I have recently built a box at my home in a DMZ with ASL 4.0.16 and would like to connect using IPSEC via Sentinel 1.4. I setup my connection similar to X509_Host_to_Net_Dynamic.pdf instructions and connection failed. I then read that I wouldn't be able to connect because I was behind a firewall doing NAT. To attempt to rectify this issue I set IPTABLES to forward all prtocol 50 , and UDP port 500 traffic directly to my client machine. Still didn't work. When I run a diagnostic the IKE Phase-1 works but IKE Phase-2 (IPSec proposal) fails. Here is an bit of the log file on ASL:
2003-Nov 20 14:36:47 (none) pluto[988]: packet from 12.5.16.129:500: ignoring Vendor ID payload [SSH Sentinel 1.4]
2003-Nov 20 14:36:47 (none) pluto[988]: "chad_1"[1] 12.5.16.129 #11: responding to Main Mode from unknown peer 12.5.16.129
2003-Nov 20 14:36:47 (none) pluto[988]: "chad_1"[1] 12.5.16.129 #11: ignoring informational payload, type IPSEC_INITIAL_CONTACT
2003-Nov 20 14:36:47 (none) pluto[988]: "chad_1"[1] 12.5.16.129 #11: Main mode peer ID is ID_USER_FQDN: 'claud1e@ctk.phoenix-int.com'
2003-Nov 20 14:36:47 (none) pluto[988]: "chad_1"[1] 12.5.16.129 #11: Issuer CRL not found
2003-Nov 20 14:36:47 (none) pluto[988]: "chad_1"[1] 12.5.16.129 #11: Issuer CRL not found
2003-Nov 20 14:36:47 (none) pluto[988]: "chad_1"[1] 12.5.16.129 #11: sent MR3, ISAKMP SA established
2003-Nov 20 14:36:47 (none) pluto[988]: "chad_1"[1] 12.5.16.129 #11: cannot respond to IPsec SA request because no connection is known for 192.168.0.0/24===192.168.0.3:17/67...x.x.x.x[claud1e@ctk.phoenix-int.com]:17/68===10.10.10.33/32
2003-Nov 20 14:36:47 (none) pluto[988]: "chad_1"[1] x.x.x.x #11: sending encrypted notification INVALID_ID_INFORMATION to x.x.x.x:500
Since I'm new to this I assume it something in the config. Any help would be greatly appreciated!
Thank you for your time,
Claud1e
This thread was automatically locked due to age.