2009-11-09 17:08:39

by Mariusz Smykula

[permalink] [raw]
Subject: Kernel 2.6.29+ broke Cisco VPN Client

Kernel 2.6.31 go mainstream and there new problem grow up for many
users of poor Cisco VPN Client with certs authentication (there is no
alternative for this). I know, this is not yours problem but maybe
someone can help us and look into cisco vpn client code. There is
problem with freezing system after some time from connection. This
problem start with 2.6.29 kernel.

More info about this:
http://forum.tuxx-home.at/viewforum.php?f=15&sid=8a427ce7fd1fd5b5c5110348e8f0041a
http://www.painfullscratch.nl/code/vpn/
http://ilapstech.blogspot.com/2009/09/cisco-vpn-client-on-karmic-koala.html#comment-form
http://projects.tuxx-home.at/ciscovpn/

Sorry for disturbing.

--
Mariusz Smyku?a
mariuszs-gmail-com


2009-11-09 17:55:37

by Alan

[permalink] [raw]
Subject: Re: Kernel 2.6.29+ broke Cisco VPN Client

On Mon, 9 Nov 2009 18:08:40 +0100
Mariusz Smykula <[email protected]> wrote:

> Kernel 2.6.31 go mainstream and there new problem grow up for many
> users of poor Cisco VPN Client with certs authentication (there is no
> alternative for this).

I must have imagined openconnect. Failing that you need to talk to your
distro if they shipped the module or to cisco.

Alan

2009-11-10 07:04:07

by Mariusz Smykula

[permalink] [raw]
Subject: Re: Kernel 2.6.29+ broke Cisco VPN Client

On Mon, Nov 9, 2009 at 6:57 PM, Alan Cox <[email protected]> wrote:
> I must have imagined openconnect. Failing that you need to talk to your
> distro if they shipped the module or to cisco.

OpenConnect supports the new Cisco "AnyConnect" SSL VPN, not the old
IPsec-based VPN. Cisco ended support for this software and devices and
is not interested in helping us. All we have is open sourced cisco vpn
client which is broken since 2.6.29.

--
Mariusz Smykuła

2009-11-10 07:48:16

by Fabio Comolli

[permalink] [raw]
Subject: Re: Kernel 2.6.29+ broke Cisco VPN Client

Please have a look at:

http://forum.tuxx-home.at/viewtopic.php?f=15&t=790#p5227

There is a patch there that can be used to make CiscoVPN work with the
latest stable kernels. For me it worked fine (over a wifi connection)
until I lost interest as now I'm able to use vpnc, thanks to the
people on the vpnc support forum.

Hope this helps.

[BTW, CiscoPVN is OT on this list]

On Tue, Nov 10, 2009 at 8:04 AM, Mariusz Smykula <[email protected]> wrote:
> On Mon, Nov 9, 2009 at 6:57 PM, Alan Cox <[email protected]> wrote:
>> I must have imagined openconnect. Failing that you need to talk to your
>> distro if they shipped the module or to cisco.
>
> OpenConnect supports the new Cisco "AnyConnect" SSL VPN, not the old
> IPsec-based VPN. Cisco ended support for this software and devices and
> is not interested in helping us. All we have is open sourced cisco vpn
> client which is broken since 2.6.29.
>
> --
> Mariusz Smykuła
> --
> To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
> the body of a message to [email protected]
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
> Please read the FAQ at  http://www.tux.org/lkml/
>

2009-11-10 09:49:45

by Mariusz Smykula

[permalink] [raw]
Subject: Re: Kernel 2.6.29+ broke Cisco VPN Client

On Tue, Nov 10, 2009 at 8:48 AM, Fabio Comolli <[email protected]> wrote:
> Please have a look at:
>
> http://forum.tuxx-home.at/viewtopic.php?f=15&t=790#p5227
>
> There is a patch there that can be used to make CiscoVPN work with the
> latest stable kernels. For me it worked fine (over a wifi connection)
> until I lost interest as now I'm able to use vpnc, thanks to the
> people on the vpnc support forum.

I have no problem to compile and connect using CiscoVPN + 2.6.31, but
this is unstable solution. After some time (seconds or minutes) whole
computer is freezing dead.

vpnc is no option, because he lacks supports of certs auth.

I think something was changed in kernel Tun-Tap layer (or something
like that) that cause CIscoVPN problem.


--
Mariusz Smykuła

2009-11-11 06:54:49

by Philipp Hahn

[permalink] [raw]
Subject: Re: Kernel 2.6.29+ broke Cisco VPN Client

Hello,

On Tue, Nov 10, 2009 at 10:49:48AM +0100, Mariusz Smykula wrote:
> On Tue, Nov 10, 2009 at 8:48 AM, Fabio Comolli <[email protected]> wrote:
> > Please have a look at:
> >
> > http://forum.tuxx-home.at/viewtopic.php?f=15&t=790#p5227
> >
> > There is a patch there that can be used to make CiscoVPN work with the
> > latest stable kernels. For me it worked fine (over a wifi connection)
> > until I lost interest as now I'm able to use vpnc, thanks to the
> > people on the vpnc support forum.
>
> I have no problem to compile and connect using CiscoVPN + 2.6.31, but
> this is unstable solution. After some time (seconds or minutes) whole
> computer is freezing dead.
>
> vpnc is no option, because he lacks supports of certs auth.

You might want to give http://www.shrew.net/software a try. I'd be
interested if this works for you.

BYtE
Philipp
--
/ / (_)__ __ ____ __ Philipp Hahn
/ /__/ / _ \/ // /\ \/ /
/____/_/_//_/\_,_/ /_/\_\ [email protected]