Am Die, 2003-08-26 um 13.16 schrieb Nico Schottelius: > Are there still known problems with ipsec/2.6.0test4 ? > I am trying it with isakmpd with the following result: > > bruehe:/etc/cron.d# isakmpd -d > 131816.802082 Default check_policy: negotiated SA failed policy check > 131816.802744 Default message_negotiate_sa: no compatible proposal found > 131816.803208 Default dropped message from 213.69.232.59 port 500 due to notification type NO_PROPOSAL_CHOSEN > 131816.803910 Default responder_recv_HASH_SA_NONCE: KEY_EXCH payload without a group desc. attribute > 131816.804268 Default dropped message from 213.69.232.59 port 500 due to notification type NO_PROPOSAL_CHOSEN > 131816.804797 Default group_get: group ID (0) out of range Could you post your configuration? Did you compile the isakmpd referencing the test4 kernel? There have been some changes in the ABI and I have not tested the newest kernel using isakmpd myself, so it might not work. Cheers, Ralf -- Ralf Spenneberg RHCE, RHCX Book: Intrusion Detection für Linux Server http://www.spenneberg.com IPsec-Howto http://www.ipsec-howto.org Honeynet Project Mirror: http://honeynet.spenneberg.org - : send the line "unsubscribe linux-net" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html