Hi,
I am going to establish a connection between a roadwarrior (mobile, GPRS, SSH Sentinel 1.4) and the ASL. Everything works fine with a standard dial-up modem connection, also diagnostic in the SSH Sentinel when using GPRS mobile-to-net, but a real connecton is impossible. NAT-T is activated, IP compression disabled. What's wrong ?
Mar 13 15:54:07 (none) pluto[2140]: packet from 212.2.100.250:873: ignoring Vendor ID payload [SSH Sentinel 1.4]
Mar 13 15:54:07 (none) pluto[2140]: packet from 212.2.100.250:873: ignoring Vendor ID payload [draft-stenberg-ipsec-nat-traversal-01]
Mar 13 15:54:07 (none) pluto[2140]: packet from 212.2.100.250:873: ignoring Vendor ID payload [draft-stenberg-ipsec-nat-traversal-02]
Mar 13 15:54:07 (none) pluto[2140]: packet from 212.2.100.250:873: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]
Mar 13 15:54:07 (none) pluto[2140]: "xxx_1"[8] 212.2.100.250:873 #24: responding to Main Mode from unknown peer 212.2.100.250:873
Mar 13 15:54:07 (none) pluto[2140]: "xxx_1"[8] 212.2.100.250:873 #23: NAT-Traversal: Result using draft-ietf-ipsec-nat-t-ike-00: peer is NATed
Mar 13 15:54:08 (none) pluto[2140]: "xxx_1"[8] 212.2.100.250:873 #23: discarding duplicate packet; already STATE_MAIN_R2
Mar 13 15:54:09 (none) pluto[2140]: "xxx_1"[8] 212.2.100.250:873 #23: ignoring informational payload, type IPSEC_INITIAL_CONTACT
Mar 13 15:54:09 (none) pluto[2140]: "xxx_1"[8] 212.2.100.250:873 #23: Peer ID is ID_USER_FQDN: 'aaa@bbb.ccc'
Mar 13 15:54:09 (none) pluto[2140]: "xxx_1"[8] 212.2.100.250:873 #23: Issuer CRL not found
Mar 13 15:54:09 (none) pluto[2140]: "xxx_1"[8] 212.2.100.250:873 #23: Issuer CRL not found
Mar 13 15:54:09 (none) pluto[2140]: "xxx_1"[8] 212.2.100.250:873 #23: sent MR3, ISAKMP SA established
Mar 13 15:54:12 (none) pluto[2140]: "xxx_1"[8] 212.2.100.250:873 #23: retransmitting in response to duplicate packet; already STATE_MAIN_R3
Mar 13 15:54:13 (none) pluto[2140]: "xxx_1"[8] 212.2.100.250:873 #23: retransmitting in response to duplicate packet; already STATE_MAIN_R3
Mar 13 15:54:13 (none) pluto[2140]: "xxx_1"[8] 212.2.100.250:873 #25: ENCAPSULATION_MODE_TUNNEL must only be used if NAT-Traversal is not detected
Mar 13 15:54:13 (none) pluto[2140]: "xxx_1"[8] 212.2.100.250:873 #25: responding to Quick Mode
Mar 13 15:54:15 (none) pluto[2140]: "xxx_1"[8] 212.2.100.250:873 #25: discarding duplicate packet; already STATE_QUICK_R1
Mar 13 15:54:15 (none) pluto[2140]: "xxx_1"[8] 212.2.100.250:873 #25: IPsec SA established
Mar 13 15:54:15 (none) pluto[2140]: "xxx_1"[8] 212.2.100.250:873 #23: received Delete SA payload: deleting IPSEC State #25
Mar 13 15:54:15 (none) pluto[2140]: "xxx_1"[8] 212.2.100.250:873 #23: received Delete SA payload: deleting ISAKMP State #23
Mar 13 15:55:17 (none) pluto[2140]: "xxx_1"[8] 212.2.100.250:873 #24: max number of retransmissions (2) reached STATE_MAIN_R1
Mar 13 15:55:17 (none) pluto[2140]: "xxx_1"[8] 212.2.100.250:873: deleting connection "xxx_1" instance with peer 212.2.100.250
Sentinel is always retrying a connection 5 times and disconnecting.
This thread was automatically locked due to age.