A problem in a Cisco VPN client connection to a Cisco Pix using X509 certificates

"Benkirane Youssef" <[email protected]>
Newsgroups gmane.comp.security.vpn
Message-ID <000001c3fadf$7478ca30$2f1ac289@Youssef>
Hi,

 

I have a cisco Pix 515. The wan interface is connected behind an internet
Link.

When I try to connect with a cisco VPN client 3.6.3 to the PIX using
certificate. The ISAKMP authentication blocks.

The IPSEC log viewer shows that the message SENDING >>> ISAKMP OAK MM *(ID,
CERT, CERT_REQ, SIG, NOTIFY:STATUS_INITIAL_CONTACT) to 217.128.150.77, has
no response from the PIX.

Does someone have a diagnostic for this problem? 

 

Thank you by advance

Youssef

 

Those are the whole logs of the VPN client.

 

 

 

1      11:58:33.134  02/24/04  Sev=Info/6           DIALER/0x63300002

Initiating connection.

 

2      11:58:33.134  02/24/04  Sev=Info/4           CM/0x63100002

Begin connection process

 

3      11:58:33.144  02/24/04  Sev=Info/4           CM/0x63100004

Establish secure connection using Ethernet

 

4      11:58:33.144  02/24/04  Sev=Info/4           CM/0x63100026

Attempt connection with server "217.128.150.77"

 

5      11:58:33.144  02/24/04  Sev=Info/6           IKE/0x6300003B

Attempting to establish a connection with 217.128.150.77.

 

6      11:58:33.204  02/24/04  Sev=Info/4           IKE/0x63000013

SENDING >>> ISAKMP OAK MM (SA, VID, VID, VID, VID, VID) to 217.128.150.77

 

7      11:58:34.035  02/24/04  Sev=Info/4           IPSEC/0x63700014

Deleted all keys

 

8      11:58:38.241  02/24/04  Sev=Info/4           IKE/0x63000013

SENDING >>> ISAKMP OAK MM (Retransmission) to 217.128.150.77

 

9      11:58:43.248  02/24/04  Sev=Info/4           IKE/0x63000013

SENDING >>> ISAKMP OAK MM (Retransmission) to 217.128.150.77

 

10     11:58:48.256  02/24/04  Sev=Info/4          IKE/0x63000013

SENDING >>> ISAKMP OAK MM (Retransmission) to 217.128.150.77

 

11     11:58:48.306  02/24/04  Sev=Info/5          IKE/0x6300002F

Received ISAKMP packet: peer = 217.128.150.77

 

12     11:58:48.306  02/24/04  Sev=Info/4          IKE/0x63000014

RECEIVING <<< ISAKMP OAK MM (SA, VID, VID) from 217.128.150.77

 

13     11:58:48.316  02/24/04  Sev=Info/5          IKE/0x63000059

Vendor ID payload = 7D9419A65310CA6F2C179D9215529D56

 

14     11:58:48.316  02/24/04  Sev=Info/5          IKE/0x63000059

Vendor ID payload = 90CB80913EBB696E086381B5EC427B1F

 

15     11:58:48.316  02/24/04  Sev=Info/5          IKE/0x63000001

Peer supports NAT-T

 

16     11:58:48.316  02/24/04  Sev=Info/4          IKE/0x63000013

SENDING >>> ISAKMP OAK MM (KE, NON, NAT-D, NAT-D) to 217.128.150.77

 

17     11:58:48.416  02/24/04  Sev=Info/5          IKE/0x6300002F

Received ISAKMP packet: peer = 217.128.150.77

 

18     11:58:48.416  02/24/04  Sev=Info/4          IKE/0x63000014

RECEIVING <<< ISAKMP OAK MM (KE, NON, CERT_REQ, VID, VID, VID, VID, NAT-D,
NAT-D) from 217.128.150.77

 

19     11:58:48.416  02/24/04  Sev=Info/5          IKE/0x63000059

Vendor ID payload = 09002689DFD6B712

 

20     11:58:48.416  02/24/04  Sev=Info/5          IKE/0x63000001

Peer supports XAUTH

 

21     11:58:48.416  02/24/04  Sev=Info/5          IKE/0x63000059

Vendor ID payload = AFCAD71368A1F1C96B8696FC77570100

 

22     11:58:48.416  02/24/04  Sev=Info/5          IKE/0x63000001

Peer supports DPD

 

23     11:58:48.416  02/24/04  Sev=Info/5          IKE/0x63000059

Vendor ID payload = 12F5F28C457168A9702D9FE274CC0100

 

24     11:58:48.416  02/24/04  Sev=Info/5          IKE/0x63000001

Peer is a Cisco-Unity compliant peer

 

25     11:58:48.416  02/24/04  Sev=Info/5          IKE/0x63000059

Vendor ID payload = B11B2FEEE3184CADFA563C07828BFA2F

 

26     11:58:48.506  02/24/04  Sev=Info/4          IKE/0x63000013

SENDING >>> ISAKMP OAK MM *(ID, CERT, CERT_REQ, SIG,
NOTIFY:STATUS_INITIAL_CONTACT) to 217.128.150.77

 

27     11:58:53.513  02/24/04  Sev=Warning/2   IKE/0xE300007C

Exceeded 3 IKE SA negotiation retransmits... peer is not responding

 

28     11:58:53.513  02/24/04  Sev=Info/4          CM/0x63100014

Unable to establish Phase 1 SA with server "217.128.150.77" because of
"DEL_REASON_PEER_NOT_RESPONDING"

 

29     11:58:53.513  02/24/04  Sev=Info/5          CM/0x63100029

Initializing CVPNDrv

 

30     11:58:53.563  02/24/04  Sev=Warning/3   DIALER/0xE3300008

GI VPNStart callback failed "CM_PEER_NOT_RESPONDING" (16h).

 

31     11:58:54.575  02/24/04  Sev=Info/4          IPSEC/0x63700014

Deleted all keys

_______________________________________________
VPN mailing list
[email protected]
http://lists.shmoo.com/mailman/listinfo/vpn
Config_Pix.txt (text/plain, 5.5 KB)
devernois# sh run
: Saved
:
PIX Version 6.3(1)
interface ethernet0 auto
interface ethernet1 auto
interface ethernet2 auto
nameif ethernet0 outside security0
nameif ethernet1 inside security100
nameif ethernet2 DMZ security10
enable password 55mL3Sy2t8ppawHj encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
hostname devernois
domain-name mystream.org
fixup protocol ftp 21
fixup protocol h323 h225 1720
fixup protocol h323 ras 1718-1719
fixup protocol http 80
fixup protocol ils 389
fixup protocol rsh 514
fixup protocol rtsp 554
fixup protocol sip 5060
fixup protocol sip udp 5060
fixup protocol skinny 2000
fixup protocol smtp 25
fixup protocol sqlnet 1521
names
object-group network LAN
  network-object 192.9.200.0 255.255.255.0
object-group network DMZ
  network-object 192.168.20.0 255.255.255.0
access-list OUTSIDE permit tcp any interface outside eq www
access-list LAN_Split_Access permit ip 192.9.200.0 255.255.255.0 any
access-list LAN_Split_Access permit ip 192.168.20.0 255.255.255.0 any
access-list inside_access permit ip 192.9.200.0 255.255.255.0 192.168.50.0 255.255.255.0
access-list ICMP permit icmp any any echo-reply
access-list DMZ_nat permit ip 192.168.20.0 255.255.255.0 192.168.253.0 255.255.255.0
access-list DMZ_nat permit ip 192.168.20.0 255.255.255.0 192.168.50.0 255.255.255.0
access-list NONAT permit ip 192.9.200.0 255.255.255.0 192.168.50.0 255.255.255.0
pager lines 30
logging on
logging timestamp
logging buffered informational
logging trap informational
logging history informational
logging facility 21
icmp permit any echo outside
icmp permit any unreachable outside
icmp permit any echo-reply outside
icmp permit any time-exceeded outside
icmp permit any echo DMZ
icmp permit any echo-reply DMZ
mtu outside 1500
mtu inside 1500
mtu DMZ 1500
ip address outside 192.168.1.254 255.255.255.0
ip address inside 192.9.200.7 255.255.255.0
ip address DMZ 192.168.20.254 255.255.255.0
ip verify reverse-path interface outside
ip verify reverse-path interface DMZ
ip audit info action alarm
ip audit attack action alarm
ip local pool Marboeuf 192.168.50.1
ip local pool Supervision 192.168.253.1
pdm location 192.168.3.1 255.255.255.255 inside
pdm location 137.194.26.0 255.255.254.0 outside
pdm location 192.9.200.232 255.255.255.255 inside
pdm location 192.168.20.1 255.255.255.255 DMZ
pdm location 137.194.26.46 255.255.255.255 outside
pdm location 217.128.150.78 255.255.255.255 outside
pdm history enable
arp timeout 14400
nat (inside) 0 access-list NONAT
nat (DMZ) 0 access-list DMZ_nat
static (DMZ,outside) tcp interface www 192.168.20.1 www netmask 255.255.255.255 0 0
access-group OUTSIDE in interface outside
access-group inside_access in interface inside
route outside 0.0.0.0 0.0.0.0 192.168.1.1 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00
timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
aaa-server TACACS+ protocol tacacs+
aaa-server RADIUS protocol radius
aaa-server LOCAL protocol local
aaa authentication ssh console LOCAL
ntp server 152.81.1.12 source outside prefer
http server enable
http 137.194.26.0 255.255.254.0 outside
http 192.168.3.1 255.255.255.255 inside
http 192.9.200.232 255.255.255.255 inside
no snmp-server location
no snmp-server contact
snmp-server community public
no snmp-server enable traps
floodguard enable
sysopt connection permit-ipsec
crypto ipsec transform-set MYSTREAM-TRANSFORM-SET esp-des esp-md5-hmac
crypto ipsec security-association lifetime seconds 1200
crypto dynamic-map MYSTREAM-CRYPTO-DYN 10 set transform-set MYSTREAM-TRANSFORM-SET
crypto dynamic-map MYSTREAM-CRYPTO-DYN 10 set security-association lifetime seconds 18000 kilobytes 4608000
crypto map MYSTREAM-CHIFFREMENT 65535 ipsec-isakmp dynamic MYSTREAM-CRYPTO-DYN
crypto map MYSTREAM-CHIFFREMENT client authentication LOCAL
crypto map MYSTREAM-CHIFFREMENT interface outside
isakmp enable outside
isakmp key ******** address 0.0.0.0 netmask 0.0.0.0
isakmp keepalive 10
isakmp nat-traversal 10
isakmp policy 1 authentication pre-share
isakmp policy 1 encryption 3des
isakmp policy 1 hash md5
isakmp policy 1 group 2
isakmp policy 1 lifetime 1000
isakmp policy 5 authentication rsa-sig
isakmp policy 5 encryption des
isakmp policy 5 hash md5
isakmp policy 5 group 1
isakmp policy 5 lifetime 3600
isakmp policy 10 authentication rsa-sig
isakmp policy 10 encryption des
isakmp policy 10 hash sha
isakmp policy 10 group 1
isakmp policy 10 lifetime 36000
isakmp policy 15 authentication pre-share
isakmp policy 15 encryption 3des
isakmp policy 15 hash md5
isakmp policy 15 group 1
isakmp policy 15 lifetime 86400
vpngroup Marboeuf address-pool Marboeuf
vpngroup Marboeuf idle-time 1800
vpngroup Supervision address-pool Supervision
vpngroup Supervision split-tunnel LAN_Split_Access
vpngroup Supervision idle-time 1800
ca identity devernoisca 192.168.20.1:/certsrv/mscep/mscep.dll
ca configure devernoisca ra 20 5 crloptional
telnet 192.168.253.1 255.255.255.255 inside
telnet timeout 60
ssh 137.194.26.0 255.255.254.0 outside
ssh 217.128.150.78 255.255.255.255 outside
ssh 137.194.26.46 255.255.255.255 outside
ssh 192.168.253.1 255.255.255.255 outside
ssh 192.168.1.1 255.255.255.255 outside
ssh 192.168.253.1 255.255.255.255 inside
ssh 192.168.50.1 255.255.255.255 inside
ssh 192.168.20.0 255.255.255.0 DMZ
ssh timeout 60
management-access inside
console timeout 0
username DEVERNOIS password Hn3kLFsHo2vgxJAg encrypted privilege 2
username Mystream password iN5YsityeK09FteP encrypted privilege 2
username pixadmin password w0uKSedXcuoUpAoY encrypted privilege 2
terminal width 80
Cryptochecksum:657790aeb8f580ea44b6adb23afc72fd
: end
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.