Hallo zusammen,
dacht ich schreib mal hier, bevor ich ein neues Thema aufmache.
Wir nutzen u.A. auch bei einigen Kunden VPN mit Zertifikaten, und Lancom Gateways, was ja soweit auch perfekt funktioniert.
Seit iOS6 ist das aber mit nichten zum Laufen zu bewegen,
auf den Apple Geräten erscheitn "Kommunikation mit dem Server fehlgeschlagen",
wenn man während des Verbindungsaufbaus die Konsole (iPhone Konfiguration Tool) anschaut erschein folgendes
Code: Alles auswählen
Oct 1 13:51:54 iPad-von-xy racoon[1297] <Notice>: accepted connection on vpn control socket.
Oct 1 13:51:54 iPad-von-xy racoon[1297] <Notice>: IPSec connecting to server 217.92.34.131
Oct 1 13:51:54 iPad-von-xy racoon[1297] <Notice>: IPSec Phase1 started (Initiated by me).
Oct 1 13:51:54 iPad-von-xy racoon[1297] <Notice>: >>>>> phase change status = phase 1 started by us
Oct 1 13:51:54 iPad-von-xy configd[49] <Notice>: network changed: v4(en0:192.168.2.100, pdp_ip0) DNS* Proxy
Oct 1 13:51:54 iPad-von-xy racoon[1297] <Notice>: >>>>> phase change status = phase 1 started by peer
Oct 1 13:51:54 iPad-von-xy configd[49] <Notice>: network changed: v4(en0:192.168.2.100, pdp_ip0) DNS* Proxy
Oct 1 13:51:55 iPad-von-xy racoon[1297] <Error>: unknown Informational exchange received.
Oct 1 13:51:55 iPad-von-xy racoon[1297] <Error>: unknown Informational exchange received.
Oct 1 13:51:58 iPad-von-xy racoon[1297] <Error>: unknown Informational exchange received.
Oct 1 13:51:58 iPad-von-xy racoon[1297] <Error>: unknown Informational exchange received.
Oct 1 13:52:01 iPad-von-xy racoon[1297] <Error>: unknown Informational exchange received.
Oct 1 13:52:01 iPad-von-xy racoon[1297] <Error>: unknown Informational exchange received.
Oct 1 13:52:04 iPad-von-xy racoon[1297] <Error>: unknown Informational exchange received.
Oct 1 13:52:04 iPad-von-xy racoon[1297] <Error>: unknown Informational exchange received.
Oct 1 13:52:16 iPad-von-xy racoon[1297] <Error>: unknown Informational exchange received.
Oct 1 13:52:16 iPad-von-xy racoon[1297] <Error>: unknown Informational exchange received.
Oct 1 13:52:24 iPad-von-xy configd[49] <Notice>: IPSec disconnecting from server 111.222.333.444
Oct 1 13:52:24 iPad-von-xy configd[49] <Notice>: network changed: v4(en0:192.168.2.100, pdp_ip0) DNS* Proxy
Oct 1 13:52:24 iPad-von-xy configd[49] <Notice>: network changed: v4(en0:192.168.2.100, pdp_ip0) DNS* Proxy
Oct 1 13:52:24 iPad-von-xy racoon[1297] <Notice>: IPSec disconnecting from server 111.222.333.444
Oct 1 13:52:24 iPad-von-xy racoon[1297] <Error>: failed to send vpn_control message: Broken pipe
Oct 1 13:52:24 iPad-von-xy racoon[1297] <Warning>: glob found no matches for path "/var/run/racoon/*.conf"
Oct 1 13:52:24 iPad-von-xy racoon[1297] <Notice>: IPSec disconnecting from server 111.222.333.444
Im Router Trace erscheint folgendes:
Code: Alles auswählen
[VPN-Status] 2012/10/01 14:19:44,824
IKE info: The remote peer def-main-peer supports NAT-T in RFC mode
IKE info: The remote peer def-main-peer supports NAT-T in draft mode
IKE info: The remote peer def-main-peer supports NAT-T in draft mode
IKE info: The remote server 95.208.212.3:500 (UDP) peer def-main-peer id <no_id> supports draft-ietf-ipsec-isakmp-xauth
IKE info: The remote server 95.208.212.3:500 (UDP) peer def-main-peer id <no_id> negotiated rfc-3706-dead-peer-detection
[VPN-Status] 2012/10/01 14:19:44,825
IKE info: Phase-1 remote proposal 1 for peer def-main-peer matched with local proposal 1
[VPN-Status] 2012/10/01 14:19:45,651
IKE log: 141945.000000 Default message_recv: invalid payload type 132 in ISAKMP header (check passphrases, if applicable and in Phase 1)
[VPN-Status] 2012/10/01 14:19:45,651
IKE log: 141945.000000 Default dropped message from 95.208.212.3 port 4294950912 due to notification type INVALID_PAYLOAD_TYPE
[VPN-Status] 2012/10/01 14:19:45,651
IKE info: dropped message from peer unknown 95.208.212.3 port 4294950912 due to notification type INVALID_PAYLOAD_TYPE
[VPN-Status] 2012/10/01 14:19:45,651
IKE log: 141945.000000 Default message_recv: invalid payload type 132 in ISAKMP header (check passphrases, if applicable and in Phase 1)
[VPN-Status] 2012/10/01 14:19:45,652
IKE log: 141945.000000 Default dropped message from 95.208.212.3 port 4294950912 due to notification type INVALID_PAYLOAD_TYPE
[VPN-Status] 2012/10/01 14:19:45,652
IKE info: dropped message from peer unknown 95.208.212.3 port 4294950912 due to notification type INVALID_PAYLOAD_TYPE
[VPN-Status] 2012/10/01 14:19:48,668
IKE log: 141948.000000 Default message_recv: invalid payload type 132 in ISAKMP header (check passphrases, if applicable and in Phase 1)
[VPN-Status] 2012/10/01 14:19:48,668
IKE log: 141948.000000 Default dropped message from 95.208.212.3 port 4294950912 due to notification type INVALID_PAYLOAD_TYPE
[VPN-Status] 2012/10/01 14:19:48,668
IKE info: dropped message from peer unknown 95.208.212.3 port 4294950912 due to notification type INVALID_PAYLOAD_TYPE
[VPN-Status] 2012/10/01 14:19:48,668
IKE log: 141948.000000 Default message_recv: invalid payload type 132 in ISAKMP header (check passphrases, if applicable and in Phase 1)
[VPN-Status] 2012/10/01 14:19:48,669
IKE log: 141948.000000 Default dropped message from 95.208.212.3 port 4294950912 due to notification type INVALID_PAYLOAD_TYPE
[VPN-Status] 2012/10/01 14:19:48,669
IKE info: dropped message from peer unknown 95.208.212.3 port 4294950912 due to notification type INVALID_PAYLOAD_TYPE
[VPN-Status] 2012/10/01 14:19:50,505
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE for peer MK_WORKSTATION Seq-Nr 0x247da834, expected 0x247da834
[VPN-Status] 2012/10/01 14:19:50,505
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE_ACK sent for Phase-1 SA to peer MK_WORKSTATION, sequence nr 0x247da834
[VPN-Status] 2012/10/01 14:19:51,708
IKE log: 141951.000000 Default message_recv: invalid payload type 132 in ISAKMP header (check passphrases, if applicable and in Phase 1)
[VPN-Status] 2012/10/01 14:19:51,708
IKE log: 141951.000000 Default dropped message from 95.208.212.3 port 4294950912 due to notification type INVALID_PAYLOAD_TYPE
[VPN-Status] 2012/10/01 14:19:51,708
IKE info: dropped message from peer unknown 95.208.212.3 port 4294950912 due to notification type INVALID_PAYLOAD_TYPE
[VPN-Status] 2012/10/01 14:19:51,711
IKE log: 141951.000000 Default message_recv: invalid payload type 132 in ISAKMP header (check passphrases, if applicable and in Phase 1)
[VPN-Status] 2012/10/01 14:19:51,711
IKE log: 141951.000000 Default dropped message from 95.208.212.3 port 4294950912 due to notification type INVALID_PAYLOAD_TYPE
[VPN-Status] 2012/10/01 14:19:51,712
IKE info: dropped message from peer unknown 95.208.212.3 port 4294950912 due to notification type INVALID_PAYLOAD_TYPE
[VPN-Status] 2012/10/01 14:19:54,745
IKE log: 141954.000000 Default message_recv: invalid payload type 132 in ISAKMP header (check passphrases, if applicable and in Phase 1)
[VPN-Status] 2012/10/01 14:19:54,745
IKE log: 141954.000000 Default dropped message from 95.208.212.3 port 4294950912 due to notification type INVALID_PAYLOAD_TYPE
[VPN-Status] 2012/10/01 14:19:54,745
IKE info: dropped message from peer unknown 95.208.212.3 port 4294950912 due to notification type INVALID_PAYLOAD_TYPE
[VPN-Status] 2012/10/01 14:19:54,748
IKE log: 141954.000000 Default message_recv: invalid payload type 132 in ISAKMP header (check passphrases, if applicable and in Phase 1)
[VPN-Status] 2012/10/01 14:19:54,748
IKE log: 141954.000000 Default dropped message from 95.208.212.3 port 4294950912 due to notification type INVALID_PAYLOAD_TYPE
[VPN-Status] 2012/10/01 14:19:54,748
IKE info: dropped message from peer unknown 95.208.212.3 port 4294950912 due to notification type INVALID_PAYLOAD_TYPE
[TELNET] INFO: DISCONNECTED
Hat jemand eine Idee?
Gruss