[Ilugc] ipsec problems

  • From: mvikyk@xxxxxxxxxxx (Vignesh)
  • Date: Thu Feb 22 02:15:01 2007

SK,

I am not using any *swan as of now.  Currently using
setkey utility and revolve around add/spdadd.

Interestingly if the rules given are for transport
mode instead of tunnel mode, the ping goes through!
:-(

Here is the output you asked for:
[root@imslab a21034]# /sbin/iptables -L -n -V
iptables v1.3.5
[root@imslab a21034]# strace ping 144.190.76.187
execve("/bin/ping", ["ping", "144.190.76.187"], [/* 45
vars */]) = 0
brk(0)                                  =
0x555555770000
mmap(NULL, 4096, PROT_READ|PROT_WRITE,
MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b8656213000
uname({sys="Linux", node="imslab.localdomain", ...}) =
0
access("/etc/ld.so.preload", R_OK)      = -1 ENOENT
(No such file or directory)
open("/etc/ld.so.cache", O_RDONLY)      = 3
fstat(3, {st_mode=S_IFREG|0644, st_size=170833, ...})
= 0
mmap(NULL, 170833, PROT_READ, MAP_PRIVATE, 3, 0) =
0x2b8656214000
close(3)                                = 0
open("/lib64/libresolv.so.2", O_RDONLY) = 3
read(3,
"\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\3603\300"...,
832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=92728, ...}) =
0
mmap(NULL, 4096, PROT_READ|PROT_WRITE,
MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b865623e000
mmap(NULL, 2181864, PROT_READ|PROT_EXEC,
MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b865623f000
mprotect(0x2b8656250000, 2097152, PROT_NONE) = 0
mmap(0x2b8656450000, 8192, PROT_READ|PROT_WRITE,
MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x11000) =
0x2b8656450000
mmap(0x2b8656452000, 6888, PROT_READ|PROT_WRITE,
MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) =
0x2b8656452000
close(3)                                = 0
open("/lib64/libc.so.6", O_RDONLY)      = 3
read(3,
"\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0@\333\341"...,
832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=1678472, ...})
= 0
mmap(NULL, 3461304, PROT_READ|PROT_EXEC,
MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x2b8656454000
mprotect(0x2b8656598000, 2097152, PROT_NONE) = 0
mmap(0x2b8656798000, 20480, PROT_READ|PROT_WRITE,
MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x144000) =
0x2b8656798000
mmap(0x2b865679d000, 16568, PROT_READ|PROT_WRITE,
MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) =
0x2b865679d000
close(3)                                = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE,
MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b86567a2000
mmap(NULL, 4096, PROT_READ|PROT_WRITE,
MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b86567a3000
arch_prctl(ARCH_SET_FS, 0x2b86567a2b00) = 0
mprotect(0x2b8656798000, 16384, PROT_READ) = 0
mprotect(0x2b8656450000, 4096, PROT_READ) = 0
mprotect(0x36fb019000, 4096, PROT_READ) = 0
munmap(0x2b8656214000, 170833)          = 0
socket(PF_INET, SOCK_RAW, IPPROTO_ICMP) = 3
getuid()                                = 0
setuid(0)                               = 0
socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = 4
connect(4, {sa_family=AF_INET, sin_port=htons(1025),
sin_addr=inet_addr("144.190.76.187")}, 16) = -1 ESRCH
(No such process)
dup(2)                                  = 5
fcntl(5, F_GETFL)                       = 0x8002
(flags O_RDWR|O_LARGEFILE)
brk(0)                                  =
0x555555770000
brk(0x555555791000)                     =
0x555555791000
fstat(5, {st_mode=S_IFCHR|0600, st_rdev=makedev(136,
3), ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE,
MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b8656214000
lseek(5, 0, SEEK_CUR)                   = -1 ESPIPE
(Illegal seek)
write(5, "connect: No such process\n", 25connect: No
such process
) = 25
close(5)                                = 0
munmap(0x2b8656214000, 4096)            = 0
exit_group(2)                           = ?
Process 7309 detached

I am running out of hair to pluck for this problem.  A
google serach on this problem doesn't help much :-(

-Vignesh



                
___________________________________________________________ 
Yahoo! Messenger - with free PC-PC calling and photo sharing. 
http://uk.messenger.yahoo.com

Other related posts: