This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

ipsec tunnel asg120 to watchguard x750e

hello,

i have a problem with an ipsec tunnel between a asg120(firmware:7.404) and a watchguard x750e.

the tunnel is up, but i cant access anything through the tunnel. i have activated automatic packet filter.

here is the ipsec log:

2009:07:15-09:23:24 gw pluto[5057]: listening for IKE messages 
2009:07:15-09:23:24 gw pluto[5057]: adding interface ipsec0/eth1 80.248.200.26:500 
2009:07:15-09:23:24 gw pluto[5057]: loading secrets from "/etc/ipsec.secrets" 
2009:07:15-09:23:24 gw pluto[5057]: loaded shared key for 194.208.34.253 80.248.200.26 
2009:07:15-09:23:24 gw pluto[5057]: added connection description "S_Unknown Object" 
2009:07:15-09:23:24 gw pluto[5057]: "S_Unknown Object" #1: initiating Main Mode 
2009:07:15-09:23:24 gw pluto[5057]: "S_Unknown Object" #1: received Vendor ID payload [XAUTH] 
2009:07:15-09:23:24 gw pluto[5057]: "S_Unknown Object" #1: received Vendor ID payload [Dead Peer Detection] 
2009:07:15-09:23:24 gw pluto[5057]: "S_Unknown Object" #1: Peer ID is ID_IPV4_ADDR: '194.208.34.253' 
2009:07:15-09:23:24 gw pluto[5057]: "S_Unknown Object" #1: ISAKMP SA established 
2009:07:15-09:23:24 gw pluto[5057]: "S_Unknown Object" #2: initiating Quick Mode PSK+ENCRYPT+TUNNEL+UP {using isakmp#1} 
2009:07:15-09:23:24 gw pluto[5057]: "S_Unknown Object" #2: ignoring informational payload, type IPSEC_RESPONDER_LIFETIME 
2009:07:15-09:23:24 gw pluto[5057]: "S_Unknown Object" #2: Dead Peer Detection (RFC 3706) enabled 
2009:07:15-09:23:24 gw pluto[5057]: "S_Unknown Object" #2: sent QI2, IPsec SA established {ESP=>0x6db7c245 


This thread was automatically locked due to age.
Parents Reply
  • The only problem I can report having to do with Watchguard units is that they do not properly implement NAT-T, and there's no way to disable the negotiation of NAT-T on the Watchguard end.  Try disabling NAT Traversal (NAT-T) on the Astaro End (in the IPSEC config)... I had a ton of trouble at a client site that used Watchguards (now thankfully being replaced by Astaro units) to make connections to a central Astaro.
Children
No Data