This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Roadwarrior Doesn't work at all

Hi, can anybody find a mistake that causes the error? 
I do the config exactly as described in the Astaro howto and it doesn't work. For testing I am directly connected to the internet there is no nat.!


My logs: 

2005:07:04-18:26:43 (none) ipsec_starter[5154]: Starting FreeS/WAN IPsec 1.0.2b [starter]...
2005:07:04-18:26:43 (none) ipsec_starter[5166]: IP address of physical interface changed -> reinit of ipsec interface
2005:07:04-18:26:43 (none) ipsec_starter[5166]: attaching interface ipsec0 to ppp0
2005:07:04-18:26:43 (none) ipsec_starter[5166]: Attempting to start pluto...
2005:07:04-18:26:45 (none) ipsec_starter[5166]: pluto (5170) started
2005:07:04-18:26:45 (none) ipsec_starter[5166]: Setting --esp=aes128-sha1!;modp1536
2005:07:04-18:26:45 (none) pluto[5170]: Starting Pluto (Openswan Version 1.0.2b)
2005:07:04-18:26:45 (none) pluto[5170]:   including X.509 patch with traffic selectors (Version 0.9.39b)
2005:07:04-18:26:45 (none) pluto[5170]:   including NAT-Traversal patch (Version 0.6)
2005:07:04-18:26:45 (none) pluto[5170]: ike_alg_register_enc(): Activating OAKLEY_DES_CBC: Ok (ret=0)
2005:07:04-18:26:45 (none) pluto[5170]: ike_alg_register_enc(): Activating OAKLEY_AES_CBC: Ok (ret=0)
2005:07:04-18:26:45 (none) pluto[5170]: ike_alg_register_enc(): Activating OAKLEY_BLOWFISH_CBC: Ok (ret=0)
2005:07:04-18:26:45 (none) pluto[5170]: ike_alg_register_enc(): Activating OAKLEY_CAST_CBC: Ok (ret=0)
2005:07:04-18:26:45 (none) pluto[5170]: ike_alg_register_enc(): Activating OAKLEY_SERPENT_CBC: Ok (ret=0)
2005:07:04-18:26:45 (none) pluto[5170]: ike_alg_register_hash(): Activating OAKLEY_SHA2_256: Ok (ret=0)
2005:07:04-18:26:45 (none) pluto[5170]: ike_alg_register_hash(): Activating OAKLEY_SHA2_512: Ok (ret=0)
2005:07:04-18:26:45 (none) pluto[5170]: ike_alg_register_enc(): Activating OAKLEY_TWOFISH_CBC: Ok (ret=0)
2005:07:04-18:26:45 (none) pluto[5170]: ike_alg_register_enc(): Activating OAKLEY_SSH_PRIVATE_65289: Ok (ret=0)
2005:07:04-18:26:45 (none) pluto[5170]: Changing to directory '/etc/ipsec.d/cacerts'
2005:07:04-18:26:45 (none) pluto[5170]:   loaded cacert file 'Astaro_CA.pem' (1038 bytes)
2005:07:04-18:26:45 (none) pluto[5170]: Changing to directory '/etc/ipsec.d/crls'
2005:07:04-18:26:45 (none) pluto[5170]:   Warning: empty directory
2005:07:04-18:26:45 (none) pluto[5170]: OpenPGP certificate file '/etc/pgpcert.pgp' not found
2005:07:04-18:26:45 (none) pluto[5170]: listening for IKE messages
2005:07:04-18:26:45 (none) pluto[5170]: adding interface ipsec0/ppp0 84.158.239.56
2005:07:04-18:26:45 (none) pluto[5170]: adding interface ipsec0/ppp0 84.158.239.56:4500
2005:07:04-18:26:45 (none) pluto[5170]: loading secrets from "/etc/ipsec.secrets"
2005:07:04-18:26:45 (none) pluto[5170]:   loaded private key file '/etc/ipsec.d/private/Astaro_Schluessel.pem' (963 bytes)
2005:07:04-18:26:45 (none) pluto[5170]: | from whack: got --esp=aes128-sha1!;modp1536
2005:07:04-18:26:45 (none) pluto[5170]: | from whack: got --ike=aes256-sha-modp1536
2005:07:04-18:26:45 (none) pluto[5170]:   loaded host cert file '/etc/x509cert.der' (928 bytes)
2005:07:04-18:26:45 (none) pluto[5170]:   loaded host cert file '/etc/ipsec.d/hostcerts/Bareis.pem' (3641 bytes)
2005:07:04-18:26:45 (none) pluto[5170]: added connection description "D_Roadwarriors_0"
2005:07:04-18:33:13 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [da8e937880010000]
2005:07:04-18:33:13 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [XAUTH]
2005:07:04-18:33:13 (none) pluto[5170]: packet from 84.158.17.34:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03]
2005:07:04-18:33:13 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n]
2005:07:04-18:33:13 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]
2005:07:04-18:33:13 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [4a131c8107035845...]
2005:07:04-18:33:13 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [101fb0b35c5a4f4c...]
2005:07:04-18:33:13 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [Cisco-Unity]
2005:07:04-18:33:13 (none) pluto[5170]: "D_Roadwarriors_0"[1] 84.158.17.34 #1: responding to Main Mode from unknown peer 84.158.17.34
2005:07:04-18:33:13 (none) pluto[5170]: "D_Roadwarriors_0"[1] 84.158.17.34 #1: transition from state (null) to state STATE_MAIN_R1
2005:07:04-18:33:14 (none) pluto[5170]: "D_Roadwarriors_0"[1] 84.158.17.34 #1: NAT-Traversal: Result using draft-ietf-ipsec-nat-t-ike-02/03: no NAT detected
2005:07:04-18:33:14 (none) pluto[5170]: "D_Roadwarriors_0"[1] 84.158.17.34 #1: transition from state STATE_MAIN_R1 to state STATE_MAIN_R2
2005:07:04-18:33:15 (none) pluto[5170]: "D_Roadwarriors_0"[1] 84.158.17.34 #1: ignoring informational payload, type IPSEC_INITIAL_CONTACT
2005:07:04-18:33:15 (none) pluto[5170]: "D_Roadwarriors_0"[1] 84.158.17.34 #1: Main mode peer ID is ID_USER_FQDN: 'bareis@gmx.net'
2005:07:04-18:33:15 (none) pluto[5170]: "D_Roadwarriors_0"[1] 84.158.17.34 #1: Issuer CRL not found
2005:07:04-18:33:15 (none) pluto[5170]: "D_Roadwarriors_0"[1] 84.158.17.34 #1: Issuer CRL not found
2005:07:04-18:33:15 (none) pluto[5170]: "D_Roadwarriors_0"[1] 84.158.17.34 #1: transition from state STATE_MAIN_R2 to state STATE_MAIN_R3
2005:07:04-18:33:15 (none) pluto[5170]: "D_Roadwarriors_0"[1] 84.158.17.34 #1: sent MR3, ISAKMP SA established
2005:07:04-18:33:16 (none) pluto[5170]: "D_Roadwarriors_0"[1] 84.158.17.34 #1: received Delete SA payload: deleting ISAKMP State #1
2005:07:04-18:33:16 (none) pluto[5170]: "D_Roadwarriors_0"[1] 84.158.17.34: deleting connection "D_Roadwarriors_0" instance with peer 84.158.17.34
2005:07:04-18:33:16 (none) pluto[5170]: packet from 84.158.17.34:500: received and ignored informational message
2005:07:04-18:33:39 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [da8e937880010000]
2005:07:04-18:33:39 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [XAUTH]
2005:07:04-18:33:39 (none) pluto[5170]: packet from 84.158.17.34:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03]
2005:07:04-18:33:39 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n]
2005:07:04-18:33:39 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]
2005:07:04-18:33:39 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [4a131c8107035845...]
2005:07:04-18:33:39 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [101fb0b35c5a4f4c...]
2005:07:04-18:33:39 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [Cisco-Unity]
2005:07:04-18:33:39 (none) pluto[5170]: "D_Roadwarriors_0"[2] 84.158.17.34 #2: responding to Main Mode from unknown peer 84.158.17.34
2005:07:04-18:33:39 (none) pluto[5170]: "D_Roadwarriors_0"[2] 84.158.17.34 #2: transition from state (null) to state STATE_MAIN_R1
2005:07:04-18:33:40 (none) pluto[5170]: "D_Roadwarriors_0"[2] 84.158.17.34 #2: NAT-Traversal: Result using draft-ietf-ipsec-nat-t-ike-02/03: no NAT detected
2005:07:04-18:33:40 (none) pluto[5170]: "D_Roadwarriors_0"[2] 84.158.17.34 #2: transition from state STATE_MAIN_R1 to state STATE_MAIN_R2
2005:07:04-18:33:41 (none) pluto[5170]: "D_Roadwarriors_0"[2] 84.158.17.34 #2: ignoring informational payload, type IPSEC_INITIAL_CONTACT
2005:07:04-18:33:41 (none) pluto[5170]: "D_Roadwarriors_0"[2] 84.158.17.34 #2: Main mode peer ID is ID_USER_FQDN: 'bareis@gmx.net'
2005:07:04-18:33:41 (none) pluto[5170]: "D_Roadwarriors_0"[2] 84.158.17.34 #2: Issuer CRL not found
2005:07:04-18:33:41 (none) pluto[5170]: "D_Roadwarriors_0"[2] 84.158.17.34 #2: Issuer CRL not found
2005:07:04-18:33:41 (none) pluto[5170]: "D_Roadwarriors_0"[2] 84.158.17.34 #2: transition from state STATE_MAIN_R2 to state STATE_MAIN_R3
2005:07:04-18:33:41 (none) pluto[5170]: "D_Roadwarriors_0"[2] 84.158.17.34 #2: sent MR3, ISAKMP SA established
2005:07:04-18:33:42 (none) pluto[5170]: "D_Roadwarriors_0"[2] 84.158.17.34 #2: received Delete SA payload: deleting ISAKMP State #2
2005:07:04-18:33:42 (none) pluto[5170]: "D_Roadwarriors_0"[2] 84.158.17.34: deleting connection "D_Roadwarriors_0" instance with peer 84.158.17.34
2005:07:04-18:33:42 (none) pluto[5170]: packet from 84.158.17.34:500: received and ignored informational message
2005:07:04-18:34:29 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [da8e937880010000]
2005:07:04-18:34:29 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [XAUTH]
2005:07:04-18:34:29 (none) pluto[5170]: packet from 84.158.17.34:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03]
2005:07:04-18:34:29 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n]
2005:07:04-18:34:29 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]
2005:07:04-18:34:29 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [4a131c8107035845...]
2005:07:04-18:34:29 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [101fb0b35c5a4f4c...]
2005:07:04-18:34:29 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [Cisco-Unity]
2005:07:04-18:34:29 (none) pluto[5170]: "D_Roadwarriors_0"[3] 84.158.17.34 #3: responding to Main Mode from unknown peer 84.158.17.34
2005:07:04-18:34:29 (none) pluto[5170]: "D_Roadwarriors_0"[3] 84.158.17.34 #3: transition from state (null) to state STATE_MAIN_R1
2005:07:04-18:34:30 (none) pluto[5170]: "D_Roadwarriors_0"[3] 84.158.17.34 #3: NAT-Traversal: Result using draft-ietf-ipsec-nat-t-ike-02/03: no NAT detected
2005:07:04-18:34:30 (none) pluto[5170]: "D_Roadwarriors_0"[3] 84.158.17.34 #3: transition from state STATE_MAIN_R1 to state STATE_MAIN_R2
2005:07:04-18:34:31 (none) pluto[5170]: "D_Roadwarriors_0"[3] 84.158.17.34 #3: ignoring informational payload, type IPSEC_INITIAL_CONTACT
2005:07:04-18:34:31 (none) pluto[5170]: "D_Roadwarriors_0"[3] 84.158.17.34 #3: Main mode peer ID is ID_USER_FQDN: 'bareis@gmx.net'
2005:07:04-18:34:31 (none) pluto[5170]: "D_Roadwarriors_0"[3] 84.158.17.34 #3: Issuer CRL not found
2005:07:04-18:34:31 (none) pluto[5170]: "D_Roadwarriors_0"[3] 84.158.17.34 #3: Issuer CRL not found
2005:07:04-18:34:31 (none) pluto[5170]: "D_Roadwarriors_0"[3] 84.158.17.34 #3: transition from state STATE_MAIN_R2 to state STATE_MAIN_R3
2005:07:04-18:34:31 (none) pluto[5170]: "D_Roadwarriors_0"[3] 84.158.17.34 #3: sent MR3, ISAKMP SA established
2005:07:04-18:34:32 (none) pluto[5170]: "D_Roadwarriors_0"[3] 84.158.17.34 #3: received Delete SA payload: deleting ISAKMP State #3
2005:07:04-18:34:32 (none) pluto[5170]: "D_Roadwarriors_0"[3] 84.158.17.34: deleting connection "D_Roadwarriors_0" instance with peer 84.158.17.34
2005:07:04-18:34:32 (none) pluto[5170]: packet from 84.158.17.34:500: received and ignored informational message
2005:07:04-18:35:12 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [da8e937880010000]
2005:07:04-18:35:12 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [XAUTH]
2005:07:04-18:35:12 (none) pluto[5170]: packet from 84.158.17.34:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03]
2005:07:04-18:35:12 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n]
2005:07:04-18:35:12 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]
2005:07:04-18:35:12 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [4a131c8107035845...]
2005:07:04-18:35:12 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [101fb0b35c5a4f4c...]
2005:07:04-18:35:12 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [Cisco-Unity]
2005:07:04-18:35:12 (none) pluto[5170]: "D_Roadwarriors_0"[4] 84.158.17.34 #4: responding to Main Mode from unknown peer 84.158.17.34
2005:07:04-18:35:12 (none) pluto[5170]: "D_Roadwarriors_0"[4] 84.158.17.34 #4: transition from state (null) to state STATE_MAIN_R1
2005:07:04-18:35:13 (none) pluto[5170]: "D_Roadwarriors_0"[4] 84.158.17.34 #4: NAT-Traversal: Result using draft-ietf-ipsec-nat-t-ike-02/03: no NAT detected
2005:07:04-18:35:13 (none) pluto[5170]: "D_Roadwarriors_0"[4] 84.158.17.34 #4: transition from state STATE_MAIN_R1 to state STATE_MAIN_R2
2005:07:04-18:35:14 (none) pluto[5170]: "D_Roadwarriors_0"[4] 84.158.17.34 #4: ignoring informational payload, type IPSEC_INITIAL_CONTACT
2005:07:04-18:35:14 (none) pluto[5170]: "D_Roadwarriors_0"[4] 84.158.17.34 #4: Main mode peer ID is ID_USER_FQDN: 'bareis@gmx.net'
2005:07:04-18:35:14 (none) pluto[5170]: "D_Roadwarriors_0"[4] 84.158.17.34 #4: Issuer CRL not found
2005:07:04-18:35:14 (none) pluto[5170]: "D_Roadwarriors_0"[4] 84.158.17.34 #4: Issuer CRL not found
2005:07:04-18:35:14 (none) pluto[5170]: "D_Roadwarriors_0"[4] 84.158.17.34 #4: transition from state STATE_MAIN_R2 to state STATE_MAIN_R3
2005:07:04-18:35:14 (none) pluto[5170]: "D_Roadwarriors_0"[4] 84.158.17.34 #4: sent MR3, ISAKMP SA established
2005:07:04-18:35:15 (none) pluto[5170]: "D_Roadwarriors_0"[4] 84.158.17.34 #4: received Delete SA payload: deleting ISAKMP State #4
2005:07:04-18:35:15 (none) pluto[5170]: "D_Roadwarriors_0"[4] 84.158.17.34: deleting connection "D_Roadwarriors_0" instance with peer 84.158.17.34
2005:07:04-18:35:15 (none) pluto[5170]: packet from 84.158.17.34:500: received and ignored informational message
2005:07:04-18:37:53 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [da8e937880010000]
2005:07:04-18:37:53 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [XAUTH]
2005:07:04-18:37:53 (none) pluto[5170]: packet from 84.158.17.34:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03]
2005:07:04-18:37:53 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n]
2005:07:04-18:37:53 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]
2005:07:04-18:37:53 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [4a131c8107035845...]
2005:07:04-18:37:53 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [101fb0b35c5a4f4c...]
2005:07:04-18:37:53 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [Cisco-Unity]
2005:07:04-18:37:53 (none) pluto[5170]: "D_Roadwarriors_0"[5] 84.158.17.34 #5: responding to Main Mode from unknown peer 84.158.17.34
2005:07:04-18:37:53 (none) pluto[5170]: "D_Roadwarriors_0"[5] 84.158.17.34 #5: transition from state (null) to state STATE_MAIN_R1
2005:07:04-18:37:54 (none) pluto[5170]: "D_Roadwarriors_0"[5] 84.158.17.34 #5: NAT-Traversal: Result using draft-ietf-ipsec-nat-t-ike-02/03: no NAT detected
2005:07:04-18:37:54 (none) pluto[5170]: "D_Roadwarriors_0"[5] 84.158.17.34 #5: transition from state STATE_MAIN_R1 to state STATE_MAIN_R2
2005:07:04-18:37:55 (none) pluto[5170]: "D_Roadwarriors_0"[5] 84.158.17.34 #5: ignoring informational payload, type IPSEC_INITIAL_CONTACT
2005:07:04-18:37:55 (none) pluto[5170]: "D_Roadwarriors_0"[5] 84.158.17.34 #5: Main mode peer ID is ID_USER_FQDN: 'bareis@gmx.net'
2005:07:04-18:37:55 (none) pluto[5170]: "D_Roadwarriors_0"[5] 84.158.17.34 #5: Issuer CRL not found
2005:07:04-18:37:55 (none) pluto[5170]: "D_Roadwarriors_0"[5] 84.158.17.34 #5: Issuer CRL not found
2005:07:04-18:37:55 (none) pluto[5170]: "D_Roadwarriors_0"[5] 84.158.17.34 #5: transition from state STATE_MAIN_R2 to state STATE_MAIN_R3
2005:07:04-18:37:55 (none) pluto[5170]: "D_Roadwarriors_0"[5] 84.158.17.34 #5: sent MR3, ISAKMP SA established
2005:07:04-18:37:56 (none) pluto[5170]: "D_Roadwarriors_0"[5] 84.158.17.34 #5: received Delete SA payload: deleting ISAKMP State #5
2005:07:04-18:37:56 (none) pluto[5170]: "D_Roadwarriors_0"[5] 84.158.17.34: deleting connection "D_Roadwarriors_0" instance with peer 84.158.17.34
2005:07:04-18:37:56 (none) pluto[5170]: packet from 84.158.17.34:500: received and ignored informational message
2005:07:04-18:40:10 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [da8e937880010000]
2005:07:04-18:40:10 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [XAUTH]
2005:07:04-18:40:10 (none) pluto[5170]: packet from 84.158.17.34:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03]
2005:07:04-18:40:10 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n]
2005:07:04-18:40:10 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]
2005:07:04-18:40:10 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [4a131c8107035845...]
2005:07:04-18:40:10 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [101fb0b35c5a4f4c...]
2005:07:04-18:40:10 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [Cisco-Unity]
2005:07:04-18:40:10 (none) pluto[5170]: "D_Roadwarriors_0"[6] 84.158.17.34 #6: responding to Main Mode from unknown peer 84.158.17.34
2005:07:04-18:40:10 (none) pluto[5170]: "D_Roadwarriors_0"[6] 84.158.17.34 #6: transition from state (null) to state STATE_MAIN_R1
2005:07:04-18:40:11 (none) pluto[5170]: "D_Roadwarriors_0"[6] 84.158.17.34 #6: NAT-Traversal: Result using draft-ietf-ipsec-nat-t-ike-02/03: no NAT detected
2005:07:04-18:40:11 (none) pluto[5170]: "D_Roadwarriors_0"[6] 84.158.17.34 #6: transition from state STATE_MAIN_R1 to state STATE_MAIN_R2
2005:07:04-18:40:42 (none) pluto[5170]: "D_Roadwarriors_0"[6] 84.158.17.34 #6: ignoring informational payload, type IPSEC_INITIAL_CONTACT
2005:07:04-18:40:42 (none) pluto[5170]: "D_Roadwarriors_0"[6] 84.158.17.34 #6: Main mode peer ID is ID_USER_FQDN: 'bareis@gmx.net'
2005:07:04-18:40:42 (none) pluto[5170]: "D_Roadwarriors_0"[6] 84.158.17.34 #6: Issuer CRL not found
2005:07:04-18:40:42 (none) pluto[5170]: "D_Roadwarriors_0"[6] 84.158.17.34 #6: Issuer CRL not found
2005:07:04-18:40:42 (none) pluto[5170]: "D_Roadwarriors_0"[6] 84.158.17.34 #6: transition from state STATE_MAIN_R2 to state STATE_MAIN_R3
2005:07:04-18:40:42 (none) pluto[5170]: "D_Roadwarriors_0"[6] 84.158.17.34 #6: sent MR3, ISAKMP SA established
2005:07:04-18:40:43 (none) pluto[5170]: "D_Roadwarriors_0"[6] 84.158.17.34 #6: retransmitting in response to duplicate packet; already STATE_MAIN_R3
2005:07:04-18:40:44 (none) pluto[5170]: "D_Roadwarriors_0"[6] 84.158.17.34 #6: received Delete SA payload: deleting ISAKMP State #6
2005:07:04-18:40:44 (none) pluto[5170]: "D_Roadwarriors_0"[6] 84.158.17.34: deleting connection "D_Roadwarriors_0" instance with peer 84.158.17.34
2005:07:04-18:40:44 (none) pluto[5170]: packet from 84.158.17.34:500: received and ignored informational message
2005:07:04-18:43:08 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [da8e937880010000]
2005:07:04-18:43:08 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [XAUTH]
2005:07:04-18:43:08 (none) pluto[5170]: packet from 84.158.17.34:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03]
2005:07:04-18:43:08 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n]
2005:07:04-18:43:08 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]
2005:07:04-18:43:08 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [4a131c8107035845...]
2005:07:04-18:43:08 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [101fb0b35c5a4f4c...]
2005:07:04-18:43:08 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [Cisco-Unity]
2005:07:04-18:43:08 (none) pluto[5170]: "D_Roadwarriors_0"[7] 84.158.17.34 #7: responding to Main Mode from unknown peer 84.158.17.34
2005:07:04-18:43:08 (none) pluto[5170]: "D_Roadwarriors_0"[7] 84.158.17.34 #7: transition from state (null) to state STATE_MAIN_R1
2005:07:04-18:43:09 (none) pluto[5170]: "D_Roadwarriors_0"[7] 84.158.17.34 #7: NAT-Traversal: Result using draft-ietf-ipsec-nat-t-ike-02/03: no NAT detected
2005:07:04-18:43:09 (none) pluto[5170]: "D_Roadwarriors_0"[7] 84.158.17.34 #7: transition from state STATE_MAIN_R1 to state STATE_MAIN_R2
2005:07:04-18:43:10 (none) pluto[5170]: "D_Roadwarriors_0"[7] 84.158.17.34 #7: ignoring informational payload, type IPSEC_INITIAL_CONTACT
2005:07:04-18:43:10 (none) pluto[5170]: "D_Roadwarriors_0"[7] 84.158.17.34 #7: Main mode peer ID is ID_USER_FQDN: 'bareis@gmx.net'
2005:07:04-18:43:10 (none) pluto[5170]: "D_Roadwarriors_0"[7] 84.158.17.34 #7: Issuer CRL not found
2005:07:04-18:43:10 (none) pluto[5170]: "D_Roadwarriors_0"[7] 84.158.17.34 #7: Issuer CRL not found
2005:07:04-18:43:10 (none) pluto[5170]: "D_Roadwarriors_0"[7] 84.158.17.34 #7: transition from state STATE_MAIN_R2 to state STATE_MAIN_R3
2005:07:04-18:43:10 (none) pluto[5170]: "D_Roadwarriors_0"[7] 84.158.17.34 #7: sent MR3, ISAKMP SA established
2005:07:04-18:43:12 (none) pluto[5170]: "D_Roadwarriors_0"[7] 84.158.17.34 #7: received Delete SA payload: deleting ISAKMP State #7
2005:07:04-18:43:12 (none) pluto[5170]: "D_Roadwarriors_0"[7] 84.158.17.34: deleting connection "D_Roadwarriors_0" instance with peer 84.158.17.34
2005:07:04-18:43:12 (none) pluto[5170]: packet from 84.158.17.34:500: received and ignored informational message
2005:07:04-18:43:32 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [da8e937880010000]
2005:07:04-18:43:32 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [XAUTH]
2005:07:04-18:43:32 (none) pluto[5170]: packet from 84.158.17.34:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03]
2005:07:04-18:43:32 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n]
2005:07:04-18:43:32 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]
2005:07:04-18:43:32 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [4a131c8107035845...]
2005:07:04-18:43:32 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [101fb0b35c5a4f4c...]
2005:07:04-18:43:32 (none) pluto[5170]: packet from 84.158.17.34:500: ignoring Vendor ID payload [Cisco-Unity]
2005:07:04-18:43:32 (none) pluto[5170]: "D_Roadwarriors_0"[8] 84.158.17.34 #8: responding to Main Mode from unknown peer 84.158.17.34
2005:07:04-18:43:32 (none) pluto[5170]: "D_Roadwarriors_0"[8] 84.158.17.34 #8: transition from state (null) to state STATE_MAIN_R1
2005:07:04-18:43:33 (none) pluto[5170]: "D_Roadwarriors_0"[8] 84.158.17.34 #8: NAT-Traversal: Result using draft-ietf-ipsec-nat-t-ike-02/03: no NAT detected
2005:07:04-18:43:33 (none) pluto[5170]: "D_Roadwarriors_0"[8] 84.158.17.34 #8: transition from state STATE_MAIN_R1 to state STATE_MAIN_R2
2005:07:04-18:43:34 (none) pluto[5170]: "D_Roadwarriors_0"[8] 84.158.17.34 #8: ignoring informational payload, type IPSEC_INITIAL_CONTACT
2005:07:04-18:43:34 (none) pluto[5170]: "D_Roadwarriors_0"[8] 84.158.17.34 #8: Main mode peer ID is ID_USER_FQDN: 'bareis@gmx.net'
2005:07:04-18:43:34 (none) pluto[5170]: "D_Roadwarriors_0"[8] 84.158.17.34 #8: Issuer CRL not found
2005:07:04-18:43:34 (none) pluto[5170]: "D_Roadwarriors_0"[8] 84.158.17.34 #8: Issuer CRL not found
2005:07:04-18:43:34 (none) pluto[5170]: "D_Roadwarriors_0"[8] 84.158.17.34 #8: transition from state STATE_MAIN_R2 to state STATE_MAIN_R3
2005:07:04-18:43:34 (none) pluto[5170]: "D_Roadwarriors_0"[8] 84.158.17.34 #8: sent MR3, ISAKMP SA established
2005:07:04-18:43:35 (none) pluto[5170]: "D_Roadwarriors_0"[8] 84.158.17.34 #8: received Delete SA payload: deleting ISAKMP State #8
2005:07:04-18:43:35 (none) pluto[5170]: "D_Roadwarriors_0"[8] 84.158.17.34: deleting connection "D_Roadwarriors_0" instance with peer 84.158.17.34
2005:07:04-18:43:35 (none) pluto[5170]: packet from 84.158.17.34:500: received and ignored informational message


This thread was automatically locked due to age.
Parents
  • Which version are you using?
    I'm using 5.9 which seems to be flawed due to a bug in the code which blocks critical traffic at the packet filter level.

    It's remarkable that the qc guys would let this product out the door with such problems.  I'm hoping that 6.001 has this fixed - otherwise, it appears that either there will be no IPsec  VPN use or I need to find a workaround for the problem.
Reply
  • Which version are you using?
    I'm using 5.9 which seems to be flawed due to a bug in the code which blocks critical traffic at the packet filter level.

    It's remarkable that the qc guys would let this product out the door with such problems.  I'm hoping that 6.001 has this fixed - otherwise, it appears that either there will be no IPsec  VPN use or I need to find a workaround for the problem.
Children
  • Hi,

    2005:07:04-18:33:42 (none) pluto[5170]: "D_Roadwarriors_0"[2] 84.158.17.34 #2: received Delete SA payload: deleting ISAKMP State #2

    client closing connection?

    Chris
  • 2005:07:04-18:33:41 (none) pluto[5170]: "D_Roadwarriors_0"[2] 84.158.17.34 #2: sent MR3, ISAKMP SA established
    2005:07:04-18:33:42 (none) pluto[5170]: "D_Roadwarriors_0"[2] 84.158.17.34 #2: received Delete SA payload: deleting ISAKMP State #2

    As soon as Phase 1 was established successfully, ASL receives a disconnect from the client. So have a look into the logfile of the client. There you should find the reason for the disconnect.
    If the packetfilter would drop some VPN packets, you should see that in the packet filter log. Look for packets with port 500 / 4500 or ESP protocol. 

    Xeno
  • ASL doesn't seem to work for vpn and the people here can't seem to help in any tangible way.  There are dozens of posts on your particular problem but no resolutions to be found anywhere.  My guess is that these people are over their heads with support problems and are unable to work with forum users or are unwilling to provide free support & are waiting for the frustration level to rise to the point that you give them money for their opinions and advice.

    I see no evidence of a professional quality vpn solution here.  Just frustration and dispair from the userbase.