Re: Re-7: VPN not working ...

Erich Titl <[email protected]>
Newsgroups gmane.network.freeswan.user
Message-ID <[email protected]>
Kai

At 11:54 09.08.2004, [email protected] wrote:
>There is some success ....
>
>I will post my newest /var/out/security at the end of my reply.
>
>How do I set a default key? Should this been done in the ipsec.secrets or 
>where else?

There needs to be an entry in /etc/ipsec.secret which references your 
private key for a connection, it does not necessarily have to be a default 
key, but it must match your certificate.


>Greetings,
>   Kai
>
>Aug  9 11:50:23 mngateway pluto[11026]: Starting Pluto (FreeS/WAN Version 
>2.04 X.509-1.5.3 LIBCURL PLUTO_USES_KEYRR)
>Aug  9 11:50:23 mngateway pluto[11026]:   including NAT-Traversal patch 
>(Version 0.6) [disabled]
>Aug  9 11:50:23 mngateway pluto[11026]: Using Linux 2.6 IPsec interface code
>Aug  9 11:50:23 mngateway pluto[11026]: Changing to directory 
>'/etc/ipsec.d/cacerts'
>Aug  9 11:50:23 mngateway pluto[11026]:   loaded CA cert file 
>'MultinovaCA-cert.pem' (1294 bytes)

OK CA certificate gets loaded

>Aug  9 11:50:23 mngateway pluto[11026]: Changing to directory 
>'/etc/ipsec.d/aacerts'
>Aug  9 11:50:23 mngateway pluto[11026]: Changing to directory 
>'/etc/ipsec.d/ocspcerts'
>Aug  9 11:50:23 mngateway pluto[11026]: Changing to directory 
>'/etc/ipsec.d/crls'
>Aug  9 11:50:23 mngateway pluto[11026]:   loaded crl file 'crl.pem' (577 
>bytes)
>Aug  9 11:50:24 mngateway pluto[11026]:   loaded host cert file 
>'/etc/ipsec.d/certs/mnvpngw-cert.pem' (4507 bytes)
>Aug  9 11:50:24 mngateway pluto[11026]:   loaded host cert file 
>'/etc/ipsec.d/certs/vpn-key-cert.pem' (4517 bytes)

OK you loaded 2 certificates for the connections

>Aug  9 11:50:24 mngateway pluto[11026]: added connection description 
>"L2TP-CERT"
>Aug  9 11:50:24 mngateway pluto[11026]: listening for IKE messages
>Aug  9 11:50:24 mngateway pluto[11026]: adding interface ppp0/ppp0 
>217.82.92.225
>Aug  9 11:50:24 mngateway pluto[11026]: adding interface eth0/eth0 192.6.2.12

?????

>Aug  9 11:50:24 mngateway pluto[11026]: adding interface lo/lo 127.0.0.1
>Aug  9 11:50:24 mngateway pluto[11026]: adding interface lo/lo ::1
>Aug  9 11:50:24 mngateway pluto[11026]: loading secrets from 
>"/etc/ipsec.secrets"
>Aug  9 11:50:24 mngateway pluto[11026]:   loaded private key file 
>'/etc/ipsec.d/private/vpn-key.pem' (1751 bytes)
>Aug  9 11:50:24 mngateway pluto[11026]:   loaded private key file 
>'/etc/ipsec.d/private/mnvpngw-key.pem' (1751 bytes)

OK 2 private keys are loaded

>Aug  9 11:50:35 mngateway pluto[11026]: packet from 192.6.2.11:500: 
>ignoring Vendor ID payload [MS NT5 ISAKMPOAKLEY 00000003]
>Aug  9 11:50:35 mngateway pluto[11026]: "L2TP-CERT" #1: responding to Main 
>Mode
>Aug  9 11:50:35 mngateway pluto[11026]: "L2TP-CERT" #1: Peer ID is 
>ID_DER_ASN1_DN: 'C=DE, O=Multinova GmbH, OU=VPN, CN=VPNCA'
>Aug  9 11:50:35 mngateway pluto[11026]: "L2TP-CERT" #1: sent MR3, ISAKMP 
>SA established

Hey, we got a ISAKMP SA....

>Aug  9 11:50:35 mngateway pluto[11026]: "L2TP-CERT" #1: cannot respond to 
>IPsec SA request because no connection is known for 217.82.92.225[C=DE, 
>O=Multinova GmbH, CN=Multinova CA]:17/0...192.6.2.11[C=DE, O=Multinova 
>GmbH, OU=VPN, CN=VPNCA]:17/1701

Bah.... we do not have a matching connection, we need to look at the 
certificates and the connection descriptions.

>Aug  9 11:50:35 mngateway pluto[11026]: "L2TP-CERT" #1: sending encrypted 
>notification INVALID_ID_INFORMATION to 192.6.2.11:500
>Aug  9 11:50:36 mngateway pluto[11026]: "L2TP-CERT" #1: Quick Mode I1 
>message is unacceptable because it uses a previously used Message ID 
>0xe7b9b5af

cheers
Erich

THINK
Püntenstrasse 39
8143 Stallikon
mailto:[email protected]
PGP Fingerprint: BC9A 25BC 3954 3BC8 C024 8D8A B7D4 FF9D 05B8 0A16
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.