(racoon 820) RE: Windows XP Road Warrior with x509 and/or PSK
"David Herselman" <[email protected]> Thu, 21 Oct 2004 12:08:18 +0200
| Newsgroups | gmane.network.ipv6.kame.racoon |
|---|---|
| Organization | Syrex Intranets |
| Message-ID | <[email protected]> |
Many thanks for the information, I've started reading through the document and will report back on my success... ;) Would anyone else perhaps know, as a backup to x509 certificates, how to get racoon to match the IP address as a wildcard in the psk.txt file? /etc/racoon/psk.txt: 0.0.0.0 "pre-shared-key" /var/log/messages: Oct 21 12:03:13 unix-01 racoon: INFO: isakmp.c:903:isakmp_ph1begin_r(): respond new phase 1 negotiation: 165.165.178.203[500]<=>165.165.0.36[500] Oct 21 12:03:13 unix-01 racoon: INFO: isakmp.c:908:isakmp_ph1begin_r(): begin Identity Protection mode. Oct 21 12:03:13 unix-01 racoon: INFO: vendorid.c:128:check_vendorid(): received Vendor ID: MS NT5 ISAKMPOAKLEY Oct 21 12:03:13 unix-01 racoon: ERROR: oakley.c:2098:oakley_skeyid(): couldn't find the pskey for 165.165.0.36. Oct 21 12:03:13 unix-01 racoon: ERROR: isakmp.c:636:ph1_main(): failed to process packet. Oct 21 12:03:13 unix-01 racoon: ERROR: isakmp.c:451:isakmp_main(): phase1 negotiation failed. Oct 21 12:03:20 unix-01 racoon: ERROR: isakmp.c:477:isakmp_main(): unknown Informational exchange received. Syrex Intranets - Customised Solutions David Herselman Systems Engineer cell +27 (0)82 784 7222 tel +27 (0)86 11 syrex (79739) fax +27 (0)86 12 syrex (79739) 27 7th avenue parktown north 2193 email [email protected] www.syrex.co.za -----Original Message----- From: Roland Dirlewanger [mailto:[email protected]] Sent: 21 October 2004 10:36 AM To: [email protected] Cc: [email protected] Subject: Re: (racoon 817) Windows XP Road Warrior with x509 and/or PSK David Herselman wrote: >2. I next tried getting x509 certificates to work with the Windows XP >roaming machine. I've followed several documents on how to create the >relevant certificates but none of them show the required steps in how >one gets Windows XP to 'bind' the certificate to the required VPN connection... >Windows XP doesn't even attempt the connection out as it can not locate >the right certificate. > >I found some reference to a 'mini-HOWTO with Windows XP using certificates' >but the domain doesn't exist anymore... Would someone possibly still >have this document lying around? Broken link: >http://www.fatcanary.com.au/docs/xp_freebsd_cert_ipsec.txt > > Jacco De Leeuw wrote a very good step by step guide for installing and configuring FreeSwan with L2TP/IPsec clients. The part concerning the clients is not tighted to any ISAKMP or IPsec implementation. It contains a chapter named "Importing certificates (Windows 2000/XP)" in the following page : http://www.jacco2.dds.nl/networking/win2000xp-freeswan.html >Problem is that both the host and the client machine are on Dynamic IPs >so I can not simply use the local security policy to activate the >certificate on the IPSec link based on the IP filter... > > Your racoon.conf has "generate_policy on" in phase 1. On a server with a fixed address, this generates the correct policy, so there's no need to bother with setting the policy in any other script. IMHO, it should also work in your case. Roland. -- Roland Dirlewanger CNRS - Delegation Aquitaine et Poitou-Charentes Esplanade des Arts et Metiers 33402 TALENCE CEDEX Mel : [email protected], Tel : 05.57.35.58.52, Fax : 05.57.35.58.01