[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

(racoon 773) Re: Interoparability with FW-1 broken, patch included





YAMASHITA Yutaka wrote:
On Wed, 08 Sep 2004 11:51:02 +0200
Steffen Neumann <sneumann@ipk-gatersleben.de> wrote:


System is a Debian Laptop, Kernel 2.6.8, with racoon 0.3.3. Remote is a
CheckPoint FW-1, R55. The FW-1 seems to be sending a CRL within the
ISAKMP handshake, which confused racoon. I hacked oakley.c to ignore
that error, and the connection opens again.

I hope this will help to diagnose the problem
and create a proper fix in some future version,


the original kame racoon code is same as your hacked code long before.
i'm sorry that i don't know why ipsec-tools code is different.


As far as I see it, attached patch is reversed. Both kame and ipsec-tools versions are identical at that point.