Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Astaro Gateway Products > VPN: Site to Site and Remote Access

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 06-08-2009, 11:25 PM
Moderator
 
Join Date: Jul 2001
Location: southern California
Posts: 5,133
Default [BUG 7.40x] IPSec Site-to-Site VPNs don't reconnect on reboot

Continuing the thread here, previously at
http://www.astaro.org/astaro-gateway...release-2.html
and
http://www.astaro.org/closed-forums-...ostarting.html
and with support: Ticket #2009042810000389 / CaseID 00096160

Quote:
BarryG,

thanks for the logfiles and sorry for the delay. The problem you're referring to is not connected to the fix we already shipped in 7.402 and not connected to any patch included in 7.403, though. I'll need to do some guessing what could cause your problem and what could help here:

If IpsecN interface is reported as missing, there is usually a part of the configuration missing. If a part of the configuration is missing, usually one (or more) of the parameters are not present. This could i.e. mean you use a DNS definition in your IPsec connection and at the point of starting IPsec the DNS name is not resolved yet. As an alternative, the (dynamic?) interface might not be up and running at that point. Usually this should 'fix itself' once the missing part is resolved or up - but in your case this seems not to happen.

Finding the problem:
- Please make a copy of the file /var/chroot-ipsec/etc/ipsec.conf when the system is up and running.

In case this happens again, please try the following:
- check /var/chroot-ipsec/etc/ipsec.conf against the version which was ok
- check in WebAdmin if some definitions used there (e.g. interfaces, DNS hosts, ..) are unresolved
- check if pluto is running or currently being restarted i.e. by selfmon
- check if a confd restart on the shell solves your problem

I apologize for obviously not matching your problem with our fix in 7.402/7.403 and look forward to resolving that one as soon as possible.

Regards,
Marcel

I'll reboot in a few minutes and compare the files.

My remote connections are to static IP definitions, however.
The only thing that is dynamic is my internet connection at home (DHCP Fiber), but my IP doesn't change frequently, even across quick reboots.

Thanks,
Barry
__________________
http://DealBert.net
Home & business end-user since v1.x
  • ASL 6.3x, HP DL145 Dual Opteron, 1GB RAM, 6 gigE NICs, 50-IP Platinum License
  • ASL 7.3x, Dell PE1550 Dual PIII 1GHz, 1GB RAM, 2 NICs, 50-IP Platinum License
  • ASL 7.5x, 17-watt fanless mini-ITX system: MSI IM-945GSE-A Atom n270, 2GB RAM, Morex T3310 case. 2 Intel GigE, 3 VLANs. 80G 5200rpm 2.5" HD
    Netgear GS108T gigE VLAN switch & Linksys WRT54G WAP
    Total network infrastructure: 27 watts. 100-IP Home User. FiOS 10mb/2mb

Last edited by BarryG; 06-08-2009 at 11:31 PM.
Reply With Quote
  #2 (permalink)  
Old 06-08-2009, 11:38 PM
Moderator
 
Join Date: Jul 2001
Location: southern California
Posts: 5,133
Default

Also should mention that my home firewall is set to initiate, and the remote is respond only.

Just rebooted home... VPN is down...
diff'ing the old ipsec.conf vs the new one shows no difference and they both have the same md5sum

as mentioned, not using any dynamic definitions for the connection, other than the DHCP external interface, which is UP

Code:
# ps auxw |grep pluto
root      3559  0.0  0.3   4464  1692 ?        Ss   15:29   0:00 /usr/libexec/ipsec/pluto --nofork --debug-none --nocrsend --nat_traversal --keep_alive 60
root      3567  0.0  0.0   1460   300 ?        S    15:29   0:00 _pluto_adns
/etc/init.d/confdaemon restart
killed my internet connection for a minute, but the VPNs are still down.

Thanks,
Barry
__________________
http://DealBert.net
Home & business end-user since v1.x
  • ASL 6.3x, HP DL145 Dual Opteron, 1GB RAM, 6 gigE NICs, 50-IP Platinum License
  • ASL 7.3x, Dell PE1550 Dual PIII 1GHz, 1GB RAM, 2 NICs, 50-IP Platinum License
  • ASL 7.5x, 17-watt fanless mini-ITX system: MSI IM-945GSE-A Atom n270, 2GB RAM, Morex T3310 case. 2 Intel GigE, 3 VLANs. 80G 5200rpm 2.5" HD
    Netgear GS108T gigE VLAN switch & Linksys WRT54G WAP
    Total network infrastructure: 27 watts. 100-IP Home User. FiOS 10mb/2mb
Reply With Quote
  #3 (permalink)  
Old 06-22-2009, 08:23 AM
Marcel's Avatar
Administrator
 
Join Date: Dec 2001
Location: Karlsruhe, Germany
Posts: 601
Question

BarryG,

after reading the whole thread again, I must admit that it seems I was wrong with my initial diagnosis. 'IpsecN interface missing' is not a message which shows up in case one parameter is missing/unresolved. (in that case middleware would simply skip that connection when writing the ipsec.conf)

After rebooting your machine your Internet connection is (usually) directly up and running, correct? Can you check if the underlying eth interface is completetly up when the IPsecN message appears?

Regards,
Marcel
__________________
Marcel Gehrlein
Astaro AG
Reply With Quote
  #4 (permalink)  
Old 06-26-2009, 12:46 PM
Marcel's Avatar
Administrator
 
Join Date: Dec 2001
Location: Karlsruhe, Germany
Posts: 601
Default

BarryG,

as I understand you're using DHCP/Cable modem for Internet access you can also upgrade your system to (soft-released) 7.404 and check results again.

Best regards,
Marcel
__________________
Marcel Gehrlein
Astaro AG
Reply With Quote
  #5 (permalink)  
Old 06-26-2009, 03:34 PM
Wizard
 
Join Date: Oct 2005
Posts: 2,424
Default

Yes, try 7.404 ... that appears to address the issue.
__________________
Convergent Information Security Solutions, LLC
Astaro Preferred Solution Partner
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 03:57 AM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.