This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

L2TP Connection Problem, Pattern Problem?

Hello,
since yesterday we have a problem to connect our box via L2TP. Is there a relation to the pattern updates?

We get the error 619 (no connection to the remote computer) on the clients.

ASG Version. 7.507, Pattern Version 20049

Here the log:
2010:08:31-09:10:13 asg-box pluto[3810]: "S_REF_IjTGbbqTZE_1"[41] xx.xx.xx.xx:4500 #1205: received Delete SA(0x8dab7367) payload: deleting IPSEC State #1206
2010:08:31-09:10:13 asg-box pluto[3810]: "S_REF_IjTGbbqTZE_1"[41] xx.xx.xx.xx:4500 #1205: deleting connection "S_REF_IjTGbbqTZE_0" instance with peer xx.xx.xx.xx {isakmp=#0/ipsec=#0}
2010:08:31-09:10:13 asg-box pluto[3810]: "S_REF_IjTGbbqTZE_1"[41] xx.xx.xx.xx:4500 #1205: received Delete SA payload: deleting ISAKMP State #1205
2010:08:31-09:10:13 asg-box pluto[3810]: "S_REF_IjTGbbqTZE_1"[41] xx.xx.xx.xx:4500: deleting connection "S_REF_IjTGbbqTZE_1" instance with peer xx.xx.xx.xx {isakmp=#0/ipsec=#0}
2010:08:31-09:11:15 asg-box pluto[3810]: packet from :500: ignoring Vendor ID payload [MS NT5 ISAKMPOAKLEY 00000004]
2010:08:31-09:11:15 asg-box pluto[3810]: packet from xx.xx.xx.xx:500: ignoring Vendor ID payload [FRAGMENTATION]
2010:08:31-09:11:15 asg-box pluto[3810]: packet from xx.xx.xx.xx:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n]
2010:08:31-09:11:15 asg-box pluto[3810]: packet from xx.xx.xx.xx:500: ignoring Vendor ID payload [Vid-Initial-Contact]
2010:08:31-09:11:15 asg-box pluto[3810]: "S_REF_IjTGbbqTZE_1"[42] xx.xx.xx.xx #1207: responding to Main Mode from unknown peer xx.xx.xx.xx
2010:08:31-09:11:15 asg-box pluto[3810]: packet from xx.xx.xx.xx:500: ignoring Vendor ID payload [MS NT5 ISAKMPOAKLEY 00000004]
2010:08:31-09:11:15 asg-box pluto[3810]: packet from xx.xx.xx.xx:500: ignoring Vendor ID payload [FRAGMENTATION]
2010:08:31-09:11:15 asg-box pluto[3810]: packet from xx.xx.xx.xx:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n]
2010:08:31-09:11:15 asg-box pluto[3810]: packet from xx.xx.xx.xx:500: ignoring Vendor ID payload [Vid-Initial-Contact]
2010:08:31-09:11:15 asg-box pluto[3810]: "S_REF_IjTGbbqTZE_1"[42] xx.xx.xx.xx #1208: responding to Main Mode from unknown peer xx.xx.xx.xx
2010:08:31-09:11:15 asg-box pluto[3810]: "S_REF_IjTGbbqTZE_1"[42] xx.xx.xx.xx #1207: NAT-Traversal: Result using draft-ietf-ipsec-nat-t-ike-02/03: peer is NATed
2010:08:31-09:11:15 asg-box pluto[3810]: "S_REF_IjTGbbqTZE_1"[42] xx.xx.xx.xx #1207: Peer ID is ID_FQDN: '@test.test.local'
2010:08:31-09:11:15 asg-box pluto[3810]: | NAT-T: new mapping xx.xx.xx.xx:500/4500)
2010:08:31-09:11:15 asg-box pluto[3810]: "S_REF_IjTGbbqTZE_1"[43] xx.xx.xx.xx:4500 #1207: sent MR3, ISAKMP SA established
2010:08:31-09:11:16 asg-box pluto[3810]: "S_REF_IjTGbbqTZE_0"[25] xx.xx.xx.xx:4500 #1209: responding to Quick Mode
2010:08:31-09:11:18 asg-box pluto[3810]: "S_REF_IjTGbbqTZE_0"[25] xx.xx.xx.xx:4500 #1209: IPsec SA established {ESP=>0x7c2757af 


This thread was automatically locked due to age.
Parents
  • This seems strange to me.  What client are you using?  Are you using a PSK or certs?  If certs, have you made any changes?

    The other thing that would be interesting would be to compare your log above to a connection session from last week's logs.

    Cheers - Bob
Reply
  • This seems strange to me.  What client are you using?  Are you using a PSK or certs?  If certs, have you made any changes?

    The other thing that would be interesting would be to compare your log above to a connection session from last week's logs.

    Cheers - Bob
Children
No Data