Hello,
When I try to “connect” to containers (a load blancer and an application portal) though managed network, it doesn’t work.
On network agent logs I get this error message :
25 septembre 2015 16:54:07 UTC+2racoon - IKE keying daemon will not be started as /proc/net/pfkey is not
25 septembre 2015 16:54:07 UTC+2 available or a suitable 2.6 (or 2.4 with IPSEC backport)
25 septembre 2015 16:54:07 UTC+2 kernel with af_key.[k]o module installed.
On network agent container (rancher/agent-instance:v0.4.1) in /var/log/racoon.log I get :
2015-09-25 14:54:08: INFO: @(#)ipsec-tools 0.8.0 (http://ipsec-tools.sourceforge.net)
2015-09-25 14:54:08: INFO: @(#)This product linked OpenSSL 1.0.1f 6 Jan 2014 (http://www.openssl.org/)
2015-09-25 14:54:08: INFO: Reading configuration from "/etc/racoon/racoon.conf"
2015-09-25 14:54:56: WARNING: PF_KEY EXPIRE message received from kernel for SA being negotiated. Stopping negotiation.
2015-09-25 14:55:16: ERROR: phase1 negotiation failed due to time up. 7c03d4505c30deb9:0000000000000000
2015-09-25 14:55:27: WARNING: PF_KEY EXPIRE message received from kernel for SA being negotiated. Stopping negotiation.
2015-09-25 14:55:59: WARNING: PF_KEY EXPIRE message received from kernel for SA being negotiated. Stopping negotiation.
2015-09-25 14:56:19: ERROR: phase1 negotiation failed due to time up. b32b533497d4013d:0000000000000000
2015-09-25 14:56:31: WARNING: PF_KEY EXPIRE message received from kernel for SA being negotiated. Stopping negotiation.
2015-09-25 14:57:03: WARNING: PF_KEY EXPIRE message received from kernel for SA being negotiated. Stopping negotiation.
2015-09-25 14:57:23: ERROR: phase1 negotiation failed due to time up. 1b1afb9331db2048:0000000000000000
2015-09-25 14:57:35: WARNING: PF_KEY EXPIRE message received from kernel for SA being negotiated. Stopping negotiation.
2015-09-25 14:58:08: WARNING: PF_KEY EXPIRE message received from kernel for SA being negotiated. Stopping negotiation.
2015-09-25 14:58:28: ERROR: phase1 negotiation failed due to time up. 6599af15985e6d81:0000000000000000
2015-09-25 14:58:40: WARNING: PF_KEY EXPIRE message received from kernel for SA being negotiated. Stopping negotiation.
2015-09-25 14:59:12: WARNING: PF_KEY EXPIRE message received from kernel for SA being negotiated. Stopping negotiation.
2015-09-25 14:59:32: ERROR: phase1 negotiation failed due to time up. 285376db3913c48a:0000000000000000
2015-09-25 14:59:44: WARNING: PF_KEY EXPIRE message received from kernel for SA being negotiated. Stopping negotiation.
2015-09-25 15:00:16: WARNING: PF_KEY EXPIRE message received from kernel for SA being negotiated. Stopping negotiation.
So managed network seems not working because IPSec tunnel can’t establish.