IPSec net-to-net problem

Mike Beirne <[email protected]>
Newsgroups gmane.comp.security.ipcop.devel
Message-ID <[email protected]>
Hello,

I have two IPCop 2.0.1 boxes installed and am trying to set up a
net-to-net connection.

I go onto IPCop #1, ipsec->add, choose "net-to-net" and have it create a
certificate for the other host to use, download the pkcs12 file onto a
USB drive.

Then go to IPCop #2, go into ipsec->add, choose net-to-net and then
choose upload PKCS12 file from the USB drive.

This doesn't work.

Both sides expect the other side to be using the certificate from the
USB drive and both have added:
        leftcert=/var/ipcop/certs/hostcert.pem
        rightcert=/var/ipcop/certs/test10cert.pem
And the connection fails with "INVALID_ID_INFORMATION".

Okay, then I download the "host certificate" from the "VPNs->CA" page on
each and again go through setting up a net-to-net VPN, this time
choosing the "Upload a certificate" and choose the host certificate from
the other IPCop box and Success!!, it works to create the VPN.
I didn't delete the CA certificate, imported when the PKCS12
certificates were imported, so that may be a necessary step too.
I can then ping from a host on the IPCop #1 "green" to a host on the
IPCop #2 "green" network. But I cannot ping back as I used the Blue
network on IPCop #1 and again get:
"Nov  7 22:52:19 ipcop2 kernel: BLUE REJECT IN=wlan-1 OUT=lan-1
SRC=192.168.68.204 DST=192.168.69.12 LEN=84 TOS=0x00 PREC=0x00 TTL=62
ID=0 DF PROTO=ICMP TYPE=8 CODE=0 ID=11936 SEQ=50"

So this test proves that the firewall rules are not correctly modified
when an IPSec tunnel on the Blue network comes up.

When I get this all working, I am going to publish a tutorial on my web
site going through all of the steps, including real world examples of
site to site and Ubuntu road warrior IPSec configurations. Too many of
the tutorials that I have found don't use certificates or only have test
lab configurations that simplify so much that they don't work for sites
using NAT. Right now, I am using dynamic DNS names so that each side can
find the IP address of the other, and will have to include that in the
examples too.

Mike

------------------------------------------------------------------------------
RSA(R) Conference 2012
Save $700 by Nov 18
Register now
http://p.sf.net/sfu/rsa-sfdev2dev1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.