Hi Guys
I'm in a pickle and need help.
We're moving offices tomorrow, and only today I learned that the ISP delivers NAT'ed Internet connectivity on the now location.
Abbreviations:
AGS-DC = Astaro at my Datacenter. Has public IP on its external i/f
AGS-OFC = Astaro in the new office. Has a 10.7.x.y address on external.
ISP-GW = Public address of ISP's NAT router.
Situation:
AGS-DC ---Internet--ISP-GW---10.7.x.0/24 - AGS-OFC
In AGS-DC I have added a "Host" definition for the Office AGS. The IP adress is the Public ISP-GW address.
Then, set up a remote key at both end, (psk) and of we go. Not...
The log at the AGS-DC shows:
"S_CW-VPN-WTC-Schiphol_0" #11673: transition from state STATE_MAIN_R0 to state STATE_MAIN_R1
"S_CW-VPN-WTC-Schiphol_0" #11673: STATE_MAIN_R1: sent MR1, expecting MI2
"S_CW-VPN-WTC-Schiphol_0" #11673: NAT-Traversal: Result using 3: peer is NATed
"S_CW-VPN-WTC-Schiphol_0" #11673: transition from state STATE_MAIN_R1 to state STATE_MAIN_R2
"S_CW-VPN-WTC-Schiphol_0" #11673: STATE_MAIN_R2: sent MR2, expecting MI3
"S_CW-VPN-WTC-Schiphol_0" #11673: Main mode peer ID is ID_IPV4_ADDR: '10.7.184.2'
"S_CW-VPN-WTC-Schiphol_0" #11673: no suitable connection for peer '10.7.184.2'
"S_CW-VPN-WTC-Schiphol_0" #11673: sending encrypted notification INVALID_ID_INFORMATION to 194.151.91.70:4500
"S_CW-VPN-WTC-Schiphol_0" #11673: Main mode peer ID is ID_IPV4_ADDR: '10.7.184.2'
"S_CW-VPN-WTC-Schiphol_0" #11673: no suitable connection for peer '10.7.184.2'
"S_CW-VPN-WTC-Schiphol_0" #11673: sending encrypted notification INVALID_ID_INFORMATION to 194.151.91.70:4500
"S_CW-VPN-WTC-Schiphol_0" #11673: Main mode peer ID is ID_IPV4_ADDR: '10.7.184.2'
"S_CW-VPN-WTC-Schiphol_0" #11673: no suitable connection for peer '10.7.184.2'
"S_CW-VPN-WTC-Schiphol_0" #11673: sending encrypted notification INVALID_ID_INFORMATION to 194.151.91.70:4500
So the AGS-DC is confused. It expects to talk to 194.151.92.70, but gets answer by 10.7.184.12 instead !
Obviously, I can't define the "10" network as remote gatweay, because that will get me a "no route to host" type of error.
So how do I get out of this situation. Is there a walk-through of how to approach this? I need to get this live by tomorrow COB...
Thanks
Hip
This thread was automatically locked due to age.