Hi Board.
I have at problem with site to site VPN (ASL Ver 4.25)
I'm having a Direct Internet connection in both ends with static IP-addresses. In one end i have a Cisco 827 with NAT.
I think this is where my problem is since IP-address 10.0.0.2 is th external interface on ASL which goes to internal interface 10.0.0.1 on the Cisco 827 which has the external IP-address YYY.YYY.YYY.YYY
The IPsec log in the NAT end says:
000
000 "SITE1": 192.168.1.0/24===10.0.0.2...XXX.XXX.XXX.XXX===192.168.2.0/24
000 "SITE1": CAs: '%any'...'%any'
000 "SITE1": ike_life: 7800s; ipsec_life: 3600s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0
000 "SITE1": policy: RSASIG+ENCRYPT+TUNNEL; interface: eth0; unrouted
000 "SITE1": newest ISAKMP SA: #0; newest IPsec SA: #0; eroute owner: #0
000 "SITE1": IKE algorithms wanted: 5_000-1-5, flags=-strict
000 "SITE1": IKE algorithms found: 5_192-1_128-5,
000 "SITE1": ESP algorithms wanted: 3_000-1, flags=-strict
000 "SITE1": ESP algorithms loaded: 3_168-1_128,
000
000 #1: "SITE1" STATE_MAIN_I1 (sent MI1, expecting MR1); EVENT_RETRANSMIT in 31s
000
The IPsec log in the direct end says:
000
000 "SITE2": 192.168.2.0/24===XXX.XXX.XXX.XXX...YYY.YYY.YYY.YYY===10.0.0.2/32
000 "SITE2": CAs: '%any'...'%any'
000 "SITE2": ike_life: 7800s; ipsec_life: 3600s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0
000 "SITE2": policy: RSASIG+ENCRYPT+TUNNEL; interface: eth1; unrouted
000 "SITE2": newest ISAKMP SA: #0; newest IPsec SA: #0; eroute owner: #0
000 "SITE2": IKE algorithms wanted: 5_000-1-5, flags=-strict
000 "SITE2": IKE algorithms found: 5_192-1_128-5,
000 "SITE2": ESP algorithms wanted: 3_000-1, flags=-strict
000 "SITE2": ESP algorithms loaded: 3_168-1_128,
000
000 #4: "SITE2" STATE_MAIN_I1 (sent MI1, expecting MR1); EVENT_RETRANSMIT in 14s
000
The live log says:
2005-Mar 21 22:31:38 (none) pluto[23983]: packet from YYY.YYY.YYY.YYY:4500: initial Main Mode message received on XXX.XXX.XXX.XXX:4500 but no connection has been authorized
2005-Mar 21 22:32:17 (none) pluto[23983]: packet from YYY.YYY.YYY.YYY:4500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03]
2005-Mar 21 22:32:17 (none) pluto[23983]: packet from YYY.YYY.YYY.YYY:4500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02]
2005-Mar 21 22:32:17 (none) pluto[23983]: packet from YYY.YYY.YYY.YYY:4500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]
How can I solve this problem ????
I don't know a lot about the Cisco, but I can surely try if anybody can point me in the right direction...
THX
Mountainman
This thread was automatically locked due to age.