cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
539
Views
0
Helpful
1
Replies

IPsec in transport mode

markfen
Level 1
Level 1

I'm trying to setup IPsec in transport mode between a Solaris host and a PIX 515E for remote administration purposes. I have enabled telnet on the outside interface of my PIX, the documentation states that this requires IPsec protection.

The IPsec configuration is between the IP address of the Solaris system and the external IP address of the PIX, I'm using IKE.

I believe I have a configuration that fundimentally works, the debug traces on the PIX and the Solaris system show valid phase 1 SA's and phase 2 SA's, both systems appear to have valid SPI's.

But telnet does not work, I get this error:

IPSEC(ah_espd): Discard non-L2TP transport mode pkt from xxx.xxx.xxx.xxx

What did I miss ?

Thanks!

1 Reply 1

aghaznavi
Level 5
Level 5

The error message seems to be caused by non L2TP packet because IPSec SAs are established on IP address based (not L2TP, UDP=1701).

This error message does not cause any effect on communication.