-192.168.9.11/default
            spid=73 seq=1 pid=95831
            refcnt=1

    I hope this helps you find the answer.

    -GCC

    To Unsubscribe: send mail to majordomoFreeBSD.org
    with "unsubscribe freebsd-security" in the body of the message