OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
isakmpd : null source

From: xirkus (xirkusz1r0.com)
Date: Sun Feb 01 2004 - 23:03:57 CST


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

I was wondering what could cause a null source in the /kern/ipsec output:

SPI = 51bb36d6, Destination = xxx.xxx.165.70, Sproto = 50
~ Established 1072 seconds ago
~ Source = (null)
~ Flags (00001082) = <tunneling>
~ Crypto ID: 1
~ xform = <IPsec ESP>
~ Encryption = <Rijndael-128/AES>
~ Authentication = <HMAC-SHA1>
~ 0 bytes processed by this SA
~ Expirations:
~ Hard expiration(1) in 128 seconds
~ Soft expiration(1) in 8 seconds

SPI = 54374606, Destination = xxx.xxx.153.200, Sproto = 50
~ Established 1072 seconds ago
~ Source = (null)
~ Flags (00001082) = <tunneling>
~ Crypto ID: 2
~ xform = <IPsec ESP>
~ Encryption = <Rijndael-128/AES>
~ Authentication = <HMAC-SHA1>
~ 0 bytes processed by this SA
~ Expirations:
~ Hard expiration(1) in 128 seconds
~ Soft expiration(1) in 8 seconds

This just happens on only one end of the VPN tunnel on an OBSD 3.4
gateway. The output of the other gateway (OBSD 3.3) is just fine
(meaning the Source is not null and has the correct ip associated with it).

Any help in this matter would be greatly appreciated.

Mel
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)

iD8DBQFAHdo8ARB5j/LItlURApG1AJ9mmOgJCCnX5Vk5AvKn/sW6MvxSmgCglQdD
0t+G4o/skLW5KRryIX0g2aE=
=nyOo
-----END PGP SIGNATURE-----