[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

(racoon 941) Re: Repeated error message on VPN server's log



On Fri, May 06, 2005 at 12:17:34AM -0400, Christopher Rued wrote:
> Hi all,
> 
> I'm using FreeBSD 4.11 with the latest racoon port (racoon-20040818a_1) 
> and the VPN device
> I connect to (a NetScreen firewall/VPN) sends a bunch of error messages 
> to my sys admin that look
> like this:
> 
> [00001] 2005-04-15 13:47:09 [Root]system-alert-00026: IPSec tunnel on int
> ethernet3 with tunnel ID 0x80aa received a packet with a bad SPI.
> xxx.xxx.xxx.xxx->xxx.xxx.xxx.xxx/120, ESP, SPI 0xc752f16d, SEQ 0xc
> 
> Any idea what might be causing these messages?

Looks like your FreeBSD device uses an SA with a SPI which is not
known by your netscreen.


Now, the new question is "how can this happen", and we can't answer
that question without more informations on your configuration.


Yvan.