A problem in a Cisco VPN client connection to a Cisco Pix using X509 certificates
"Benkirane Youssef" <[email protected]>
| Newsgroups | gmane.comp.security.vpn |
|---|---|
| Message-ID | <000001c3fadf$7478ca30$2f1ac289@Youssef> |
Hi, I have a cisco Pix 515. The wan interface is connected behind an internet Link. When I try to connect with a cisco VPN client 3.6.3 to the PIX using certificate. The ISAKMP authentication blocks. The IPSEC log viewer shows that the message SENDING >>> ISAKMP OAK MM *(ID, CERT, CERT_REQ, SIG, NOTIFY:STATUS_INITIAL_CONTACT) to 217.128.150.77, has no response from the PIX. Does someone have a diagnostic for this problem? Thank you by advance Youssef Those are the whole logs of the VPN client. 1 11:58:33.134 02/24/04 Sev=Info/6 DIALER/0x63300002 Initiating connection. 2 11:58:33.134 02/24/04 Sev=Info/4 CM/0x63100002 Begin connection process 3 11:58:33.144 02/24/04 Sev=Info/4 CM/0x63100004 Establish secure connection using Ethernet 4 11:58:33.144 02/24/04 Sev=Info/4 CM/0x63100026 Attempt connection with server "217.128.150.77" 5 11:58:33.144 02/24/04 Sev=Info/6 IKE/0x6300003B Attempting to establish a connection with 217.128.150.77. 6 11:58:33.204 02/24/04 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK MM (SA, VID, VID, VID, VID, VID) to 217.128.150.77 7 11:58:34.035 02/24/04 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 8 11:58:38.241 02/24/04 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK MM (Retransmission) to 217.128.150.77 9 11:58:43.248 02/24/04 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK MM (Retransmission) to 217.128.150.77 10 11:58:48.256 02/24/04 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK MM (Retransmission) to 217.128.150.77 11 11:58:48.306 02/24/04 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 217.128.150.77 12 11:58:48.306 02/24/04 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK MM (SA, VID, VID) from 217.128.150.77 13 11:58:48.316 02/24/04 Sev=Info/5 IKE/0x63000059 Vendor ID payload = 7D9419A65310CA6F2C179D9215529D56 14 11:58:48.316 02/24/04 Sev=Info/5 IKE/0x63000059 Vendor ID payload = 90CB80913EBB696E086381B5EC427B1F 15 11:58:48.316 02/24/04 Sev=Info/5 IKE/0x63000001 Peer supports NAT-T 16 11:58:48.316 02/24/04 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK MM (KE, NON, NAT-D, NAT-D) to 217.128.150.77 17 11:58:48.416 02/24/04 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 217.128.150.77 18 11:58:48.416 02/24/04 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK MM (KE, NON, CERT_REQ, VID, VID, VID, VID, NAT-D, NAT-D) from 217.128.150.77 19 11:58:48.416 02/24/04 Sev=Info/5 IKE/0x63000059 Vendor ID payload = 09002689DFD6B712 20 11:58:48.416 02/24/04 Sev=Info/5 IKE/0x63000001 Peer supports XAUTH 21 11:58:48.416 02/24/04 Sev=Info/5 IKE/0x63000059 Vendor ID payload = AFCAD71368A1F1C96B8696FC77570100 22 11:58:48.416 02/24/04 Sev=Info/5 IKE/0x63000001 Peer supports DPD 23 11:58:48.416 02/24/04 Sev=Info/5 IKE/0x63000059 Vendor ID payload = 12F5F28C457168A9702D9FE274CC0100 24 11:58:48.416 02/24/04 Sev=Info/5 IKE/0x63000001 Peer is a Cisco-Unity compliant peer 25 11:58:48.416 02/24/04 Sev=Info/5 IKE/0x63000059 Vendor ID payload = B11B2FEEE3184CADFA563C07828BFA2F 26 11:58:48.506 02/24/04 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK MM *(ID, CERT, CERT_REQ, SIG, NOTIFY:STATUS_INITIAL_CONTACT) to 217.128.150.77 27 11:58:53.513 02/24/04 Sev=Warning/2 IKE/0xE300007C Exceeded 3 IKE SA negotiation retransmits... peer is not responding 28 11:58:53.513 02/24/04 Sev=Info/4 CM/0x63100014 Unable to establish Phase 1 SA with server "217.128.150.77" because of "DEL_REASON_PEER_NOT_RESPONDING" 29 11:58:53.513 02/24/04 Sev=Info/5 CM/0x63100029 Initializing CVPNDrv 30 11:58:53.563 02/24/04 Sev=Warning/3 DIALER/0xE3300008 GI VPNStart callback failed "CM_PEER_NOT_RESPONDING" (16h). 31 11:58:54.575 02/24/04 Sev=Info/4 IPSEC/0x63700014 Deleted all keys _______________________________________________ VPN mailing list [email protected] http://lists.shmoo.com/mailman/listinfo/vpn
Config_Pix.txt
(text/plain, 5.5 KB)
devernois# sh run : Saved : PIX Version 6.3(1) interface ethernet0 auto interface ethernet1 auto interface ethernet2 auto nameif ethernet0 outside security0 nameif ethernet1 inside security100 nameif ethernet2 DMZ security10 enable password 55mL3Sy2t8ppawHj encrypted passwd 2KFQnbNIdI.2KYOU encrypted hostname devernois domain-name mystream.org fixup protocol ftp 21 fixup protocol h323 h225 1720 fixup protocol h323 ras 1718-1719 fixup protocol http 80 fixup protocol ils 389 fixup protocol rsh 514 fixup protocol rtsp 554 fixup protocol sip 5060 fixup protocol sip udp 5060 fixup protocol skinny 2000 fixup protocol smtp 25 fixup protocol sqlnet 1521 names object-group network LAN network-object 192.9.200.0 255.255.255.0 object-group network DMZ network-object 192.168.20.0 255.255.255.0 access-list OUTSIDE permit tcp any interface outside eq www access-list LAN_Split_Access permit ip 192.9.200.0 255.255.255.0 any access-list LAN_Split_Access permit ip 192.168.20.0 255.255.255.0 any access-list inside_access permit ip 192.9.200.0 255.255.255.0 192.168.50.0 255.255.255.0 access-list ICMP permit icmp any any echo-reply access-list DMZ_nat permit ip 192.168.20.0 255.255.255.0 192.168.253.0 255.255.255.0 access-list DMZ_nat permit ip 192.168.20.0 255.255.255.0 192.168.50.0 255.255.255.0 access-list NONAT permit ip 192.9.200.0 255.255.255.0 192.168.50.0 255.255.255.0 pager lines 30 logging on logging timestamp logging buffered informational logging trap informational logging history informational logging facility 21 icmp permit any echo outside icmp permit any unreachable outside icmp permit any echo-reply outside icmp permit any time-exceeded outside icmp permit any echo DMZ icmp permit any echo-reply DMZ mtu outside 1500 mtu inside 1500 mtu DMZ 1500 ip address outside 192.168.1.254 255.255.255.0 ip address inside 192.9.200.7 255.255.255.0 ip address DMZ 192.168.20.254 255.255.255.0 ip verify reverse-path interface outside ip verify reverse-path interface DMZ ip audit info action alarm ip audit attack action alarm ip local pool Marboeuf 192.168.50.1 ip local pool Supervision 192.168.253.1 pdm location 192.168.3.1 255.255.255.255 inside pdm location 137.194.26.0 255.255.254.0 outside pdm location 192.9.200.232 255.255.255.255 inside pdm location 192.168.20.1 255.255.255.255 DMZ pdm location 137.194.26.46 255.255.255.255 outside pdm location 217.128.150.78 255.255.255.255 outside pdm history enable arp timeout 14400 nat (inside) 0 access-list NONAT nat (DMZ) 0 access-list DMZ_nat static (DMZ,outside) tcp interface www 192.168.20.1 www netmask 255.255.255.255 0 0 access-group OUTSIDE in interface outside access-group inside_access in interface inside route outside 0.0.0.0 0.0.0.0 192.168.1.1 1 timeout xlate 3:00:00 timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00 timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00 timeout uauth 0:05:00 absolute aaa-server TACACS+ protocol tacacs+ aaa-server RADIUS protocol radius aaa-server LOCAL protocol local aaa authentication ssh console LOCAL ntp server 152.81.1.12 source outside prefer http server enable http 137.194.26.0 255.255.254.0 outside http 192.168.3.1 255.255.255.255 inside http 192.9.200.232 255.255.255.255 inside no snmp-server location no snmp-server contact snmp-server community public no snmp-server enable traps floodguard enable sysopt connection permit-ipsec crypto ipsec transform-set MYSTREAM-TRANSFORM-SET esp-des esp-md5-hmac crypto ipsec security-association lifetime seconds 1200 crypto dynamic-map MYSTREAM-CRYPTO-DYN 10 set transform-set MYSTREAM-TRANSFORM-SET crypto dynamic-map MYSTREAM-CRYPTO-DYN 10 set security-association lifetime seconds 18000 kilobytes 4608000 crypto map MYSTREAM-CHIFFREMENT 65535 ipsec-isakmp dynamic MYSTREAM-CRYPTO-DYN crypto map MYSTREAM-CHIFFREMENT client authentication LOCAL crypto map MYSTREAM-CHIFFREMENT interface outside isakmp enable outside isakmp key ******** address 0.0.0.0 netmask 0.0.0.0 isakmp keepalive 10 isakmp nat-traversal 10 isakmp policy 1 authentication pre-share isakmp policy 1 encryption 3des isakmp policy 1 hash md5 isakmp policy 1 group 2 isakmp policy 1 lifetime 1000 isakmp policy 5 authentication rsa-sig isakmp policy 5 encryption des isakmp policy 5 hash md5 isakmp policy 5 group 1 isakmp policy 5 lifetime 3600 isakmp policy 10 authentication rsa-sig isakmp policy 10 encryption des isakmp policy 10 hash sha isakmp policy 10 group 1 isakmp policy 10 lifetime 36000 isakmp policy 15 authentication pre-share isakmp policy 15 encryption 3des isakmp policy 15 hash md5 isakmp policy 15 group 1 isakmp policy 15 lifetime 86400 vpngroup Marboeuf address-pool Marboeuf vpngroup Marboeuf idle-time 1800 vpngroup Supervision address-pool Supervision vpngroup Supervision split-tunnel LAN_Split_Access vpngroup Supervision idle-time 1800 ca identity devernoisca 192.168.20.1:/certsrv/mscep/mscep.dll ca configure devernoisca ra 20 5 crloptional telnet 192.168.253.1 255.255.255.255 inside telnet timeout 60 ssh 137.194.26.0 255.255.254.0 outside ssh 217.128.150.78 255.255.255.255 outside ssh 137.194.26.46 255.255.255.255 outside ssh 192.168.253.1 255.255.255.255 outside ssh 192.168.1.1 255.255.255.255 outside ssh 192.168.253.1 255.255.255.255 inside ssh 192.168.50.1 255.255.255.255 inside ssh 192.168.20.0 255.255.255.0 DMZ ssh timeout 60 management-access inside console timeout 0 username DEVERNOIS password Hn3kLFsHo2vgxJAg encrypted privilege 2 username Mystream password iN5YsityeK09FteP encrypted privilege 2 username pixadmin password w0uKSedXcuoUpAoY encrypted privilege 2 terminal width 80 Cryptochecksum:657790aeb8f580ea44b6adb23afc72fd : end