(racoon 946) Re: racoon + Cisco VPN Client

Aidas Kasparas <[email protected]> Tue, 12 Jul 2005 07:02:57 +0300
Newsgroups gmane.network.ipv6.kame.racoon
Message-ID <[email protected]>

Sergiy Lozovsky wrote:
>=20
>=20
> Hi,
>=20
> =20
>=20
> I try to use Cisco VPN Client with racoon. From what I can see raccoon
> supports CISCO Client only in a hybrid mode.
>=20
> CISCO Client can be set up for =E2=80=98Group Authentication=E2=80=99 (=
without any
> certificates). When it connects to raccoon =E2=80=93 phase 1 is ok, but=
 after
> that CISCO complains:
>=20
> =20
>=20
> 89     14:51:36.546  07 /11/05   Sev=3DInfo/4 IKE/0x63000017
>=20
> Marking IKE SA for deletion  (I_Cookie=3D434DF5DFB40ECB39
> R_Cookie=3DCF982318DD2078D0) reason =3D DEL_REASON_NON_UNITY_PEER
>=20
> =20
>=20
> It expects VENDORID_UNITY from us. Racoon sets VENDORID_UNITY only for =
a
> hybrid authentication. Can someone clarify:
>=20
> =20

Because it needs us to tell him what crypto parameters should used (I
did not find in that client a place to specify remote networks with whom
to crypt traffic, just gateway).

I'm not sure, but most likely that part which tells it parameters is
called "unity".

>=20
>    1. What is VENDORID_UNITY means? Hybrid auth? Or anything else?
>    2. Can CISCO Client work with raccoon using just shared key?
>=20
	Don't think it's possible.

--=20
Aidas Kasparas
IT administrator
GM Consult Group, UAB