RE : A problem in a Cisco VPN client connection to a Cisco Pixusing X509 certificates

"Benkirane Youssef" <[email protected]>
Newsgroups gmane.comp.security.vpn
Message-ID <001101c3fb8a$79cea3f0$2f1ac289@Youssef>
Yes, i think so.

i installed the pix own certificate using the following steps.

 

ca identity devernoisca 192.168.20.1:/certsrv/mscep/mscep.dll

ca configure devernoisca ra 20 5 crloptional

ca authenticate devernoisca (to authenticate the authority)

ca enroll devernoisca (to get the pix own certificate)

 

did you see the file (sh_ca_certificate)?

 

-----Message d'origine-----
De : Andrew Prince [mailto:[email protected]] 
Envoyé : mercredi 25 février 2004 11:20
À : 'Benkirane Youssef'
Objet : RE: [VPN] A problem in a Cisco VPN client connection to a Cisco
Pixusing X509 certificates

 

1) Has the PIX got it's own cert?

 

2) The PIX needs to authenticate the CA by obtaining the CA's self-signed
certificate which contains the CA's public key. Because the CA signs its own
certificate, the CA's public key should be authenticated .

 

  _____  

From: Benkirane Youssef [mailto:[email protected]] 
Sent: 25 February 2004 10:15
To: [email protected]
Subject: RE : [VPN] A problem in a Cisco VPN client connection to a Cisco
Pixusing X509 certificates

Yes,

 

In fact, i use a windows 2000 server certificate authority, with mscep
enrollement.

To help you, here are the logs of the pix (Pix_Logs.txt) while a connection
attempt using certificate.

Also a show ca certificate and a screen copy of the cisco client certificate
that I’m using to connect to the pix.

 

Thanks for your help

 

 

-----Message d'origine-----
De : Andrew Prince [mailto:[email protected]] 
Envoyé : mercredi 25 février 2004 10:29
À : 'Benkirane Youssef'
Objet : RE: [VPN] A problem in a Cisco VPN client connection to a Cisco
Pixusing X509 certificates

 

Ah - you didn't say that!!  Have you configured the PIX to use the same
Certificate Authority that the client certificate came from??

 

  _____  

From: Benkirane Youssef [mailto:[email protected]] 
Sent: 25 February 2004 09:12
To: [email protected]
Subject: RE : [VPN] A problem in a Cisco VPN client connection to a Cisco
Pixusing X509 certificates

Hi,

 

I don’t think that is the problem, because a vpn connection with preshared
keys works!

 

Youssef

 

-----Message d'origine-----
De : Andrew Prince [mailto:[email protected]] 
Envoyé : mardi 24 février 2004 20:18
À : 'Benkirane Youssef'
Objet : RE: [VPN] A problem in a Cisco VPN client connection to a Cisco
Pixusing X509 certificates

 

Youssef,

 

Ignore last mail - did not see the attachement.  the reason why it doesn't
work is you have an access-list on the inbound traffic in the outside
interface, you are only alowing www (tcp port 80) into the PIX.  You will
have to allow UDP500 (ISAKMP) ipsec (protocol 50) 

 

HTH,

Andy

 

  _____  

From: [email protected]
[mailto:[email protected]] On
Behalf Of Benkirane Youssef
Sent: 24 February 2004 14:07
To: [email protected]
Subject: [VPN] A problem in a Cisco VPN client connection to a Cisco
Pixusing X509 certificates

Hi,

 

I have a cisco Pix 515. The wan interface is connected behind an internet
Link.

When I try to connect with a cisco VPN client 3.6.3 to the PIX using
certificate. The ISAKMP authentication blocks.

The IPSEC log viewer shows that the message SENDING >>> ISAKMP OAK MM *(ID,
CERT, CERT_REQ, SIG, NOTIFY:STATUS_INITIAL_CONTACT) to 217.128.150.77, has
no response from the PIX.

Does someone have a diagnostic for this problem? 

 

Thank you by advance

Youssef

 

Those are the whole logs of the VPN client.

 

 

 

1      11:58:33.134  02/24/04  Sev=Info/6           DIALER/0x63300002

Initiating connection.

 

2      11:58:33.134  02/24/04  Sev=Info/4           CM/0x63100002

Begin connection process

 

3      11:58:33.144  02/24/04  Sev=Info/4           CM/0x63100004

Establish secure connection using Ethernet

 

4      11:58:33.144  02/24/04  Sev=Info/4           CM/0x63100026

Attempt connection with server "217.128.150.77"

 

5      11:58:33.144  02/24/04  Sev=Info/6           IKE/0x6300003B

Attempting to establish a connection with 217.128.150.77.

 

6      11:58:33.204  02/24/04  Sev=Info/4           IKE/0x63000013

SENDING >>> ISAKMP OAK MM (SA, VID, VID, VID, VID, VID) to 217.128.150.77

 

7      11:58:34.035  02/24/04  Sev=Info/4           IPSEC/0x63700014

Deleted all keys

 

8      11:58:38.241  02/24/04  Sev=Info/4           IKE/0x63000013

SENDING >>> ISAKMP OAK MM (Retransmission) to 217.128.150.77

 

9      11:58:43.248  02/24/04  Sev=Info/4           IKE/0x63000013

SENDING >>> ISAKMP OAK MM (Retransmission) to 217.128.150.77

 

10     11:58:48.256  02/24/04  Sev=Info/4          IKE/0x63000013

SENDING >>> ISAKMP OAK MM (Retransmission) to 217.128.150.77

 

11     11:58:48.306  02/24/04  Sev=Info/5          IKE/0x6300002F

Received ISAKMP packet: peer = 217.128.150.77

 

12     11:58:48.306  02/24/04  Sev=Info/4          IKE/0x63000014

RECEIVING <<< ISAKMP OAK MM (SA, VID, VID) from 217.128.150.77

 

13     11:58:48.316  02/24/04  Sev=Info/5          IKE/0x63000059

Vendor ID payload = 7D9419A65310CA6F2C179D9215529D56

 

14     11:58:48.316  02/24/04  Sev=Info/5          IKE/0x63000059

Vendor ID payload = 90CB80913EBB696E086381B5EC427B1F

 

15     11:58:48.316  02/24/04  Sev=Info/5          IKE/0x63000001

Peer supports NAT-T

 

16     11:58:48.316  02/24/04  Sev=Info/4          IKE/0x63000013

SENDING >>> ISAKMP OAK MM (KE, NON, NAT-D, NAT-D) to 217.128.150.77

 

17     11:58:48.416  02/24/04  Sev=Info/5          IKE/0x6300002F

Received ISAKMP packet: peer = 217.128.150.77

 

18     11:58:48.416  02/24/04  Sev=Info/4          IKE/0x63000014

RECEIVING <<< ISAKMP OAK MM (KE, NON, CERT_REQ, VID, VID, VID, VID, NAT-D,
NAT-D) from 217.128.150.77

 

19     11:58:48.416  02/24/04  Sev=Info/5          IKE/0x63000059

Vendor ID payload = 09002689DFD6B712

 

20     11:58:48.416  02/24/04  Sev=Info/5          IKE/0x63000001

Peer supports XAUTH

 

21     11:58:48.416  02/24/04  Sev=Info/5          IKE/0x63000059

Vendor ID payload = AFCAD71368A1F1C96B8696FC77570100

 

22     11:58:48.416  02/24/04  Sev=Info/5          IKE/0x63000001

Peer supports DPD

 

23     11:58:48.416  02/24/04  Sev=Info/5          IKE/0x63000059

Vendor ID payload = 12F5F28C457168A9702D9FE274CC0100

 

24     11:58:48.416  02/24/04  Sev=Info/5          IKE/0x63000001

Peer is a Cisco-Unity compliant peer

 

25     11:58:48.416  02/24/04  Sev=Info/5          IKE/0x63000059

Vendor ID payload = B11B2FEEE3184CADFA563C07828BFA2F

 

26     11:58:48.506  02/24/04  Sev=Info/4          IKE/0x63000013

SENDING >>> ISAKMP OAK MM *(ID, CERT, CERT_REQ, SIG,
NOTIFY:STATUS_INITIAL_CONTACT) to 217.128.150.77

 

27     11:58:53.513  02/24/04  Sev=Warning/2   IKE/0xE300007C

Exceeded 3 IKE SA negotiation retransmits... peer is not responding

 

28     11:58:53.513  02/24/04  Sev=Info/4          CM/0x63100014

Unable to establish Phase 1 SA with server "217.128.150.77" because of
"DEL_REASON_PEER_NOT_RESPONDING"

 

29     11:58:53.513  02/24/04  Sev=Info/5          CM/0x63100029

Initializing CVPNDrv

 

30     11:58:53.563  02/24/04  Sev=Warning/3   DIALER/0xE3300008

GI VPNStart callback failed "CM_PEER_NOT_RESPONDING" (16h).

 

31     11:58:54.575  02/24/04  Sev=Info/4          IPSEC/0x63700014

Deleted all keys

_______________________________________________
VPN mailing list
[email protected]
http://lists.shmoo.com/mailman/listinfo/vpn
Pix_Logs.txt (text/plain, 5.1 KB)
ISAKMP (0): processing SA payload. message ID = 0

ISAKMP (0): Checking ISAKMP transform 1 against priority 1 policy
ISAKMP:      encryption AES-CBC
ISAKMP:      hash SHA
ISAKMP:      default group 5
ISAKMP:      extended auth RSA sig (init)
ISAKMP:      life type in seconds
ISAKMP:      life duration (VPI) of  0x0 0x20 0xc4 0x9b
ISAKMP:      keylength of 256
ISAKMP (0): atts are not acceptable. Next payload is 3
ISAKMP (0): Checking ISAKMP transform 2 against priority 1 policy
ISAKMP:      encryption AES-CBC
ISAKMP:      hash MD5
ISAKMP:      default group 5
ISAKMP:      extended auth RSA sig (init)
ISAKMP:      life type in seconds
ISAKMP:      life duration (VPI) of  0x0 0x20 0xc4 0x9b
ISAKMP:      keylength of 256
ISAKMP (0): atts are not acceptable. Next payload is 3
ISAKMP (0): Checking ISAKMP transform 3 against priority 1 policy
ISAKMP:      encryption AES-CBC
ISAKMP:      hash SHA
ISAKMP:      default group 5
ISAKMP:      auth RSA sig
ISAKMP:      life type in seconds
ISAKMP:      life duration (VPI) of  0x0 0x20 0xc4 0x9b
ISAKMP:      keylength of 256
ISAKMP (0): atts are not acceptable. Next payload is 3
ISAKMP (0): Checking ISAKMP transform 4 against priority 1 policy
ISAKMP:      encryption AES-CBC
ISAKMP:      hash MD5
ISAKMP:      default group 5
ISAKMP:      auth RSA sig
ISAKMP:      life type in seconds
ISAKMP:      life duration (VPI) of  0x0 0x20 0xc4 0x9b
ISAKMP:      keylength of 256
ISAKMP (0): atts are not acceptable. Next payload is 3
ISAKMP (0): Checking ISAKMP transform 5 against priority 1 policy
ISAKMP:      encryption AES-CBC
ISAKMP:      hash SHA
ISAKMP:      default group 2
ISAKMP:      extended auth RSA sig (init)
ISAKMP:      life type in seconds
ISAKMP:      life duration (VPI) of  0x0 0x20 0xc4 0x9b
ISAKMP:      keylength of 256
ISAKMP (0): atts are not acceptable. Next payload is 3
ISAKMP (0): Checking ISAKMP transform 6 against priority 1 policy
ISAKMP:      encryption AES-CBC
ISAKMP:      hash MD5
ISAKMP:      default group 2
ISAKMP:      extended auth RSA sig (init)
ISAKMP:      life type in seconds
ISAKMP:      life duration (VPI) of  0x0 0x20 0xc4 0x9b
ISAKMP:      keylength of 256
ISAKMP (0): atts are not acceptable. Next payload is 3
ISAKMP (0): Checking ISAKMP transform 7 against priority 1 policy
ISAKMP:      encryption AES-CBC
ISAKMP:      hash SHA
ISAKMP:      default group 2
ISAKMP:      auth RSA sig
ISAKMP:      life type in seconds
ISAKMP:      life duration (VPI) of  0x0 0x20 0xc4 0x9b
ISAKMP:      keylength of 256
ISAKMP (0): atts are not acceptable. Next payload is 3
ISAKMP (0): Checking ISAKMP transform 8 against priority 1 policy
ISAKMP:      encryption AES-CBC
ISAKMP:      hash MD5
ISAKMP:      default group 2
ISAKMP:      auth RSA sig
ISAKMP:      life type in seconds
ISAKMP:      life duration (VPI) of  0x0 0x20 0xc4 0x9b
ISAKMP:      keylength of 256
ISAKMP (0): atts are not acceptable. Next payload is 3
ISAKMP (0): Checking ISAKMP transform 9 against priority 1 policy
ISAKMP:      encryption AES-CBC
ISAKMP:      hash SHA
ISAKMP:      default group 5
ISAKMP:      extended auth RSA sig (init)
ISAKMP:      life type in seconds
ISAKMP:      life duration (VPI) of  0x0 0x20 0xc4 0x9b
ISAKMP:      keylength of 192
crypto_isakmp_process_block:src:137.194.26.47, dest:192.168.1.254 spt:500 dpt:500
VPN Peer:ISAKMP: Peer Info for 137.194.26.47/500 not found - peers:2

crypto_isakmp_process_block:src:137.194.26.47, dest:192.168.1.254 spt:500 dpt:500
VPN Peer:ISAKMP: Peer Info for 137.194.26.47/500 not found - peers:2

ISAKMP (0): retransmitting phase 1...
crypto_isakmp_process_block:src:137.194.26.47, dest:192.168.1.254 spt:500 dpt:500
VPN Peer:ISAKMP: Peer Info for 137.194.26.47/500 not found - peers:2

crypto_isakmp_process_block:src:137.194.26.47, dest:192.168.1.254 spt:500 dpt:500
OAK_MM exchange
ISAKMP (0): processing KE payload. message ID = 0

ISAKMP (0): processing NONCE payload. message ID = 0

ISAKMP (0:0): Detected NAT-D payload
ISAKMP (0:0): NAT does not match MINE hash
hash received: d6 2b 1d 42 c c1 61 a8 b1 90 5b 90 e7 ab 9c 39
my nat hash  : 21 c4 5f cd 6b 6f 3b 22 28 56 18 97 f8 9b e9 4
ISAKMP (0:0): Detected NAT-D payload
ISAKMP (0:0): NAT match HIS hash
ISAKMP (0:0): constructed HIS NAT-D
ISAKMP (0:0): constructed MINE NAT-D
return status is IKMP_NO_ERROR
crypto_isakmp_process_block:src:137.194.26.47, dest:192.168.1.254 spt:4500 dpt:4500
OAK_MM exchange
ISAKMP (0): processing ID payload. message ID = 0
ISAKMP (0): processing CERT payload. message ID = 0
ISAKMP (0): Unknown error in cert validation, 65535
return status is IKMP_ERR_RETRANS
ISAKMP (0): deleting SA: src 137.194.26.47, dst 192.168.1.254
ISADB: reaper checking SA 0x10690ec, conn_id = 0
ISADB: reaper checking SA 0x111569c, conn_id = 0
ISADB: reaper checking SA 0x106ad8c, conn_id = 0  DELETE IT!

VPN Peer:ISAKMP: Peer Info for 137.194.26.47/500 not found - peers:2

ISADB: reaper checking SA 0x10690ec, conn_id = 0
ISADB: reaper checking SA 0x111569c, conn_id = 0
ISAKMP (0): deleting SA: src 137.194.26.47, dst 192.168.1.254
ISADB: reaper checking SA 0x10690ec, conn_id = 0
ISADB: reaper checking SA 0x111569c, conn_id = 0  DELETE IT!

VPN Peer:ISAKMP: Peer Info for 137.194.26.47/4500 not found - peers:2
client_certificate.jpg (image/jpeg, 52.5 KB) - not displayed
Sh ca certificate.txt (text/plain, 1.2 KB)
devernois# sh ca certificate
Certificate
  Status: Available
  Certificate Serial Number: 675a052c000000000010
  Key Usage: General Purpose
  Subject Name:
    CN = devernois.mystream.org
    UNSTRUCTURED NAME = devernois.mystream.org
  Validity Date:
    start date: 11:43:36 UTC Feb 24 2004
    end   date: 11:53:36 UTC Feb 24 2005

RA Signature Certificate
  Status: Available
  Certificate Serial Number: 61d22175000000000002
  Key Usage: Signature
    CN = DEVERNOISRA
    OU = LOIRE
    O = devernois.fr
    L = ROANNE
    C = FR
  Validity Date:
    start date: 13:53:54 UTC Feb 4 2004
    end   date: 14:03:54 UTC Feb 4 2005

CA Certificate
  Status: Available
  Certificate Serial Number: 287c4dc27d1201bb4cd2cccf33df7341
  Key Usage: Signature
    CN = DEVERNOISCA
    OID.0.9.2342.19200300.100.1.25 =<16> devernois
    OID.0.9.2342.19200300.100.1.25 =<16> fr
  Validity Date:
    start date: 10:03:18 UTC Feb 4 2004
    end   date: 10:10:26 UTC Feb 4 2009

RA KeyEncipher Certificate
  Status: Available
  Certificate Serial Number: 61d2225f000000000003
  Key Usage: Encryption
    CN = DEVERNOISRA
    OU = LOIRE
    O = devernois.fr
    L = ROANNE
    C = FR
  Validity Date:
    start date: 13:53:54 UTC Feb 4 2004
    end   date: 14:03:54 UTC Feb 4 2005
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.