openswan connection terminated after some time without packet transport

Bug #759097 reported by Thomas Schweikle
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
openswan (Ubuntu)
New
Undecided
Unassigned

Bug Description

Binary package hint: openswan

1. Install openswan
2. Configure openswan use only IPv4. Be sure to have one box *behind* a DSL router with IP-Adress change after a certain amount of time.
3. Configure your openswan server with a fixed IPv4 address in the internet.
4. Start openswan first on the server, second on the client.
5. Try to ping the server from the client. OK? If yes, config is OK.
6. Try to ping the client from the server. OK? If yes, config is OK.
7. halt both pings, leave openswan running on both boxes, but *do not have anything running trying to transfer packets*
8. Come back after at least an hour.
9. Try again to ping the server from the client. Doesn't work? Fine!
10. Try again to ping the client from the server: Doesn't work? Fine!
11. restart the openswan daemon on the server.
12. restart the openswan saemon on the client.
13. ping the server from the client. OK? Fine.
14. ping the client from the server. OK? Fine.
15. halt both pings. Wait again for at least an hour. Try again to ping. Not working?

OK. You've got it.
Openswan does not reconnect the tunnel after a longer period without any transmission. The tunnel stays down until both openswan is restarted on both sides.

Seen with:
Ubuntu 10.04.2 LTS
Ubuntu 10.10
Ubuntu 11.04b1

ProblemType: Bug
DistroRelease: Ubuntu 11.04
Package: openswan 1:2.6.28+dfsg-5
ProcVersionSignature: Ubuntu 2.6.38-8.42-virtual 2.6.38.2
Uname: Linux 2.6.38-8-virtual x86_64
Architecture: amd64
Date: Tue Apr 12 21:11:28 2011
InstallationMedia: Ubuntu-Server 10.04.1 LTS "Lucid Lynx" - Release amd64 (20100816.2)
ProcEnviron:
 PATH=(custom, user)
 LANG=en_US.UTF-8
 SHELL=/bin/bash
SourcePackage: openswan
UpgradeStatus: Upgraded to natty on 2011-04-08 (4 days ago)

Revision history for this message
Thomas Schweikle (tps) wrote :
Revision history for this message
Harald Jenny (harald-a-little-linux-box) wrote :

Dear bug reporter,

could you provide further information, for example the obfuscated openswan config file?

Kind regards
Harald Jenny

Revision history for this message
Thomas Schweikle (tps) wrote :

I have managed to make the whole stuff work after upgrading to Ubuntu 11.10

Revision history for this message
Harald Jenny (harald-a-little-linux-box) wrote :

Hello,

may I ask which steps you did take as this could maybe help others? Thanks for your help!

Kind regards
Harald Jenny

Revision history for this message
Simon Déziel (sdeziel) wrote :

The bug description seems to point to a NAT state expiration problem. If anyone is affected by this I'd recommend enabling DPD on their IPsec connections as this will keep the NAT states from expiring. DPD works by sending "R_U_THERE" packets at regular intervals and those keep the connection alive. DPD could also restart the connection after it failed.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.