Re-7: VPN not working ...

[email protected]
Newsgroups gmane.network.freeswan.user
Message-ID <[email protected]>
There is some success ....

I will post my newest /var/out/security at the end of my reply.

How do I set a default key? Should this been done in the ipsec.secrets or where else?

Greetings,
  Kai

Aug  9 11:50:23 mngateway pluto[11026]: Starting Pluto (FreeS/WAN Version 2.04 X.509-1.5.3 LIBCURL PLUTO_USES_KEYRR)
Aug  9 11:50:23 mngateway pluto[11026]:   including NAT-Traversal patch (Version 0.6) [disabled]
Aug  9 11:50:23 mngateway pluto[11026]: Using Linux 2.6 IPsec interface code
Aug  9 11:50:23 mngateway pluto[11026]: Changing to directory '/etc/ipsec.d/cacerts'
Aug  9 11:50:23 mngateway pluto[11026]:   loaded CA cert file 'MultinovaCA-cert.pem' (1294 bytes)
Aug  9 11:50:23 mngateway pluto[11026]: Changing to directory '/etc/ipsec.d/aacerts'
Aug  9 11:50:23 mngateway pluto[11026]: Changing to directory '/etc/ipsec.d/ocspcerts'
Aug  9 11:50:23 mngateway pluto[11026]: Changing to directory '/etc/ipsec.d/crls'
Aug  9 11:50:23 mngateway pluto[11026]:   loaded crl file 'crl.pem' (577 bytes)
Aug  9 11:50:24 mngateway pluto[11026]:   loaded host cert file '/etc/ipsec.d/certs/mnvpngw-cert.pem' (4507 bytes)
Aug  9 11:50:24 mngateway pluto[11026]:   loaded host cert file '/etc/ipsec.d/certs/vpn-key-cert.pem' (4517 bytes)
Aug  9 11:50:24 mngateway pluto[11026]: added connection description "L2TP-CERT"
Aug  9 11:50:24 mngateway pluto[11026]: listening for IKE messages
Aug  9 11:50:24 mngateway pluto[11026]: adding interface ppp0/ppp0 217.82.92.225
Aug  9 11:50:24 mngateway pluto[11026]: adding interface eth0/eth0 192.6.2.12
Aug  9 11:50:24 mngateway pluto[11026]: adding interface lo/lo 127.0.0.1
Aug  9 11:50:24 mngateway pluto[11026]: adding interface lo/lo ::1
Aug  9 11:50:24 mngateway pluto[11026]: loading secrets from "/etc/ipsec.secrets"
Aug  9 11:50:24 mngateway pluto[11026]:   loaded private key file '/etc/ipsec.d/private/vpn-key.pem' (1751 bytes)
Aug  9 11:50:24 mngateway pluto[11026]:   loaded private key file '/etc/ipsec.d/private/mnvpngw-key.pem' (1751 bytes)
Aug  9 11:50:35 mngateway pluto[11026]: packet from 192.6.2.11:500: ignoring Vendor ID payload [MS NT5 ISAKMPOAKLEY 00000003]
Aug  9 11:50:35 mngateway pluto[11026]: "L2TP-CERT" #1: responding to Main Mode
Aug  9 11:50:35 mngateway pluto[11026]: "L2TP-CERT" #1: Peer ID is ID_DER_ASN1_DN: 'C=DE, O=Multinova GmbH, OU=VPN, CN=VPNCA'
Aug  9 11:50:35 mngateway pluto[11026]: "L2TP-CERT" #1: sent MR3, ISAKMP SA established
Aug  9 11:50:35 mngateway pluto[11026]: "L2TP-CERT" #1: cannot respond to IPsec SA request because no connection is known for 217.82.92.225[C=DE, O=Multinova GmbH, CN=Multinova CA]:17/0...192.6.2.11[C=DE, O=Multinova GmbH, OU=VPN, CN=VPNCA]:17/1701
Aug  9 11:50:35 mngateway pluto[11026]: "L2TP-CERT" #1: sending encrypted notification INVALID_ID_INFORMATION to 192.6.2.11:500
Aug  9 11:50:36 mngateway pluto[11026]: "L2TP-CERT" #1: Quick Mode I1 message is unacceptable because it uses a previously used Message ID 0xe7b9b5af (perhaps this is a duplicated packet)
Aug  9 11:50:36 mngateway pluto[11026]: "L2TP-CERT" #1: sending encrypted notification INVALID_MESSAGE_ID to 192.6.2.11:500
Aug  9 11:50:38 mngateway pluto[11026]: "L2TP-CERT" #1: Quick Mode I1 message is unacceptable because it uses a previously used Message ID 0xe7b9b5af (perhaps this is a duplicated packet)
Aug  9 11:50:38 mngateway pluto[11026]: "L2TP-CERT" #1: sending encrypted notification INVALID_MESSAGE_ID to 192.6.2.11:500
Aug  9 11:50:42 mngateway pluto[11026]: "L2TP-CERT" #1: Quick Mode I1 message is unacceptable because it uses a previously used Message ID 0xe7b9b5af (perhaps this is a duplicated packet)
Aug  9 11:50:42 mngateway pluto[11026]: "L2TP-CERT" #1: sending encrypted notification INVALID_MESSAGE_ID to 192.6.2.11:500
Aug  9 11:50:50 mngateway pluto[11026]: "L2TP-CERT" #1: Quick Mode I1 message is unacceptable because it uses a previously used Message ID 0xe7b9b5af (perhaps this is a duplicated packet)
Aug  9 11:50:50 mngateway pluto[11026]: "L2TP-CERT" #1: sending encrypted notification INVALID_MESSAGE_ID to 192.6.2.11:500
Aug  9 11:51:06 mngateway pluto[11026]: "L2TP-CERT" #1: Quick Mode I1 message is unacceptable because it uses a previously used Message ID 0xe7b9b5af (perhaps this is a duplicated packet)
Aug  9 11:51:06 mngateway pluto[11026]: "L2TP-CERT" #1: sending encrypted notification INVALID_MESSAGE_ID to 192.6.2.11:500
Aug  9 11:51:13 mngateway pluto[11026]: "L2TP-CERT" #1: received Delete SA payload: deleting ISAKMP State #1




-------- Original Message --------
Subject: Re-6: [Users] VPN not working ... (09-Aug-2004 11:21)
From:    [email protected]
To:      [email protected]

> At 11:08 09.08.2004, [email protected] wrote:
> >Hi,
> >
> >Now I have entered the private key files into the ipsec.secrets file and
> >they are loaded on ipsec startup.
> >
> >Ipsec verify now tells me
> >
> >Checking for RSA privte key (/etc/ipsec.secrets) ... [Failed]
> >ipsec showhostkey: No default key in "etc/ipsec.secrets"
>
> Ahhhh..... well the message tells the truth, you need a default key for
> connections to/from %any
>
>
> >I also generated the crl.
> >
> >But it's still not working.
> >
> >I'm going insane some day ....
>
> Welcome to the club, once you are there, enjoy....
>
> cheers
> Erich
>
> THINK
> Püntenstrasse 39
> 8143 Stallikon
> mailto:[email protected]
> PGP Fingerprint: BC9A 25BC 3954 3BC8 C024 8D8A B7D4 FF9D 05B8 0A16
>
> _______________________________________________
> FreeS/WAN Users mailing list
> [email protected]
> https://mj2.freeswan.org/cgi-bin/mj_wwwusr
>


To: [email protected]
    [email protected]
    [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.