Hi All,
I'm currently busy with a IpSec connection to my ASL 4.x box, using the trial secure client from Astaro. For almost 14 hours of work it still isn't working. I've started to debug the IKE process and found a strange thing, which I was unsuccesfull to resolve so far.
My IPSec log (part)
-------
May 16 22:23:52 (none) pluto[22008]: | ***parse ISAKMP Identification Payload (IPsec DOI):
May 16 22:23:52 (none) pluto[22008]: | next payload type: ISAKMP_NEXT_NONE
May 16 22:23:52 (none) pluto[22008]: | length: 16
May 16 22:23:52 (none) pluto[22008]: | ID type: ID_IPV4_ADDR_SUBNET
May 16 22:23:52 (none) pluto[22008]: | Protocol ID: 0
May 16 22:23:52 (none) pluto[22008]: | port: 0
May 16 22:23:52 (none) pluto[22008]: | HASH(1) computed:
May 16 22:23:52 (none) pluto[22008]: | 64 fe a9 95 6e c4 ad 17 05 49 71 75 69 bc d5 72
May 16 22:23:52 (none) pluto[22008]: | f9 cf 48 ba
May 16 22:23:52 (none) pluto[22008]: | peer client is 172.16.0.1/32
May 16 22:23:52 (none) pluto[22008]: | peer client protocol/port is 0/0
May 16 22:23:52 (none) pluto[22008]: | our client is subnet 0.0.0.0/0
May 16 22:23:52 (none) pluto[22008]: | our client protocol/port is 0/0
May 16 22:23:52 (none) pluto[22008]: "RoadWarrior_1"[2] 192.168.1.106:4500 #5: cannot respond to IPsec SA request because no connection is known for 0.0.0.0/0===10.30.0.2:4500...192.168.1.106:4500[orsel-dc@zonnet.nl]===172.16.0.1/32
May 16 22:23:52 (none) pluto[22008]: "RoadWarrior_1"[2] 192.168.1.106:4500 #5: sending encrypted notification INVALID_ID_INFORMATION to 192.168.1.106:4500
May 16 22:23:52 (none) pluto[22008]: | **emit ISAKMP Message:
May 16 22:23:52 (none) pluto[22008]: | initiator cookie:
May 16 22:23:52 (none) pluto[22008]: | 7a c5 84 11 c6 56 36 73
May 16 22:23:52 (none) pluto[22008]: | responder cookie:
May 16 22:23:52 (none) pluto[22008]: | 34 1d 94 55 29 74 d7 2e
May 16 22:23:52 (none) pluto[22008]: | next payload type: ISAKMP_NEXT_HASH
May 16 22:23:52 (none) pluto[22008]: | ISAKMP version: ISAKMP Version 1.0
May 16 22:23:52 (none) pluto[22008]: | exchange type: ISAKMP_XCHG_INFO
May 16 22:23:52 (none) pluto[22008]: | flags: ISAKMP_FLAG_ENCRYPTION
May 16 22:23:52 (none) pluto[22008]: | message ID: f7 1c 29 36
May 16 22:23:52 (none) pluto[22008]: | ***emit ISAKMP Hash Payload:
May 16 22:23:52 (none) pluto[22008]: | next payload type: ISAKMP_NEXT_N
May 16 22:23:52 (none) pluto[22008]: | emitting 20 zero bytes of HASH(1) into ISAKMP Hash Payload
May 16 22:23:52 (none) pluto[22008]: | emitting length of ISAKMP Hash Payload: 24
May 16 22:23:52 (none) pluto[22008]: | ***emit ISAKMP Notification Payload:
May 16 22:23:52 (none) pluto[22008]: | next payload type: ISAKMP_NEXT_NONE
May 16 22:23:52 (none) pluto[22008]: | DOI: ISAKMP_DOI_IPSEC
May 16 22:23:52 (none) pluto[22008]: | protocol ID: 1
May 16 22:23:52 (none) pluto[22008]: | SPI size: 0
May 16 22:23:52 (none) pluto[22008]: | Notify Message Type: INVALID_ID_INFORMATION
--
And this finally ends up with a message in the secure client:
INVALID_ID_INFORMATION and disconnect. Does anybody has an idea what i'm doing wrong?
Any help would be appreciated very much,
Regards,
Dave
This thread was automatically locked due to age.