RE : A problem in a Cisco VPN client connection to a Cisco Pixusing X509 certificates
"Benkirane Youssef" <[email protected]>
| Newsgroups | gmane.comp.security.vpn |
|---|---|
| Message-ID | <001101c3fb8a$79cea3f0$2f1ac289@Youssef> |
Yes, i think so. i installed the pix own certificate using the following steps. ca identity devernoisca 192.168.20.1:/certsrv/mscep/mscep.dll ca configure devernoisca ra 20 5 crloptional ca authenticate devernoisca (to authenticate the authority) ca enroll devernoisca (to get the pix own certificate) did you see the file (sh_ca_certificate)? -----Message d'origine----- De : Andrew Prince [mailto:[email protected]] Envoyé : mercredi 25 février 2004 11:20 À : 'Benkirane Youssef' Objet : RE: [VPN] A problem in a Cisco VPN client connection to a Cisco Pixusing X509 certificates 1) Has the PIX got it's own cert? 2) The PIX needs to authenticate the CA by obtaining the CA's self-signed certificate which contains the CA's public key. Because the CA signs its own certificate, the CA's public key should be authenticated . _____ From: Benkirane Youssef [mailto:[email protected]] Sent: 25 February 2004 10:15 To: [email protected] Subject: RE : [VPN] A problem in a Cisco VPN client connection to a Cisco Pixusing X509 certificates Yes, In fact, i use a windows 2000 server certificate authority, with mscep enrollement. To help you, here are the logs of the pix (Pix_Logs.txt) while a connection attempt using certificate. Also a show ca certificate and a screen copy of the cisco client certificate that Im using to connect to the pix. Thanks for your help -----Message d'origine----- De : Andrew Prince [mailto:[email protected]] Envoyé : mercredi 25 février 2004 10:29 À : 'Benkirane Youssef' Objet : RE: [VPN] A problem in a Cisco VPN client connection to a Cisco Pixusing X509 certificates Ah - you didn't say that!! Have you configured the PIX to use the same Certificate Authority that the client certificate came from?? _____ From: Benkirane Youssef [mailto:[email protected]] Sent: 25 February 2004 09:12 To: [email protected] Subject: RE : [VPN] A problem in a Cisco VPN client connection to a Cisco Pixusing X509 certificates Hi, I dont think that is the problem, because a vpn connection with preshared keys works! Youssef -----Message d'origine----- De : Andrew Prince [mailto:[email protected]] Envoyé : mardi 24 février 2004 20:18 À : 'Benkirane Youssef' Objet : RE: [VPN] A problem in a Cisco VPN client connection to a Cisco Pixusing X509 certificates Youssef, Ignore last mail - did not see the attachement. the reason why it doesn't work is you have an access-list on the inbound traffic in the outside interface, you are only alowing www (tcp port 80) into the PIX. You will have to allow UDP500 (ISAKMP) ipsec (protocol 50) HTH, Andy _____ From: [email protected] [mailto:[email protected]] On Behalf Of Benkirane Youssef Sent: 24 February 2004 14:07 To: [email protected] Subject: [VPN] A problem in a Cisco VPN client connection to a Cisco Pixusing X509 certificates Hi, I have a cisco Pix 515. The wan interface is connected behind an internet Link. When I try to connect with a cisco VPN client 3.6.3 to the PIX using certificate. The ISAKMP authentication blocks. The IPSEC log viewer shows that the message SENDING >>> ISAKMP OAK MM *(ID, CERT, CERT_REQ, SIG, NOTIFY:STATUS_INITIAL_CONTACT) to 217.128.150.77, has no response from the PIX. Does someone have a diagnostic for this problem? Thank you by advance Youssef Those are the whole logs of the VPN client. 1 11:58:33.134 02/24/04 Sev=Info/6 DIALER/0x63300002 Initiating connection. 2 11:58:33.134 02/24/04 Sev=Info/4 CM/0x63100002 Begin connection process 3 11:58:33.144 02/24/04 Sev=Info/4 CM/0x63100004 Establish secure connection using Ethernet 4 11:58:33.144 02/24/04 Sev=Info/4 CM/0x63100026 Attempt connection with server "217.128.150.77" 5 11:58:33.144 02/24/04 Sev=Info/6 IKE/0x6300003B Attempting to establish a connection with 217.128.150.77. 6 11:58:33.204 02/24/04 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK MM (SA, VID, VID, VID, VID, VID) to 217.128.150.77 7 11:58:34.035 02/24/04 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 8 11:58:38.241 02/24/04 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK MM (Retransmission) to 217.128.150.77 9 11:58:43.248 02/24/04 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK MM (Retransmission) to 217.128.150.77 10 11:58:48.256 02/24/04 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK MM (Retransmission) to 217.128.150.77 11 11:58:48.306 02/24/04 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 217.128.150.77 12 11:58:48.306 02/24/04 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK MM (SA, VID, VID) from 217.128.150.77 13 11:58:48.316 02/24/04 Sev=Info/5 IKE/0x63000059 Vendor ID payload = 7D9419A65310CA6F2C179D9215529D56 14 11:58:48.316 02/24/04 Sev=Info/5 IKE/0x63000059 Vendor ID payload = 90CB80913EBB696E086381B5EC427B1F 15 11:58:48.316 02/24/04 Sev=Info/5 IKE/0x63000001 Peer supports NAT-T 16 11:58:48.316 02/24/04 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK MM (KE, NON, NAT-D, NAT-D) to 217.128.150.77 17 11:58:48.416 02/24/04 Sev=Info/5 IKE/0x6300002F Received ISAKMP packet: peer = 217.128.150.77 18 11:58:48.416 02/24/04 Sev=Info/4 IKE/0x63000014 RECEIVING <<< ISAKMP OAK MM (KE, NON, CERT_REQ, VID, VID, VID, VID, NAT-D, NAT-D) from 217.128.150.77 19 11:58:48.416 02/24/04 Sev=Info/5 IKE/0x63000059 Vendor ID payload = 09002689DFD6B712 20 11:58:48.416 02/24/04 Sev=Info/5 IKE/0x63000001 Peer supports XAUTH 21 11:58:48.416 02/24/04 Sev=Info/5 IKE/0x63000059 Vendor ID payload = AFCAD71368A1F1C96B8696FC77570100 22 11:58:48.416 02/24/04 Sev=Info/5 IKE/0x63000001 Peer supports DPD 23 11:58:48.416 02/24/04 Sev=Info/5 IKE/0x63000059 Vendor ID payload = 12F5F28C457168A9702D9FE274CC0100 24 11:58:48.416 02/24/04 Sev=Info/5 IKE/0x63000001 Peer is a Cisco-Unity compliant peer 25 11:58:48.416 02/24/04 Sev=Info/5 IKE/0x63000059 Vendor ID payload = B11B2FEEE3184CADFA563C07828BFA2F 26 11:58:48.506 02/24/04 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK MM *(ID, CERT, CERT_REQ, SIG, NOTIFY:STATUS_INITIAL_CONTACT) to 217.128.150.77 27 11:58:53.513 02/24/04 Sev=Warning/2 IKE/0xE300007C Exceeded 3 IKE SA negotiation retransmits... peer is not responding 28 11:58:53.513 02/24/04 Sev=Info/4 CM/0x63100014 Unable to establish Phase 1 SA with server "217.128.150.77" because of "DEL_REASON_PEER_NOT_RESPONDING" 29 11:58:53.513 02/24/04 Sev=Info/5 CM/0x63100029 Initializing CVPNDrv 30 11:58:53.563 02/24/04 Sev=Warning/3 DIALER/0xE3300008 GI VPNStart callback failed "CM_PEER_NOT_RESPONDING" (16h). 31 11:58:54.575 02/24/04 Sev=Info/4 IPSEC/0x63700014 Deleted all keys _______________________________________________ VPN mailing list [email protected] http://lists.shmoo.com/mailman/listinfo/vpn
Pix_Logs.txt
(text/plain, 5.1 KB)
ISAKMP (0): processing SA payload. message ID = 0 ISAKMP (0): Checking ISAKMP transform 1 against priority 1 policy ISAKMP: encryption AES-CBC ISAKMP: hash SHA ISAKMP: default group 5 ISAKMP: extended auth RSA sig (init) ISAKMP: life type in seconds ISAKMP: life duration (VPI) of 0x0 0x20 0xc4 0x9b ISAKMP: keylength of 256 ISAKMP (0): atts are not acceptable. Next payload is 3 ISAKMP (0): Checking ISAKMP transform 2 against priority 1 policy ISAKMP: encryption AES-CBC ISAKMP: hash MD5 ISAKMP: default group 5 ISAKMP: extended auth RSA sig (init) ISAKMP: life type in seconds ISAKMP: life duration (VPI) of 0x0 0x20 0xc4 0x9b ISAKMP: keylength of 256 ISAKMP (0): atts are not acceptable. Next payload is 3 ISAKMP (0): Checking ISAKMP transform 3 against priority 1 policy ISAKMP: encryption AES-CBC ISAKMP: hash SHA ISAKMP: default group 5 ISAKMP: auth RSA sig ISAKMP: life type in seconds ISAKMP: life duration (VPI) of 0x0 0x20 0xc4 0x9b ISAKMP: keylength of 256 ISAKMP (0): atts are not acceptable. Next payload is 3 ISAKMP (0): Checking ISAKMP transform 4 against priority 1 policy ISAKMP: encryption AES-CBC ISAKMP: hash MD5 ISAKMP: default group 5 ISAKMP: auth RSA sig ISAKMP: life type in seconds ISAKMP: life duration (VPI) of 0x0 0x20 0xc4 0x9b ISAKMP: keylength of 256 ISAKMP (0): atts are not acceptable. Next payload is 3 ISAKMP (0): Checking ISAKMP transform 5 against priority 1 policy ISAKMP: encryption AES-CBC ISAKMP: hash SHA ISAKMP: default group 2 ISAKMP: extended auth RSA sig (init) ISAKMP: life type in seconds ISAKMP: life duration (VPI) of 0x0 0x20 0xc4 0x9b ISAKMP: keylength of 256 ISAKMP (0): atts are not acceptable. Next payload is 3 ISAKMP (0): Checking ISAKMP transform 6 against priority 1 policy ISAKMP: encryption AES-CBC ISAKMP: hash MD5 ISAKMP: default group 2 ISAKMP: extended auth RSA sig (init) ISAKMP: life type in seconds ISAKMP: life duration (VPI) of 0x0 0x20 0xc4 0x9b ISAKMP: keylength of 256 ISAKMP (0): atts are not acceptable. Next payload is 3 ISAKMP (0): Checking ISAKMP transform 7 against priority 1 policy ISAKMP: encryption AES-CBC ISAKMP: hash SHA ISAKMP: default group 2 ISAKMP: auth RSA sig ISAKMP: life type in seconds ISAKMP: life duration (VPI) of 0x0 0x20 0xc4 0x9b ISAKMP: keylength of 256 ISAKMP (0): atts are not acceptable. Next payload is 3 ISAKMP (0): Checking ISAKMP transform 8 against priority 1 policy ISAKMP: encryption AES-CBC ISAKMP: hash MD5 ISAKMP: default group 2 ISAKMP: auth RSA sig ISAKMP: life type in seconds ISAKMP: life duration (VPI) of 0x0 0x20 0xc4 0x9b ISAKMP: keylength of 256 ISAKMP (0): atts are not acceptable. Next payload is 3 ISAKMP (0): Checking ISAKMP transform 9 against priority 1 policy ISAKMP: encryption AES-CBC ISAKMP: hash SHA ISAKMP: default group 5 ISAKMP: extended auth RSA sig (init) ISAKMP: life type in seconds ISAKMP: life duration (VPI) of 0x0 0x20 0xc4 0x9b ISAKMP: keylength of 192 crypto_isakmp_process_block:src:137.194.26.47, dest:192.168.1.254 spt:500 dpt:500 VPN Peer:ISAKMP: Peer Info for 137.194.26.47/500 not found - peers:2 crypto_isakmp_process_block:src:137.194.26.47, dest:192.168.1.254 spt:500 dpt:500 VPN Peer:ISAKMP: Peer Info for 137.194.26.47/500 not found - peers:2 ISAKMP (0): retransmitting phase 1... crypto_isakmp_process_block:src:137.194.26.47, dest:192.168.1.254 spt:500 dpt:500 VPN Peer:ISAKMP: Peer Info for 137.194.26.47/500 not found - peers:2 crypto_isakmp_process_block:src:137.194.26.47, dest:192.168.1.254 spt:500 dpt:500 OAK_MM exchange ISAKMP (0): processing KE payload. message ID = 0 ISAKMP (0): processing NONCE payload. message ID = 0 ISAKMP (0:0): Detected NAT-D payload ISAKMP (0:0): NAT does not match MINE hash hash received: d6 2b 1d 42 c c1 61 a8 b1 90 5b 90 e7 ab 9c 39 my nat hash : 21 c4 5f cd 6b 6f 3b 22 28 56 18 97 f8 9b e9 4 ISAKMP (0:0): Detected NAT-D payload ISAKMP (0:0): NAT match HIS hash ISAKMP (0:0): constructed HIS NAT-D ISAKMP (0:0): constructed MINE NAT-D return status is IKMP_NO_ERROR crypto_isakmp_process_block:src:137.194.26.47, dest:192.168.1.254 spt:4500 dpt:4500 OAK_MM exchange ISAKMP (0): processing ID payload. message ID = 0 ISAKMP (0): processing CERT payload. message ID = 0 ISAKMP (0): Unknown error in cert validation, 65535 return status is IKMP_ERR_RETRANS ISAKMP (0): deleting SA: src 137.194.26.47, dst 192.168.1.254 ISADB: reaper checking SA 0x10690ec, conn_id = 0 ISADB: reaper checking SA 0x111569c, conn_id = 0 ISADB: reaper checking SA 0x106ad8c, conn_id = 0 DELETE IT! VPN Peer:ISAKMP: Peer Info for 137.194.26.47/500 not found - peers:2 ISADB: reaper checking SA 0x10690ec, conn_id = 0 ISADB: reaper checking SA 0x111569c, conn_id = 0 ISAKMP (0): deleting SA: src 137.194.26.47, dst 192.168.1.254 ISADB: reaper checking SA 0x10690ec, conn_id = 0 ISADB: reaper checking SA 0x111569c, conn_id = 0 DELETE IT! VPN Peer:ISAKMP: Peer Info for 137.194.26.47/4500 not found - peers:2
client_certificate.jpg
(image/jpeg, 52.5 KB) - not displayed
Sh ca certificate.txt
(text/plain, 1.2 KB)
devernois# sh ca certificate
Certificate
Status: Available
Certificate Serial Number: 675a052c000000000010
Key Usage: General Purpose
Subject Name:
CN = devernois.mystream.org
UNSTRUCTURED NAME = devernois.mystream.org
Validity Date:
start date: 11:43:36 UTC Feb 24 2004
end date: 11:53:36 UTC Feb 24 2005
RA Signature Certificate
Status: Available
Certificate Serial Number: 61d22175000000000002
Key Usage: Signature
CN = DEVERNOISRA
OU = LOIRE
O = devernois.fr
L = ROANNE
C = FR
Validity Date:
start date: 13:53:54 UTC Feb 4 2004
end date: 14:03:54 UTC Feb 4 2005
CA Certificate
Status: Available
Certificate Serial Number: 287c4dc27d1201bb4cd2cccf33df7341
Key Usage: Signature
CN = DEVERNOISCA
OID.0.9.2342.19200300.100.1.25 =<16> devernois
OID.0.9.2342.19200300.100.1.25 =<16> fr
Validity Date:
start date: 10:03:18 UTC Feb 4 2004
end date: 10:10:26 UTC Feb 4 2009
RA KeyEncipher Certificate
Status: Available
Certificate Serial Number: 61d2225f000000000003
Key Usage: Encryption
CN = DEVERNOISRA
OU = LOIRE
O = devernois.fr
L = ROANNE
C = FR
Validity Date:
start date: 13:53:54 UTC Feb 4 2004
end date: 14:03:54 UTC Feb 4 2005