(racoon 820) RE: Windows XP Road Warrior with x509 and/or PSK

"David Herselman" <[email protected]> Thu, 21 Oct 2004 12:08:18 +0200
Newsgroups gmane.network.ipv6.kame.racoon
Organization Syrex Intranets
Message-ID <[email protected]>
Many thanks for the information, I've started reading through the document
and will report back on my success... ;)

Would anyone else perhaps know, as a backup to x509 certificates, how to get
racoon to match the IP address as a wildcard in the psk.txt file?

/etc/racoon/psk.txt:
0.0.0.0                 "pre-shared-key"

/var/log/messages:
Oct 21 12:03:13 unix-01 racoon: INFO: isakmp.c:903:isakmp_ph1begin_r():
respond new phase 1 negotiation: 165.165.178.203[500]<=>165.165.0.36[500]
Oct 21 12:03:13 unix-01 racoon: INFO: isakmp.c:908:isakmp_ph1begin_r():
begin Identity Protection mode.
Oct 21 12:03:13 unix-01 racoon: INFO: vendorid.c:128:check_vendorid():
received Vendor ID: MS NT5 ISAKMPOAKLEY
Oct 21 12:03:13 unix-01 racoon: ERROR: oakley.c:2098:oakley_skeyid():
couldn't find the pskey for 165.165.0.36.
Oct 21 12:03:13 unix-01 racoon: ERROR: isakmp.c:636:ph1_main(): failed to
process packet.
Oct 21 12:03:13 unix-01 racoon: ERROR: isakmp.c:451:isakmp_main(): phase1
negotiation failed.
Oct 21 12:03:20 unix-01 racoon: ERROR: isakmp.c:477:isakmp_main(): unknown
Informational exchange received.


Syrex Intranets - Customised Solutions

	David Herselman
	Systems Engineer
 	
	cell	 +27 (0)82 784 7222
	tel	 +27 (0)86 11 syrex (79739)
	fax	 +27 (0)86 12 syrex (79739)
	27 7th avenue parktown north 2193
	email [email protected]
	www.syrex.co.za

-----Original Message-----
From: Roland Dirlewanger [mailto:[email protected]] 
Sent: 21 October 2004 10:36 AM
To: [email protected]
Cc: [email protected]
Subject: Re: (racoon 817) Windows XP Road Warrior with x509 and/or PSK

David Herselman wrote:

>2. I next tried getting x509 certificates to work with the Windows XP 
>roaming machine. I've followed several documents on how to create the 
>relevant certificates but none of them show the required steps in how 
>one gets Windows XP to 'bind' the certificate to the required VPN
connection...
>Windows XP doesn't even attempt the connection out as it can not locate 
>the right certificate.
>
>I found some reference to a 'mini-HOWTO with Windows XP using certificates'
>but the domain doesn't exist anymore... Would someone possibly still 
>have this document lying around? Broken link:
>http://www.fatcanary.com.au/docs/xp_freebsd_cert_ipsec.txt
>  
>
Jacco De Leeuw wrote a very good step by step guide for installing and
configuring FreeSwan  with L2TP/IPsec clients. The part concerning the
clients is not tighted to any ISAKMP or IPsec implementation. It contains a
chapter named "Importing certificates (Windows 2000/XP)" in the following
page :

http://www.jacco2.dds.nl/networking/win2000xp-freeswan.html

>Problem is that both the host and the client machine are on Dynamic IPs 
>so I can not simply use the local security policy to activate the 
>certificate on the IPSec link based on the IP filter...
>  
>
Your racoon.conf has  "generate_policy on" in phase 1. On a server with a
fixed address, this  generates the correct policy, so there's no need to
bother with setting the policy in  any other script. IMHO, it should also
work in your case.

Roland.

--
Roland Dirlewanger
CNRS - Delegation Aquitaine et Poitou-Charentes Esplanade des Arts et
Metiers
33402 TALENCE CEDEX

Mel : [email protected], Tel : 05.57.35.58.52, Fax : 05.57.35.58.01