Hallo...
So habe ich mal nur ein Trace auf dem 1821 gemacht und den Filter für den 3850 gesetzt...
Also irgendwie schickt der 1821 ja den Poll zum 3850, der antwortet jedoch nicht... und deshalb wird der VPN nach 5 Versuchen vom 1821 terminiert.
Was ich nicht verstehe... warum er den 3850 nicht erreicht.... also ich habe schon die Firewall usw. deaktiviert, aber es haut trotzdem nicht hin....
VPN-Status OFF
VPN-Packet OFF
VPN-Status ON @ 1821_01 3850_05
root@1821_01:/
>
[VPN-Status] 2008/02/09 11:01:58,160
IKE info: Phase-1 [responder] for peer 3850_05 between initiator id 3850_05@lanc
om.de, responder id
1821_01@lancom.de done
IKE info: SA ISAKMP for peer 3850_05 encryption aes-cbc authentication md5
IKE info: life time ( 108000 sec/ 0 kb)
[VPN-Status] 2008/02/09 11:01:58,250
IKE info: Phase-2 remote proposal 1 for peer 3850_05 matched with local proposal
1
[VPN-Status] 2008/02/09 11:01:58,420
IKE info: Phase-2 [responder] done with 2 SAS for peer 3850_05 rule ipsec-2-3850
_05-pr0-l0-r0
IKE info: rule:' ipsec 192.168.1.0/255.255.255.0 <-> 192.168.5.0/255.255.255.0 '
IKE info: SA ESP [0x1ef8db86] alg AES keylength 128 +hmac HMAC_M
IKE info: SA ESP [0x3cb742d1] alg AES keylength 128 +hmac HMAC_MD5 incoming
IKE info: life soft( 1800 sec/180000 kb) hard (2000 sec/200000 kb)
IKE info: tunnel between src: 87.xxx.xxx.xx dst: 90.187.104.138
[VPN-Status] 2008/02/09 11:01:58,430
VPN: wait for IKE negotiation from 3850_05 (90.187.104.138)
A new configuration is being uploaded ...
[VPN-Status] 2008/02/09 11:01:59,440
VPN: 3850_05 (90.187.104.138) connected, set poll timer to 30 sec
Configuration has been uploaded successfully
[VPN-Status] 2008/02
VPN: selecting first remote gateway using strategy eFirst for 3850_05
=> no remote gateway selected
[VPN-Status] 2008/02/09 11:02:04,440
VPN: poll timeout for 3850_05 (90.187.104.138)
send poll frame to 90.187.104.138
[VPN-Status] 2008/02/09 11:02:34,440
VPN: poll timeout for 3850_05 (90.187.104.138)
remote site did not answer during interval
setting poll time to 1 sec.
(5 retries left)
send poll frame to 90.187.104.138
[VPN-Status] 2008/02/09 11:02:35,440
VPN: poll timeout for 3850_05 (90.187.104.138)
remote site did not answer during interval
(4 retries left)
send poll frame to 90.187.104.138
[VPN-Status] 2008/02/09 11:02:36,440
VPN: poll timeout for 3850_05 (90.187.104.138)
remote site did not answer during interval
(3 retries left)
send poll frame to 90.187.104.138
[VPN-Status] 2008/02/09 11:02:37,440
VPN: poll timeout for 3850_05 (90.187.104.138)
remote site did not answer during interval
(2 retries left)
send poll frame to 90.187.104.138
[VPN-Status] 2008/02/09 11:02:38,440
VPN: poll timeout for 3850_05 (
remote site did not answer during interval
(1 retries left)
send poll frame to 90.187.104.138
[VPN-Status] 2008/02/09 11:02:39,440
VPN: poll timeout for 3850_05 (90.187.104.138)
remote site did not answer during interval
no retries left, disconnect channel
[VPN-Status] 2008/02/09 11:02:39,450
VPN: Error: IFC-X-Line-polling-failed (0x1307) for 3850_05 (90.187.104.138)
[VPN-Status] 2008/02/09 11:02:39,450
VPN: disconnecting 3850_05 (90.187.104.138)
[VPN-Status] 2008/02/09 11:02:39,450
VPN: Error: (unknown) (0x0301) for 3850_05 (90.187.104.138)
[VPN-Status] 2008/02/09 11:02:39,460
IKE info: Delete Notificaton sent for Phase-2 SA ipsec-2-3850_05-pr0-l0-r0 to pe
er 3850_05, spi [0x3cb742d1]
[VPN-Status] 2008/02/09 11:02:39,460
IKE info: Phase-2 SA removed: peer 3850_05 rule ipsec-2-3850_05-pr0-l0-r0 remove
d
IKE info: containing Protocol IPSEC_ESP, with spis [1ef8db86 ] [3cb742d1 ]
[VPN-Status] 2008/02/09 11:02:39,460
IKE info: Delete Notificaton sent for Phase-1 SA to peer 3850_05
[VPN-Status] 2008/02/09 11:02:39,460
IKE info: Phase-1 SA removed: peer 3850_05 rule 3850_05 removed
[VPN-Status] 2008/02/09 11:02:39,500
VPN: selecting first remote gateway using strategy eFirst for 3850_05
=> no remote gateway selected
[VPN-Status] 2008/02/09 11:02:39,500
VPN: installing ruleset for 3850_05 (0.0.0.0)
[VPN-Status] 2008/02/09 11:02:39,510
VPN: 3850_05 (0.0.0.0) disconnected
[VPN-Status] 2008/02/09 11:02:42,030
IKE info: Phase-1 [responder] for peer 3850_05 between initiator id 3850_05@lan
om.de, responder id
1821_01@lancom.de done
IKE info: SA ISAKMP for peer 3850_05 encryption aes-cbc authentication md5
IKE info: life time ( 108000 sec/ 0 kb)
[VPN-Status] 2008/02/09 11:02:42,040
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE sent for Phase-1 SA to peer 3850_05, seque
nce nr 0x3ee1f92c
[VPN-Status] 2008/02/09 11:02:42,110
IKE info: Phase-2 remote proposal 1 for peer 3850_05 matched with local proposal
1
[VPN-Status] 2008/02/09 11:02:42,280
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE_
05 Seq-Nr 0x3ee1f92c, expected 0x3ee1f92c
[VPN-Status] 2008/02/09 11:02:42,290
IKE info: Phase-2 [responder] done with 2 SAS for peer 3850_05 rule ipsec-2-3850
_05-pr0-l0-r0
IKE info: rule:' ipsec 192.168.1.0/255.255.255.0 <-> 192.168.5.0/255.255.255.0 '
IKE info: SA ESP [0x3857768c] alg AES keylength 128 +hmac HMAC_MD5 outgoing
IKE info: SA ESP [0x240cb60f] alg AES keylength 128 +hmac HMAC_MD5 incoming
IKE info: life soft( 1800 sec/180000 kb) hard (2000 sec/200000 kb)
IKE info: tunnel between src: 87.139.13
[VPN-Status] 2008/02/09 11:02:42,290
VPN: wait for IKE negotiation from 3850_05 (90.187.104.138)
[VPN-Status] 2008/02/09 11:02:43,310
VPN: 3850_05 (90.187.104.138) connected, set poll timer to 30 sec
[VPN-Status] 2008/02/09 11:02:48,310
VPN: poll timeout for 3850_05 (90.187.104.138)
send poll frame to 90.187.104.138
[VPN-Status] 2008/02/09 11:03:18,310
VPN: poll timeout for 3850_05 (90.187.104.138)
remote site did not answer during interval
setting poll time to 1 sec.
(5 retries left)
send poll frame to 90.187.
[VPN-Status] 2008/02/09 11:03:19,310
VPN: poll timeout for 3850_05 (90.187.104.138)
remote site did not answer during interval
(4 retries left)
send poll frame to 90.187.104.138
[VPN-Status] 2008/02/09 11:03:20,310
VPN: poll timeout for 3850_05 (90.187.104.138)
remote site did not answer during interval
(3 retries left)
send poll frame to 90.187.104.138
[VPN-Status] 2008/02/09 11:03:21,310
VPN: poll timeout for 3850_05 (90.187.104.138)
remote site did not answer during interval
(2 retries left)
send poll frame to
[VPN-Status] 2008/02/09 11:03:22,310
VPN: poll timeout for 3850_05 (90.187.104.138)
remote site did not answer during interval
(1 retries left)
send poll frame to 90.187.104.138
[VPN-Status] 2008/02/09 11:03:23,310
VPN: poll timeout for 3850_05 (90.187.104.138)
remote site did not answer during interval
no retries left, disconnect channel
[VPN-Status] 2008/02/09 11:03:23,320
VPN: Error: IFC-X-Line-polling-failed (0x1307) for 3850_05 (90.187.104.138)
[VPN-Status] 2008/02/09 11:03:23,320
VPN: disconnecting 3850_0
[VPN-Status] 2008/02/09 11:03:23,320
VPN: Error: (unknown) (0x0301) for 3850_05 (90.187.104.138)
[VPN-Status] 2008/02/09 11:03:23,330
IKE info: Delete Notificaton sent for Phase-2 SA ipsec-2-3850_05-pr0-l0-r0 to pe
er 3850_05, spi [0x240cb60f]
[VPN-Status] 2008/02/09 11:03:23,330
IKE info: Phase-2 SA removed: peer 3850_05 rule ipsec-2-3850_05-pr0-l0-r0 remove
d
IKE info: containing Protocol IPSEC_ESP, with spis [3857768c ] [240cb60f ]
[VPN-Status] 2008/02/09 11:03:23,330
IKE info: Delete Notificaton sent fo
[VPN-Status] 2008/02/09 11:03:23,330
IKE info: Phase-1 SA removed: peer 3850_05 rule 3850_05 removed
[VPN-Status] 2008/02/09 11:03:23,370
VPN: selecting first remote gateway using strategy eFirst for 3850_05
=> no remote gateway selected
[VPN-Status] 2008/02/09 11:03:23,370
VPN: installing ruleset for 3850_05 (0.0.0.0)
[VPN-Status] 2008/02/09 11:03:23,380
VPN: 3850_05 (0.0.0.0) disconnected
[VPN-Status] 2008/02/09 11:03:25,870
IKE info: Phase-1 [responder] for peer 3850_05 between initiator id 3850_05@la
om.de, responder id
1821_01@lancom.de done
IKE info: SA ISAKMP for peer 3850_05 encryption aes-cbc authentication md5
IKE info: life time ( 108000 sec/ 0 kb)
[VPN-Status] 2008/02/09 11:03:25,950
IKE info: Phase-2 remote proposal 1 for peer 3850_05 matched with local proposal
1
[VPN-Status] 2008/02/09 11:03:26,130
IKE info: Phase-2 [responder] done with 2 SAS for peer 3850_05 rule ipsec-2-3850
_05-pr0-l0-r0
IKE info: rule:' ipsec 192.168.1.0/255.255.255.0 <-> 192.168.5.0/255.255.255.0 '
IKE info: SA ESP [0x5bc28195] alg AES keylength 128 +hmac HMAC_MD5 outgoing
IKE info: SA ESP [0x468ffc33] alg AES keylength 128 +hmac HMAC_MD5 incoming
IKE info: life soft( 1800 sec/180000 kb) hard (2000 sec/200000 kb)
IKE info: tunnel between src: 87.xxx.xxx.xx dst: 90.187.104.138
[VPN-Status] 2008/02/09 11:03:26,130
VPN: wait for IKE negotiation from 3850_05 (90.187.104.138)
[VPN-Status] 2008/02/09 11:03:27,140
VPN: 3850_05 (90.187.104.138) connected, set poll timer to 30 sec
[VPN-Status] 2008/02/09 11:03:
VPN: poll timeout for 3850_05 (90.187.104.138)
send poll frame to 90.187.104.138
[VPN-Status] 2008/02/09 11:04:02,140
VPN: poll timeout for 3850_05 (90.187.104.138)
remote site did not answer during interval
setting poll time to 1 sec.
(5 retries left)
send poll frame to 90.187.104.138
[VPN-Status] 2008/02/09 11:04:03,140
VPN: poll timeout for 3850_05 (90.187.104.138)
remote site did not answer during interval
(4 retries left)
send poll frame to 90.187.104.138
[VPN-Status] 2008/02/09 11:04:04,140
VPN: poll timeout for 3850_05 (90.187.104.138)
remote site did not answer during interval
(3 retries left)
send poll frame to 90.187.104.138
[VPN-Status] 2008/02/09 11:04:05,140
VPN: poll timeout for 3850_05 (90.187.104.138)
remote site did not answer during interval
(2 retries left)
send poll frame to 90.187.104.138
[VPN-Status] 2008/02/09 11:04:06,140
VPN: poll timeout for 3850_05 (90.187.104.138)
remote site did not answer during interval
(1 retries left)
send poll frame to 90.187.104.138
[VPN-Status] 2008/02/
VPN: poll timeout for 3850_05 (90.187.104.138)
remote site did not answer during interval
no retries left, disconnect channel
[VPN-Status] 2008/02/09 11:04:07,150
VPN: Error: IFC-X-Line-polling-failed (0x1307) for 3850_05 (90.187.104.138)
[VPN-Status] 2008/02/09 11:04:07,150
VPN: disconnecting 3850_05 (90.187.104.138)
[VPN-Status] 2008/02/09 11:04:07,150
VPN: Error: (unknown) (0x0301) for 3850_05 (90.187.104.138)
[VPN-Status] 2008/02/09 11:04:07,160
IKE info: Delete Notificaton sent for Phase-2 SA ipsec-2-3850
er 3850_05, spi [0x468ffc33]
[VPN-Status] 2008/02/09 11:04:07,160
IKE info: Phase-2 SA removed: peer 3850_05 rule ipsec-2-3850_05-pr0-l0-r0 remove
d
IKE info: containing Protocol IPSEC_ESP, with spis [5bc28195 ] [468ffc33 ]
[VPN-Status] 2008/02/09 11:04:07,160
IKE info: Delete Notificaton sent for Phase-1 SA to peer 3850_05
[VPN-Status] 2008/02/09 11:04:07,160
IKE info: Phase-1 SA removed: peer 3850_05 rule 3850_05 removed
[VPN-Status] 2008/02/09 11:04:07,200
VPN: selecting first remote gateway using strat
=> no remote gateway selected
[VPN-Status] 2008/02/09 11:04:07,200
VPN: installing ruleset for 3850_05 (0.0.0.0)
[VPN-Status] 2008/02/09 11:04:07,210
VPN: 3850_05 (0.0.0.0) disconnected
[VPN-Status] 2008/02/09 11:04:09,560
IKE info: Phase-1 [responder] for peer 3850_05 between initiator id 3850_05@lanc
om.de, responder id
1821_01@lancom.de done
IKE info: SA ISAKMP for peer 3850_05 encryption aes-cbc authentication md5
IKE info: life time ( 108000 sec/ 0 kb)
[VPN-Status] 2008/02/09 11:04:09,570
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE sent for Phase-1 SA to peer 3850_05, seque
nce nr 0x67757933
[VPN-Status] 2008/02/09 11:04:09,640
IKE info: Phase-2 remote proposal 1 for peer 3850_05 matched with local proposal
1
[VPN-Status] 2008/02/09 11:04:09,810
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE_ACK for peer 3850_
05 Seq-Nr 0x67757933, expected 0x67757933
[VPN-Status] 2008/02/09 11:04:09,820
IKE info: Phase-2 [responder] done with 2 SAS for peer 3850_05 rule ipsec-2-3850
_05-pr0-l0-r0
IKE info: rule:' ipsec 192.168.1.0/255.255.255.0 <-> 192.168.5.0/255.255.255.0 '
IKE info: SA ESP [0x1dbee107] alg AES keylength 128 +hmac HMAC_MD5 outgoing
IKE info: SA ESP [0x17c847c7] alg AES keylength 128 +hmac HMAC_MD5 incoming
IKE info: life soft( 1800 sec/180000 kb) hard (2000 sec/200000 kb)
IKE info: tunnel between src: 87.xxx.xxx.xx dst: 90.187.104.138
[VPN-Status] 2008/02/09 11:04:09,830
VPN: wait for IKE negotiation from 3850_05 (90.187.104.138)
[VPN-Status] 2008/02/09 11:04:10,840
VPN: 3850_05 (90.187.104.138) connected, set poll timer to 30 sec
[VPN-Status] 2008/02/09 11:04:15,840
VPN: poll timeout for 3850_05 (90.187.104.138)
send poll frame to 90.187.104.138
[VPN-Status] 2008/02/09 11:04:45,840
VPN: poll timeout for 3850_05 (90.187.104.138)
remote site did not answer during interval
setting poll time to 1 sec.
(5 retries left)
send poll frame to 90.187.104.138
[VPN-Status] 2008/02/09 11:04:46,840
VPN: poll timeout for 3850_05 (90.187.104.138)
remote site did not answer during interval
(4 retries left)
send poll frame to 90.187.104.138
[VPN-Status] 2008/02/09 11:04:47,840
VPN: poll timeout for 3850_05 (90.187.104.138)
remote site did not answer during interval
(3 retries left)
send poll frame to 90.187.104.138
[VPN-Status] 2008/02/09 11:04:48,840
VPN: poll timeout for 3850_05 (90.187.104.138)
remote site did not answer during interval
(2 retries left)
send poll frame to 90.187.104.138
[VPN-Status] 2008/02/09 11:04:49,840
VPN: poll timeout for 3850_05 (90.187.104.138)
remote site did not answer
(1 retries left)
send poll frame to 90.187.104.138
[VPN-Status] 2008/02/09 11:04:50,840
VPN: poll timeout for 3850_05 (90.187.104.138)
remote site did not answer during interval
no retries left, disconnect channel
[VPN-Status] 2008/02/09 11:04:50,850
VPN: Error: IFC-X-Line-polling-failed (0x1307) for 3850_05 (90.187.104.138)
[VPN-Status] 2008/02/09 11:04:50,850
VPN: disconnecting 3850_05 (90.187.104.138)
[VPN-Status] 2008/02/09 11:04:50,850
VPN: Error: (unknown) (0x0301) for 3850_05 (90.187.104.138)
[VPN-Status] 2008/02/09 11:04:50,860
IKE info: Delete Notificaton sent for Phase-2 SA ipsec-2-3850_05-pr0-l0-r0 to pe
er 3850_05, spi [0x17c847c7]
[VPN-Status] 2008/02/09 11:04:50,860
IKE info: Phase-2 SA removed: peer 3850_05 rule ipsec-2-3850_05-pr0-l0-r0 remove
d
IKE info: containing Protocol IPSEC_ESP, with spis [1dbee107 ] [17c847c7 ]
[VPN-Status] 2008/02/09 11:04:50,860
IKE info: Delete Notificaton sent for Phase-1 SA to peer 3850_05
[VPN-Status] 2008/02/09 11:04:50,860
IKE info: Phase-1 SA removed: peer 3850_05 rule 3850_05 removed
[VPN-Status] 2008/02/09 11:04:50,900
VPN: selecting first remote gateway using strategy eFirst for 3850_05
=> no remote gateway selected
[VPN-Status] 2008/02/09 11:04:50,900
VPN: installing ruleset for 3850_05 (0.0.0.0)
[VPN-Status] 2008/02/09 11:04:50,910
VPN: 3850_05 (0.0.0.0) disconnected
[VPN-Status] 2008/02/09 11:04:53,370
IKE info: Phase-1 [responder] for peer 3850_05 between initiator id 3850_05@lanc
om.de, responder id 1821_01@lancom.
IKE info: SA ISAKMP for peer 3850_05 encryption aes-cbc authentication md5
IKE info: life time ( 108000 sec/ 0 kb)
[VPN-Status] 2008/02/09 11:04:53,380
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE sent for Phase-1 SA to peer 3850_05, seque
nce nr 0x4ab69c0a
[VPN-Status] 2008/02/09 11:04:53,450
IKE info: Phase-2 remote proposal 1 for peer 3850_05 matched with local proposal
1
[VPN-Status] 2008/02/09 11:04:53,610
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE_ACK for peer 3850_
05 Seq-Nr 0x4ab69c0a, expected 0x4ab69c0a
[VPN-Status] 2008/02/09 11:04:53,630
IKE info: Phase-2 [responder] done with 2 SAS for peer 3850_05 rule ipsec-2-3850
_05-pr0-l0-r0
IKE info: rule:' ipsec 192.168.1.0/255.255.255.0 <-> 192.168.5.0/255.255.255.0 '
IKE info: SA ESP [0x1e09dba9] alg AES keylength 128 +hmac HMAC_MD5 outgoing
IKE info: SA ESP [0x064d3606] alg AES keylength 128 +hmac HMAC_MD5 incoming
IKE info: life soft( 1800 sec/180000 kb) hard (2000 sec/200000 kb)
IKE info: tunnel between src: 87.xxx.xxx.xx dst: 90.187.104.138
[VPN-Status] 2008/02/09 11:04:53,630
VPN: wait for IKE negotiation from 3850_05 (90.187.104.138)
[VPN-Status] 2008/02/09 11:04:54,640
VPN: 3850_05 (90.187.104.138) connected, set poll timer to 30 sec