So, jetzt ist der Fehler wieder aufgetreten. Folgendes hat der Tracer aufgezeichnet:
Code: Alles auswählen
[VPN-Status] 2014/11/21 11:32:21,341 Devicetime: 2014/11/21 11:32:27,352
VPN: GEGENSTELLE (1.1.1.1) disconnected
[VPN-Status] 2014/11/21 11:39:51,560 Devicetime: 2014/11/21 11:39:57,534
IKE info: Phase-1 remote proposal 1 for peer GEGENSTELLE matched with local proposal 1
[VPN-Status] 2014/11/21 11:39:51,591 Devicetime: 2014/11/21 11:39:57,589
IKE info: Phase-1 [responder] for peer GEGENSTELLE initiator id 172.16.a.b, responder id 2.2.2.2
IKE info: initiator cookie: 0xef666e83c40e6971, responder cookie: 0x94d23095e4095573
IKE info: SA ISAKMP for peer GEGENSTELLE encryption aes-cbc authentication SHA1
IKE info: life time ( 86400 sec/ 0 kb)
[VPN-Status] 2014/11/21 11:39:51,591 Devicetime: 2014/11/21 11:39:57,589
IKE info: Phase-1 SA Rekeying Timeout (Soft-Event) for peer GEGENSTELLE set to 77760 seconds (Responder)
[VPN-Status] 2014/11/21 11:39:51,591 Devicetime: 2014/11/21 11:39:57,589
IKE info: Phase-1 SA Timeout (Hard-Event) for peer GEGENSTELLE set to 86400 seconds (Responder)
[VPN-Status] 2014/11/21 11:39:51,591 Devicetime: 2014/11/21 11:39:57,616
IKE info: Phase-2 failed for peer GEGENSTELLE: no rule matches the phase-2 ids 172.16.0.0/255.255.0.0 <-> 10.x.x.x/255.255.255.0
IKE log: 113957.616072 Default message_negotiate_sa: no compatible proposal found
IKE log: 113957.616115 Default dropped message from 1.1.1.1 port 500 due to notification type NO_PROPOSAL_CHOSEN
[VPN-Status] 2014/11/21 11:39:51,591 Devicetime: 2014/11/21 11:39:57,616
policy manager error indication: GEGENSTELLE (1.1.1.1), cause: 12801
[VPN-Status] 2014/11/21 11:39:51,591 Devicetime: 2014/11/21 11:39:57,616
VPN: WAN state changed to WanCalled for GEGENSTELLE (1.1.1.1), called by: 009cba0c
[VPN-Status] 2014/11/21 11:39:51,591 Devicetime: 2014/11/21 11:39:57,618
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for GEGENSTELLE (1.1.1.1)
[VPN-Status] 2014/11/21 11:39:51,591 Devicetime: 2014/11/21 11:39:57,618
vpn-maps[25], remote: GEGENSTELLE, idle, static-name
[VPN-Status] 2014/11/21 11:39:51,591 Devicetime: 2014/11/21 11:39:57,620
selecting next remote gateway using strategy eFirst for GEGENSTELLE
=> no remote gateway selected
[VPN-Status] 2014/11/21 11:39:51,591 Devicetime: 2014/11/21 11:39:57,620
selecting first remote gateway using strategy eFirst for GEGENSTELLE
=> CurrIdx=0, IpStr=>1.1.1.1<, IpAddr=1.1.1.1, IpTtl=0s
[VPN-Status] 2014/11/21 11:39:51,591 Devicetime: 2014/11/21 11:39:57,621
VPN: installing ruleset for GEGENSTELLE (1.1.1.1)
[VPN-Status] 2014/11/21 11:39:51,591 Devicetime: 2014/11/21 11:39:57,621
VPN: WAN state changed to WanDisconnect for GEGENSTELLE (1.1.1.1), called by: 009cba0c
[VPN-Status] 2014/11/21 11:39:51,591 Devicetime: 2014/11/21 11:39:57,621
VPN: WAN state changed to WanIdle for GEGENSTELLE (1.1.1.1), called by: 009cba0c
[VPN-Status] 2014/11/21 11:39:53,748 Devicetime: 2014/11/21 11:39:59,616
IKE info: Phase-2 failed for peer GEGENSTELLE: no rule matches the phase-2 ids 172.16.0.0/255.255.0.0 <-> 10.x.x.x/255.255.255.0
IKE log: 113959.616398 Default message_negotiate_sa: no compatible proposal found
IKE log: 113959.616442 Default dropped message from 1.1.1.1 port 500 due to notification type NO_PROPOSAL_CHOSEN
[VPN-Status] 2014/11/21 11:39:53,748 Devicetime: 2014/11/21 11:39:59,616
policy manager error indication: GEGENSTELLE (1.1.1.1), cause: 12801
[VPN-Status] 2014/11/21 11:39:53,748 Devicetime: 2014/11/21 11:39:59,616
VPN: WAN state changed to WanCalled for GEGENSTELLE (1.1.1.1), called by: 009cba0c
[VPN-Status] 2014/11/21 11:39:53,748 Devicetime: 2014/11/21 11:39:59,616
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for GEGENSTELLE (1.1.1.1)
[VPN-Status] 2014/11/21 11:39:55,826 Devicetime: 2014/11/21 11:40:01,616
IKE info: Phase-2 failed for peer GEGENSTELLE: no rule matches the phase-2 ids 172.16.0.0/255.255.0.0 <-> 10.x.x.x/255.255.255.0
IKE log: 114001.616290 Default message_negotiate_sa: no compatible proposal found
IKE log: 114001.616333 Default dropped message from 1.1.1.1 port 500 due to notification type NO_PROPOSAL_CHOSEN
[VPN-Status] 2014/11/21 11:39:55,826 Devicetime: 2014/11/21 11:40:01,616
policy manager error indication: GEGENSTELLE (1.1.1.1), cause: 12801
[VPN-Status] 2014/11/21 11:39:55,826 Devicetime: 2014/11/21 11:40:01,616
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for GEGENSTELLE (1.1.1.1)
[VPN-Status] 2014/11/21 11:39:57,794 Devicetime: 2014/11/21 11:40:03,616
IKE info: Phase-2 failed for peer GEGENSTELLE: no rule matches the phase-2 ids 172.16.0.0/255.255.0.0 <-> 10.x.x.x/255.255.255.0
IKE log: 114003.616712 Default message_negotiate_sa: no compatible proposal found
IKE log: 114003.616755 Default dropped message from 1.1.1.1 port 500 due to notification type NO_PROPOSAL_CHOSEN
[VPN-Status] 2014/11/21 11:39:57,794 Devicetime: 2014/11/21 11:40:03,617
policy manager error indication: GEGENSTELLE (1.1.1.1), cause: 12801
[VPN-Status] 2014/11/21 11:39:57,794 Devicetime: 2014/11/21 11:40:03,617
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for GEGENSTELLE (1.1.1.1)
[VPN-Status] 2014/11/21 11:39:59,873 Devicetime: 2014/11/21 11:40:05,616
IKE info: Phase-2 failed for peer GEGENSTELLE: no rule matches the phase-2 ids 172.16.0.0/255.255.0.0 <-> 10.x.x.x/255.255.255.0
IKE log: 114005.616531 Default message_negotiate_sa: no compatible proposal found
IKE log: 114005.616575 Default dropped message from 1.1.1.1 port 500 due to notification type NO_PROPOSAL_CHOSEN
[VPN-Status] 2014/11/21 11:39:59,873 Devicetime: 2014/11/21 11:40:05,616
policy manager error indication: GEGENSTELLE (1.1.1.1), cause: 12801
[VPN-Status] 2014/11/21 11:39:59,873 Devicetime: 2014/11/21 11:40:05,616
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for GEGENSTELLE (1.1.1.1)
[VPN-Status] 2014/11/21 11:40:01,841 Devicetime: 2014/11/21 11:40:07,616
IKE info: Phase-2 failed for peer GEGENSTELLE: no rule matches the phase-2 ids 172.16.0.0/255.255.0.0 <-> 10.x.x.x/255.255.255.0
IKE log: 114007.616998 Default message_negotiate_sa: no compatible proposal found
IKE log: 114007.617041 Default dropped message from 1.1.1.1 port 500 due to notification type NO_PROPOSAL_CHOSEN
[VPN-Status] 2014/11/21 11:40:01,841 Devicetime: 2014/11/21 11:40:07,617
policy manager error indication: GEGENSTELLE (1.1.1.1), cause: 12801
[VPN-Status] 2014/11/21 11:40:01,841 Devicetime: 2014/11/21 11:40:07,617
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for GEGENSTELLE (1.1.1.1)
[VPN-Status] 2014/11/21 11:40:03,919 Devicetime: 2014/11/21 11:40:09,617
IKE info: Phase-2 failed for peer GEGENSTELLE: no rule matches the phase-2 ids 172.16.0.0/255.255.0.0 <-> 10.x.x.x/255.255.255.0
IKE log: 114009.617897 Default message_negotiate_sa: no compatible proposal found
IKE log: 114009.617940 Default dropped message from 1.1.1.1 port 500 due to notification type NO_PROPOSAL_CHOSEN
[VPN-Status] 2014/11/21 11:40:03,919 Devicetime: 2014/11/21 11:40:09,618
policy manager error indication: GEGENSTELLE (1.1.1.1), cause: 12801
[VPN-Status] 2014/11/21 11:40:03,919 Devicetime: 2014/11/21 11:40:09,618
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for GEGENSTELLE (1.1.1.1)
[VPN-Status] 2014/11/21 11:40:07,857 Devicetime: 2014/11/21 11:40:13,617
IKE info: Phase-2 failed for peer GEGENSTELLE: no rule matches the phase-2 ids 172.16.0.0/255.255.0.0 <-> 10.x.x.x/255.255.255.0
IKE log: 114013.617977 Default message_negotiate_sa: no compatible proposal found
IKE log: 114013.618020 Default dropped message from 1.1.1.1 port 500 due to notification type NO_PROPOSAL_CHOSEN
[VPN-Status] 2014/11/21 11:40:07,857 Devicetime: 2014/11/21 11:40:13,618
policy manager error indication: GEGENSTELLE (1.1.1.1), cause: 12801
[VPN-Status] 2014/11/21 11:40:07,857 Devicetime: 2014/11/21 11:40:13,618
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for GEGENSTELLE (1.1.1.1)
[VPN-Status] 2014/11/21 11:40:11,794 Devicetime: 2014/11/21 11:40:17,618
IKE info: Phase-2 failed for peer GEGENSTELLE: no rule matches the phase-2 ids 172.16.0.0/255.255.0.0 <-> 10.x.x.x/255.255.255.0
IKE log: 114017.618202 Default message_negotiate_sa: no compatible proposal found
IKE log: 114017.618245 Default dropped message from 1.1.1.1 port 500 due to notification type NO_PROPOSAL_CHOSEN
[VPN-Status] 2014/11/21 11:40:11,794 Devicetime: 2014/11/21 11:40:17,618
policy manager error indication: GEGENSTELLE (1.1.1.1), cause: 12801
[VPN-Status] 2014/11/21 11:40:11,794 Devicetime: 2014/11/21 11:40:17,618
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for GEGENSTELLE (1.1.1.1)
[VPN-Status] 2014/11/21 11:40:15,732 Devicetime: 2014/11/21 11:40:21,618
IKE info: Phase-2 failed for peer GEGENSTELLE: no rule matches the phase-2 ids 172.16.0.0/255.255.0.0 <-> 10.x.x.x/255.255.255.0
IKE log: 114021.618572 Default message_negotiate_sa: no compatible proposal found
IKE log: 114021.618614 Default dropped message from 1.1.1.1 port 500 due to notification type NO_PROPOSAL_CHOSEN
[VPN-Status] 2014/11/21 11:40:15,732 Devicetime: 2014/11/21 11:40:21,618
policy manager error indication: GEGENSTELLE (1.1.1.1), cause: 12801
[VPN-Status] 2014/11/21 11:40:15,732 Devicetime: 2014/11/21 11:40:21,618
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for GEGENSTELLE (1.1.1.1)
[VPN-Status] 2014/11/21 11:40:19,888 Devicetime: 2014/11/21 11:40:25,618
IKE info: Phase-2 failed for peer GEGENSTELLE: no rule matches the phase-2 ids 172.16.0.0/255.255.0.0 <-> 10.x.x.x/255.255.255.0
IKE log: 114025.619005 Default message_negotiate_sa: no compatible proposal found
IKE log: 114025.619048 Default dropped message from 1.1.1.1 port 500 due to notification type NO_PROPOSAL_CHOSEN
[VPN-Status] 2014/11/21 11:40:19,888 Devicetime: 2014/11/21 11:40:25,619
policy manager error indication: GEGENSTELLE (1.1.1.1), cause: 12801
[VPN-Status] 2014/11/21 11:40:19,888 Devicetime: 2014/11/21 11:40:25,619
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for GEGENSTELLE (1.1.1.1)
[VPN-Status] 2014/11/21 11:40:23,716 Devicetime: 2014/11/21 11:40:29,619
IKE info: Phase-2 failed for peer GEGENSTELLE: no rule matches the phase-2 ids 172.16.0.0/255.255.0.0 <-> 10.x.x.x/255.255.255.0
IKE log: 114029.619574 Default message_negotiate_sa: no compatible proposal found
IKE log: 114029.619618 Default dropped message from 1.1.1.1 port 500 due to notification type NO_PROPOSAL_CHOSEN
[VPN-Status] 2014/11/21 11:40:23,716 Devicetime: 2014/11/21 11:40:29,619
policy manager error indication: GEGENSTELLE (1.1.1.1), cause: 12801
[VPN-Status] 2014/11/21 11:40:23,716 Devicetime: 2014/11/21 11:40:29,619
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for GEGENSTELLE (1.1.1.1)
[TraceStopped] 2014/11/21 16:00:33,357
Used config:
# Trace config
trace + VPN-Status @ GEGENSTELLE
Unser Partner hatte mir als zusätzliche "VPN-ID" die 172.16.a.b genannt. Damit konnte ich nichts anfangen, d.h. ich konnte es in der LANCOM-Konfiguration nirgends unterbringen.