On Wed, 08 Sep 2004 11:51:02 +0200 Steffen Neumann <sneumann@ipk-gatersleben.de> wrote:
System is a Debian Laptop, Kernel 2.6.8, with racoon 0.3.3. Remote is a CheckPoint FW-1, R55. The FW-1 seems to be sending a CRL within the ISAKMP handshake, which confused racoon. I hacked oakley.c to ignore that error, and the connection opens again.
I hope this will help to diagnose the problem and create a proper fix in some future version,
the original kame racoon code is same as your hacked code long before. i'm sorry that i don't know why ipsec-tools code is different.