I'm trying to get an VPN connection working between a Zywall10 and my Astaro 3.208 Box. It seems like this 2 wont get working together.
I have a working configuration between 2 Zywall10 and also one between 2 Astaro Boxes. Then I tried to VPN between Astaro and ZyWall10, but I get allways the same:
The first Key (ISAKMP) negotiation works without any problem, but the second Key (IPSEC SA) dont works.
I must say here that I'm a newbie regarding VPN's.
Both side has static IP's and like I can see in my logs the first Key is beeing exchanged. So Please can someone tell where I have a look for finding the Problem? Or, has someone a VPN up and running with the same components (Astaro ZyWall10)?
here a look in my log:
000 "Domis__VPN__CNSD_1": newest ISAKMP SA: #1; newest IPsec SA: #0; eroute owner: #0I've searched in every searchengine in the Internet for the line:
000 "Domis__VPN__CNSD_1": ESP algorithms wanted: 3/000-1/000, 3/000-2/000,
000 "Domis__VPN__CNSD_1": ESP algorithms loaded: 3/168-1/128, 3/168-2/160,
000
000 #2: "Domis__VPN__CNSD_1" STATE_QUICK_I1 (sent QI1, expecting QR1); EVENT_RETRANSMIT in 8s
000 #1: "Domis__VPN__CNSD_1" STATE_MAIN_I4 (ISAKMP SA established); EVENT_SA_REPLACE in 27806s; newest ISAKMP
"STATE_QUICK_I1 (sent QI1, expecting QR1); EVENT_RETRANSMIT in 8s".
I think this is the problem, but there is nowhere an explanation what this means.
this is also what I found in the logfile of VPN:
Pluto[29147]: | ***parse ISAKMP Notification Payload:what means this?
Pluto[29147]: | next payload type: ISAKMP_NEXT_NONE
Pluto[29147]: | length: 16
Pluto[29147]: | DOI: ISAKMP_DOI_IPSEC
Pluto[29147]: | protocol ID: 3
Pluto[29147]: | SPI size: 4
Pluto[29147]: | Notify Message Type: INVALID_ID_INFORMATION
Pluto[29147]: | removing 4 bytes of padding
Pluto[29147]: "Domis__VPN__CNSD_1" #1: ignoring informational payload, type INVALID_ID_INFORMATION
Pluto[29147]: | info: 48 54 0f fb
Pluto[29147]: "Domis__VPN__CNSD_1" #1: received and ignored informational message
Pluto[29147]: | next event EVENT_RETRANSMIT in 10 seconds for #2
thanx a lot for some help
eldorado
[size="1"][ 05 September 2002, 13:53: Message edited by: eldorado ][/size]
This thread was automatically locked due to age.