[Soekris] Corrupted MAC w/VPN1411

andrew fabbro andrew at fabbro.org
Wed Jan 17 22:06:37 UTC 2007


I have a Soekris 4801 with a VPN1411 card running OpenBSD 4.0.  The
BIOS version is 1.28 (the latest).

sis0 and sis1 both have frequent "Corrupted MAC on input" when I 
ssh to them.  

$ ssh root at 192.168.1.2
Received disconnect from 192.168.1.2: 2: Corrupted MAC on input.
$ 

The OpenBSD USENET group didn't have much to say, though it's been 
mentioned there several times:

http://groups.google.com/group/comp.unix.bsd.openbsd.misc/browse_thread/thread/7e0738b24daec4e1/b0cf0c55a42eabfc#b0cf0c55a42eabfc

The connection works fine if I don't use hifn, e.g.:

	 ssh -o Ciphers=blowfish-cbc root at 192.168.1.2

alleviates the problem, since hifn doesn't support Blowfish.  Of
course, going around hardware crypto sort of defeats the purpose 
of having a VPN1411 ;)

Help?


andrew fabbro [ andrew at fabbro.org ] [ blog: http://www.joshusdog.org/ ]
--------------------------[ quote-o-matic] ----------------------------- 
If life gives you lemons, make lemonade.  Well, assuming life also gives
you sugar and water.


More information about the Soekris-tech mailing list