My set-up is as follows:
WORK LAN --- ASL v4 --- ADSL Modem --- [Internet] --- Cable Modem --- Home PC (WinXP Pro)
Using the "Host to Net - Static / Dynamic - X509" document I have created and
been using a VPN tunnel between my Home PC (using SSH Sentinal) and Work LAN.
At the Home side of the tunnel I have added a Linksys Wireless Broadband Router (WRT54G)
between the Home PC and Cable Modem. My set-up now looks as follows:
WORK LAN --- ASL v4 --- ADSL Modem --- [Internet] --- Cable Modem --- Linksys Wireless Router --- Home PC (WinXP Pro)
My problem is that since installing the Linksys I have not been able to create the VPN
tunnel.
If I run diagnostics on SSH Sentinal I get the following error messge:
Cannot run the diagnostics. The remote end cannot find suitable
IPSec proposal (phase-2) parameters. Verify the IPSec proposal
parameters.
And my ASL reports the following (note. I have masked my Work IP as aaa.aaa.aaa.aaa and Home IP (ISP - DHCP assigned) as bbb.bbb.bbb.bbb):
2004-Apr 28 20:00:25 (none) pluto[2110]: "IanMacey_1"[7] bbb.bbb.bbb.bbb #117: initiating Main Mode to replace #116
2004-Apr 28 20:06:21 (none) pluto[2110]: packet from bbb.bbb.bbb.bbb:500: ignoring Vendor ID payload [SSH Communications Security IPSEC Express version 4.1.0]
2004-Apr 28 20:06:21 (none) pluto[2110]: "IanMacey_1"[7] bbb.bbb.bbb.bbb #118: responding to Main Mode from unknown peer bbb.bbb.bbb.bbb
2004-Apr 28 20:06:21 (none) pluto[2110]: "IanMacey_1"[7] bbb.bbb.bbb.bbb #118: ignoring informational payload, type IPSEC_INITIAL_CONTACT
2004-Apr 28 20:06:21 (none) pluto[2110]: "IanMacey_1"[7] bbb.bbb.bbb.bbb #118: Main mode peer ID is ID_USER_FQDN: 'ian.macey@havanaintbank.co.uk'
2004-Apr 28 20:06:21 (none) pluto[2110]: "IanMacey_1"[7] bbb.bbb.bbb.bbb #118: Issuer CRL not found
2004-Apr 28 20:06:21 (none) pluto[2110]: "IanMacey_1"[7] bbb.bbb.bbb.bbb #118: Issuer CRL not found
2004-Apr 28 20:06:21 (none) pluto[2110]: "IanMacey_1"[7] bbb.bbb.bbb.bbb #118: sent MR3, ISAKMP SA established
2004-Apr 28 20:06:21 (none) pluto[2110]: "IanMacey_1"[7] bbb.bbb.bbb.bbb #118: cannot respond to IPsec SA request because no connection is known for 192.168.0.0/24===aaa.aaa.aaa.aaa[@aaa.aaa.aaa.aaa]...bbb.bbb.bbb.bbb[ian.macey@havanaintbank.co.uk]===192.168.1.100/32
2004-Apr 28 20:06:21 (none) pluto[2110]: "IanMacey_1"[7] bbb.bbb.bbb.bbb #118: sending encrypted notification INVALID_ID_INFORMATION to bbb.bbb.bbb.bbb:500
2004-Apr 28 20:06:55 (none) pluto[2110]: "IanMacey_1"[7] bbb.bbb.bbb.bbb #117: ignoring Vendor ID payload [SSH Communications Security IPSEC Express version 4.1.0]
2004-Apr 28 20:06:55 (none) pluto[2110]: "IanMacey_1"[7] bbb.bbb.bbb.bbb #117: ignoring Vendor ID payload [draft-stenberg-ipsec-nat-traversal-01]
2004-Apr 28 20:06:55 (none) pluto[2110]: "IanMacey_1"[7] bbb.bbb.bbb.bbb #117: ignoring Vendor ID payload [draft-stenberg-ipsec-nat-traversal-02]
2004-Apr 28 20:06:55 (none) pluto[2110]: "IanMacey_1"[7] bbb.bbb.bbb.bbb #117: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]
2004-Apr 28 20:06:56 (none) pluto[2110]: "IanMacey_1"[7] bbb.bbb.bbb.bbb #117: Main mode peer ID is ID_USER_FQDN: 'ian.macey@havanaintbank.co.uk'
2004-Apr 28 20:06:56 (none) pluto[2110]: "IanMacey_1"[7] bbb.bbb.bbb.bbb #117: Issuer CA certificate not found
2004-Apr 28 20:06:56 (none) pluto[2110]: "IanMacey_1"[7] bbb.bbb.bbb.bbb #117: X.509 certificate rejected
2004-Apr 28 20:06:56 (none) pluto[2110]: "IanMacey_1"[7] bbb.bbb.bbb.bbb #117: Signature check (on ian.macey@havanaintbank.co.uk) failed (wrong key?); tried *AwEAAax/1
2004-Apr 28 20:06:56 (none) pluto[2110]: "IanMacey_1"[7] bbb.bbb.bbb.bbb #117: sending notification INVALID_KEY_INFORMATION to bbb.bbb.bbb.bbb:500
Now if I disconnect the Linksys and put everything back as it originally was, I can create the VPN tunnel.
If anyone can offer any assistance it would be most welcome.
Regards Ian
This thread was automatically locked due to age.