Re-5: VPN not working ...
| Newsgroups | gmane.network.freeswan.user |
|---|---|
| Message-ID | <[email protected]> |
Hi, the ipsec.secrets file has been populated but for some reason it is empty now. Maybe I deleted the file for testing purposes. I tested a lot the last days. Any idea how I can "rebuild" this file with my RSA 2048 bit keys without creating a complete new set? There are 3 certificates I generated: MultinovaCA-cert = root CA (located in /etc/ipsec.d/cacerts/) mnvpngw-cert = gateway CA (located in /etc/ipsec.d/private/) vpn-key = user certificate (located in /etc/ipsec.d/private/) How can I implement the private key for the user in my ipsec.conf? I accessed my gateway and will show you the /var/log/security here: Aug 9 09:53:01 mngateway ipsec__plutorun: Starting Pluto subsystem... Aug 9 09:53:01 mngateway pluto[10003]: Starting Pluto (FreeS/WAN Version 2.04 X.509-1.5.3 LIBCURL PLUTO_USES_KEYRR) Aug 9 09:53:01 mngateway pluto[10003]: including NAT-Traversal patch (Version 0.6) [disabled] Aug 9 09:53:01 mngateway pluto[10003]: Using Linux 2.6 IPsec interface code Aug 9 09:53:02 mngateway pluto[10003]: Changing to directory '/etc/ipsec.d/cacerts' Aug 9 09:53:02 mngateway pluto[10003]: loaded CA cert file 'MultinovaCA-cert.pem' (1294 bytes) Aug 9 09:53:02 mngateway pluto[10003]: Changing to directory '/etc/ipsec.d/aacerts' Aug 9 09:53:02 mngateway pluto[10003]: Changing to directory '/etc/ipsec.d/ocspcerts' Aug 9 09:53:02 mngateway pluto[10003]: Changing to directory '/etc/ipsec.d/crls' Aug 9 09:53:02 mngateway pluto[10003]: loaded host cert file '/etc/ipsec.d/certs/mnvpngw-cert.pem' (4507 bytes) Aug 9 09:53:02 mngateway pluto[10003]: added connection description "L2TP-CERT" Aug 9 09:53:02 mngateway pluto[10003]: listening for IKE messages Aug 9 09:53:02 mngateway pluto[10003]: adding interface ppp0/ppp0 80.130.191.226 Aug 9 09:53:02 mngateway pluto[10003]: adding interface eth0/eth0 192.6.2.12 Aug 9 09:53:02 mngateway pluto[10003]: adding interface lo/lo 127.0.0.1 Aug 9 09:53:02 mngateway pluto[10003]: adding interface lo/lo ::1 Aug 9 09:53:02 mngateway pluto[10003]: loading secrets from "/etc/ipsec.secrets" Aug 9 09:59:53 mngateway pluto[10003]: packet from 192.6.2.11:500: ignoring Vendor ID payload [MS NT5 ISAKMPOAKLEY 00000003] Aug 9 09:59:53 mngateway pluto[10003]: "L2TP-CERT"[1] 192.6.2.11 #1: responding to Main Mode from unknown peer 192.6.2.11 Aug 9 09:59:54 mngateway pluto[10003]: "L2TP-CERT"[1] 192.6.2.11 #1: Peer ID is ID_DER_ASN1_DN: 'C=DE, O=Multinova GmbH, OU=VPN, CN=VPNCA' Aug 9 09:59:54 mngateway pluto[10003]: "L2TP-CERT"[1] 192.6.2.11 #1: issuer crl not found Aug 9 09:59:54 mngateway pluto[10003]: "L2TP-CERT"[1] 192.6.2.11 #1: no suitable connection for peer 'C=DE, O=Multinova GmbH, OU=VPN, CN=VPNCA' Aug 9 09:59:54 mngateway pluto[10003]: "L2TP-CERT"[1] 192.6.2.11 #1: sending encrypted notification INVALID_ID_INFORMATION to 192.6.2.11:500 Aug 9 09:59:54 mngateway pluto[10003]: "L2TP-CERT"[1] 192.6.2.11 #1: next payload type of ISAKMP Hash Payload has an unknown value: 237 Aug 9 09:59:54 mngateway pluto[10003]: "L2TP-CERT"[1] 192.6.2.11 #1: malformed payload in packet Aug 9 09:59:54 mngateway pluto[10003]: "L2TP-CERT"[1] 192.6.2.11 #1: sending encrypted notification PAYLOAD_MALFORMED to 192.6.2.11:500 Aug 9 10:00:04 mngateway pluto[10003]: "L2TP-CERT"[1] 192.6.2.11 #1: Informational Exchange message must be encrypted Thanks again for your help. I'm completely stuck at this. Greetings, Kai To: [email protected] [email protected] [email protected]