Re-5: VPN not working ...

[email protected]
Newsgroups gmane.network.freeswan.user
Message-ID <[email protected]>
Hi,

the ipsec.secrets file has been populated but for some reason it is empty now. Maybe I deleted the file for testing purposes. I tested a lot the last days. Any idea how I can "rebuild" this file with my RSA 2048 bit keys without creating a complete new set?

There are 3 certificates I generated: 

MultinovaCA-cert  = root CA (located in /etc/ipsec.d/cacerts/)
mnvpngw-cert      = gateway CA (located in /etc/ipsec.d/private/)
vpn-key               = user certificate (located in /etc/ipsec.d/private/)

How can I implement the private key for the user in my ipsec.conf? 

I accessed my gateway and will show you the /var/log/security here:


Aug  9 09:53:01 mngateway ipsec__plutorun: Starting Pluto subsystem...
Aug  9 09:53:01 mngateway pluto[10003]: Starting Pluto (FreeS/WAN Version 2.04 X.509-1.5.3 LIBCURL PLUTO_USES_KEYRR)
Aug  9 09:53:01 mngateway pluto[10003]:   including NAT-Traversal patch (Version 0.6) [disabled]
Aug  9 09:53:01 mngateway pluto[10003]: Using Linux 2.6 IPsec interface code
Aug  9 09:53:02 mngateway pluto[10003]: Changing to directory '/etc/ipsec.d/cacerts'
Aug  9 09:53:02 mngateway pluto[10003]:   loaded CA cert file 'MultinovaCA-cert.pem' (1294 bytes)
Aug  9 09:53:02 mngateway pluto[10003]: Changing to directory '/etc/ipsec.d/aacerts'
Aug  9 09:53:02 mngateway pluto[10003]: Changing to directory '/etc/ipsec.d/ocspcerts'
Aug  9 09:53:02 mngateway pluto[10003]: Changing to directory '/etc/ipsec.d/crls'
Aug  9 09:53:02 mngateway pluto[10003]:   loaded host cert file '/etc/ipsec.d/certs/mnvpngw-cert.pem' (4507 bytes)
Aug  9 09:53:02 mngateway pluto[10003]: added connection description "L2TP-CERT"
Aug  9 09:53:02 mngateway pluto[10003]: listening for IKE messages
Aug  9 09:53:02 mngateway pluto[10003]: adding interface ppp0/ppp0 80.130.191.226
Aug  9 09:53:02 mngateway pluto[10003]: adding interface eth0/eth0 192.6.2.12
Aug  9 09:53:02 mngateway pluto[10003]: adding interface lo/lo 127.0.0.1
Aug  9 09:53:02 mngateway pluto[10003]: adding interface lo/lo ::1
Aug  9 09:53:02 mngateway pluto[10003]: loading secrets from "/etc/ipsec.secrets"
Aug  9 09:59:53 mngateway pluto[10003]: packet from 192.6.2.11:500: ignoring Vendor ID payload [MS NT5 ISAKMPOAKLEY 00000003]
Aug  9 09:59:53 mngateway pluto[10003]: "L2TP-CERT"[1] 192.6.2.11 #1: responding to Main Mode from unknown peer 192.6.2.11
Aug  9 09:59:54 mngateway pluto[10003]: "L2TP-CERT"[1] 192.6.2.11 #1: Peer ID is ID_DER_ASN1_DN: 'C=DE, O=Multinova GmbH, OU=VPN, CN=VPNCA'
Aug  9 09:59:54 mngateway pluto[10003]: "L2TP-CERT"[1] 192.6.2.11 #1: issuer crl not found
Aug  9 09:59:54 mngateway pluto[10003]: "L2TP-CERT"[1] 192.6.2.11 #1: no suitable connection for peer 'C=DE, O=Multinova GmbH, OU=VPN, CN=VPNCA'
Aug  9 09:59:54 mngateway pluto[10003]: "L2TP-CERT"[1] 192.6.2.11 #1: sending encrypted notification INVALID_ID_INFORMATION to 192.6.2.11:500
Aug  9 09:59:54 mngateway pluto[10003]: "L2TP-CERT"[1] 192.6.2.11 #1: next payload type of ISAKMP Hash Payload has an unknown value: 237
Aug  9 09:59:54 mngateway pluto[10003]: "L2TP-CERT"[1] 192.6.2.11 #1: malformed payload in packet
Aug  9 09:59:54 mngateway pluto[10003]: "L2TP-CERT"[1] 192.6.2.11 #1: sending encrypted notification PAYLOAD_MALFORMED to 192.6.2.11:500
Aug  9 10:00:04 mngateway pluto[10003]: "L2TP-CERT"[1] 192.6.2.11 #1: Informational Exchange message must be encrypted


Thanks again for your help. I'm completely stuck at this.

Greetings,
  Kai

To: [email protected]
    [email protected]
    [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.