Problem in ipsec vpn setup.

Virendra Yelurkar <[email protected]> Thu, 5 Jan 2006 05:10:18 +0000
Newsgroups gmane.comp.security.vpn
Message-ID <[email protected]>
--===============1163817933==
Content-Type: multipart/alternative; 
	boundary="----=_Part_20334_9947826.1136437818888"

------=_Part_20334_9947826.1136437818888
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

Hi all,

I am trying to setup a tunnel mode ipsec vpn connection between two
gateways. (196.1.109.54 <--> 196.1.109.71). Each of these gateways are
connected to a client using cross cables. The configuration is :



                               (10.1.1.234)             (196.1.109.54)
|
|  (196.1.109.71)                              (10.2.2.234)
client-1 -------------------------- Gateway-1=3D=3D=3D=3D=3D| Router |=3D=
=3D=3D=3D=3D=3D=3D
Gateway-2 -------------------------client-2
( 10.1.1.1 )   cross cable
|            |                                            cross
cable               ( 10.2.2.1 )

Routing table entries on Gateway-1 are:

eth0: default gw=3DRouter
eth1 : default gw=3D10.1.1.1

Routing table entries on Gateway-2 are:

eth0: default gw=3DRouter
eth1 : default gw=3D10.2.2.1

When I try to ping one client from another, following error occures:

sshipm: warning; SPD Phase-1 policy [responder]; Can not get policy
for ipv4(any:0,[0..3]=3D0.0.0.0) <-> ipv4(any:0,[0..3]=3D196.1.109.71)

sshipm: error; SPD rejected conn using selectors
unknown(any:0,[0..0]=3D)(ipv4(any:0,[0..3]=3D0.0.0.0)) <->
(ipv4(any:0,[0..3]=3D196.1.109.71))unknown(any:0,[0..0]=3D)
sshipm: info; The remote server 196.1.109.71:500 is SSH Communications
Security IPSEC Express version 5.0.0

Please help me in this regard..
Thanking you in anticipation.
-----------------------------------------------------------------------
Regards,

Virendra Yelurkar

------=_Part_20334_9947826.1136437818888
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

Hi all,<br>
<br>
I am trying to setup a tunnel mode ipsec vpn connection between two
gateways. (<a href=3D"http://196.1.109.54">196.1.109.54</a> &lt;--&gt; <a h=
ref=3D"http://196.1.109.71">196.1.109.71</a>). Each of these
gateways are connected to a client using cross cables. The
configuration is :<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
(<font size=3D"1"><a href=3D"http://10.1.1.234">10.1.1.234</a>)</font>&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <font s=
ize=3D"1">(<a href=3D"http://196.1.109.54">196.1.109.54</a>) </font>|&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; <font =
size=3D"1">(<a href=3D"http://196.1.109.71">196.1.109.71
</a>)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;
(<a href=3D"http://10.2.2.234">10.2.2.234</a>)</font><br>
client-1 -------------------------- Gateway-1=3D=3D=3D=3D=3D| Router |=3D=
=3D=3D=3D=3D=3D=3D Gateway-2 -------------------------client-2<br>
<font size=3D"1">( <a href=3D"http://10.1.1.1">10.1.1.1</a> )</font>&nbsp;&=
nbsp; <font size=3D"1">cross cable</font>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&nbsp;
|&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
|&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
<font size=3D"1">cross cable&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ( <a href=3D"http://10.2.2.1">10.2.2.=
1</a> )</font><br>
<br clear=3D"all">Routing table entries on Gateway-1 are:<br>
<br>
eth0: default gw=3DRouter<br>
eth1 : default gw=3D<a href=3D"http://10.1.1.1">10.1.1.1</a><br>
<br>
Routing table entries on Gateway-2 are:<br>

<br>

eth0: default gw=3DRouter<br>

eth1 : default gw=3D<a href=3D"http://10.2.2.1">10.2.2.1</a><br>
<br>
When I try to ping one client from another, following error occures:<br>
<br>
<pre>sshipm: warning; SPD Phase-1 policy [responder]; Can not get policy fo=
r ipv4(any:0,[0..3]=3D<a href=3D"http://0.0.0.0">0.0.0.0</a>) &lt;-&gt; ipv=
4(any:0,[0..3]=3D<a href=3D"http://196.1.109.71">196.1.109.71</a>)<br><br>s=
shipm: error; SPD rejected conn using selectors unknown(any:0,[0..0]=3D)(ip=
v4(any:0,[0..3]=3D
<a href=3D"http://0.0.0.0">0.0.0.0</a>)) &lt;-&gt; (ipv4(any:0,[0..3]=3D<a =
href=3D"http://196.1.109.71">196.1.109.71</a>))unknown(any:0,[0..0]=3D)<br>=
sshipm: info; The remote server <a href=3D"http://196.1.109.71:500">196.1.1=
09.71:500
</a> is SSH Communications Security IPSEC Express version 5.0.0</pre>
Please help me in this regard..<br>
Thanking you in anticipation.<br>------------------------------------------=
-----------------------------<br>Regards,<br><br>Virendra Yelurkar<br><br>

------=_Part_20334_9947826.1136437818888--

--===============1163817933==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
VPN mailing list
[email protected]
http://lists.shmoo.com/mailman/listinfo/vpn
--===============1163817933==--