Ich versuche einen VPN-Tunnel zwischen einem Lancom 1721+ VPN und einem Dr.Neuhaus Tainy Emod herzustellen. Bei dem Tainy handelt es sich um einen IP-Router mit GPRS/UMTS.
Das verwendete BS ist allem Anschein nach ein Linux - für die VPN-Funktionalität ist racoon zuständig. Bisher ist es mir nicht gelungen, einen funktionierenden VPN-Tunnel zwischen beiden System zu realisieren. Allem Anschein nach funktioniert die Phase 1 des Schlüsselaustauschs - weiter aber tut sich nichts.
Hier eingestellt ein Ausschnitt aus der VPN-Logdatei des Tainy Emods. Vielleicht liest jemand mehr daraus als ich und kann mir einen Tipp zur Konfiguration geben.
Code: Alles auswählen
Oct 12 12:50:58 dnt3173 daemon.info racoon: INFO: ISAKMP-SA expired 123.123.123.123[4500]-124.124.124.124[4500] spi:7a56da98a71ec4fc:b655943146908cd8
Oct 12 12:50:59 dnt3173 daemon.info racoon: INFO: ISAKMP-SA deleted 123.123.123.123[4500]-124.124.124.124[4500] spi:7a56da98a71ec4fc:b655943146908cd8
Oct 12 12:51:04 dnt3173 daemon.info racoon: INFO: respond new phase 1 negotiation: 123.123.123.123[500]<=>124.124.124.124[500]
Oct 12 12:51:04 dnt3173 daemon.info racoon: INFO: begin Aggressive mode.
Oct 12 12:51:04 dnt3173 daemon.info racoon: INFO: received Vendor ID: draft-ietf-ipsec-nat-t-ike-02
Oct 12 12:51:04 dnt3173 daemon.info racoon: INFO: received Vendor ID: draft-ietf-ipsec-nat-t-ike-03
Oct 12 12:51:04 dnt3173 daemon.info racoon: INFO: received Vendor ID: RFC 3947
Oct 12 12:51:04 dnt3173 daemon.info racoon: INFO: received Vendor ID: draft-ietf-ipsra-isakmp-xauth-06.txt
Oct 12 12:51:04 dnt3173 daemon.info racoon: INFO: received Vendor ID: DPD
Oct 12 12:51:04 dnt3173 daemon.info racoon: INFO: Selected NAT-T version: RFC 3947
Oct 12 12:51:05 dnt3173 daemon.notice racoon: oakley_dh_generate(MODP1024): 0.276739
Oct 12 12:51:05 dnt3173 daemon.notice racoon: oakley_dh_compute(MODP1024): 0.275534
Oct 12 12:51:05 dnt3173 daemon.notice racoon: alg_oakley_hmacdef_one(hmac_sha1 size=32): 0.000269
Oct 12 12:51:05 dnt3173 daemon.notice racoon: alg_oakley_hmacdef_one(hmac_sha1 size=145): 0.000303
Oct 12 12:51:05 dnt3173 daemon.notice racoon: alg_oakley_hmacdef_one(hmac_sha1 size=165): 0.000307
Oct 12 12:51:05 dnt3173 daemon.notice racoon: alg_oakley_hmacdef_one(hmac_sha1 size=165): 0.000306
Oct 12 12:51:05 dnt3173 daemon.notice racoon: alg_oakley_hmacdef_one(hmac_sha1 size=1): 0.000271
Oct 12 12:51:05 dnt3173 daemon.notice racoon: alg_oakley_hmacdef_one(hmac_sha1 size=20): 0.000273
Oct 12 12:51:05 dnt3173 daemon.notice racoon: alg_oakley_hmacdef_one(hmac_sha1 size=617): 0.000369
Oct 12 12:51:05 dnt3173 daemon.info racoon: INFO: Adding remote and local NAT-D payloads.
Oct 12 12:51:05 dnt3173 daemon.info racoon: INFO: Hashing 124.124.124.124[500] with algo #2 (NAT-T forced)
Oct 12 12:51:05 dnt3173 daemon.info racoon: INFO: Hashing 123.123.123.123[500] with algo #2 (NAT-T forced)
Oct 12 12:51:05 dnt3173 daemon.notice racoon: phase1(agg R msg1): 0.585814
Oct 12 12:51:06 dnt3173 daemon.info racoon: INFO: NAT-T: ports changed to: 124.124.124.124[4500]<->123.123.123.123[4500]
Oct 12 12:51:06 dnt3173 daemon.notice racoon: alg_oakley_encdef_decrypt(3des klen=192 size=72): 0.000325
Oct 12 12:51:06 dnt3173 daemon.info racoon: INFO: NAT-D payload #0 doesn't match
Oct 12 12:51:06 dnt3173 daemon.info racoon: INFO: NAT-D payload #1 doesn't match
Oct 12 12:51:06 dnt3173 daemon.info racoon: INFO: NAT detected: ME PEER
Oct 12 12:51:06 dnt3173 daemon.notice racoon: alg_oakley_hmacdef_one(hmac_sha1 size=617): 0.000381
Oct 12 12:51:06 dnt3173 daemon.notice racoon: oakley_validate_auth(pre-shared key): 0.001250
Oct 12 12:51:06 dnt3173 daemon.notice racoon: phase1(???): 0.005189
Oct 12 12:51:06 dnt3173 daemon.notice racoon: phase1(Aggressive): 1.483491
Oct 12 12:51:06 dnt3173 daemon.info racoon: INFO: ISAKMP-SA established 123.123.123.123[4500]-124.124.124.124[4500] spi:203949f18bb47926:3e35d4bdb2bbd385
Oct 12 12:51:06 dnt3173 daemon.info racoon: INFO: respond new phase 2 negotiation: 123.123.123.123[4500]<=>124.124.124.124[4500]
Oct 12 12:51:06 dnt3173 daemon.notice racoon: alg_oakley_encdef_decrypt(3des klen=192 size=544): 0.001213
Oct 12 12:51:06 dnt3173 daemon.notice racoon: alg_oakley_hmacdef_one(hmac_sha1 size=520): 0.000366
Oct 12 12:51:06 dnt3173 daemon.info racoon: ERROR: failed to get sainfo.
Oct 12 12:51:06 dnt3173 daemon.info racoon: ERROR: failed to get sainfo.
Oct 12 12:51:06 dnt3173 daemon.info racoon: ERROR: failed to pre-process packet.
Oct 12 12:51:07 dnt3173 daemon.info racoon: INFO: initiate new phase 2 negotiation: 123.123.123.123[4500]<=>124.124.124.124[4500]
Oct 12 12:51:07 dnt3173 daemon.info racoon: INFO: NAT detected -> UDP encapsulation (ENC_MODE 1->3).
Oct 12 12:51:07 dnt3173 daemon.notice racoon: oakley_dh_generate(MODP1024): 0.279098
Oct 12 12:51:07 dnt3173 daemon.notice racoon: alg_oakley_hmacdef_one(hmac_sha1 size=244): 0.000316
Oct 12 12:51:07 dnt3173 daemon.notice racoon: alg_oakley_encdef_encrypt(3des klen=192 size=272): 0.000703
Oct 12 12:51:07 dnt3173 daemon.notice racoon: phase2(quick I msg1): 0.290138
Oct 12 12:51:08 dnt3173 daemon.notice racoon: alg_oakley_encdef_decrypt(3des klen=192 size=56): 0.000310
Oct 12 12:51:08 dnt3173 daemon.notice racoon: alg_oakley_hmacdef_one(hmac_sha1 size=36): 0.000274
Oct 12 12:51:08 dnt3173 daemon.notice racoon: alg_oakley_hmacdef_one(hmac_sha1 size=36): 0.000274
Oct 12 12:51:08 dnt3173 daemon.notice racoon: alg_oakley_encdef_encrypt(3des klen=192 size=64): 0.000323
Oct 12 12:51:08 dnt3173 daemon.notice racoon: alg_oakley_encdef_decrypt(3des klen=192 size=40): 0.000289
Oct 12 12:51:08 dnt3173 daemon.notice racoon: alg_oakley_hmacdef_one(hmac_sha1 size=16): 0.000274
Oct 12 12:51:08 dnt3173 daemon.info racoon: ERROR: fatal NO-PROPOSAL-CHOSEN notify messsage, phase1 should be deleted.
Oct 12 12:51:13 dnt3173 daemon.info racoon: INFO: respond new phase 2 negotiation: 123.123.123.123[4500]<=>124.124.124.124[4500]
Oct 12 12:51:13 dnt3173 daemon.notice racoon: alg_oakley_encdef_decrypt(3des klen=192 size=544): 0.001207
Oct 12 12:51:13 dnt3173 daemon.notice racoon: alg_oakley_hmacdef_one(hmac_sha1 size=520): 0.000364
Oct 12 12:51:13 dnt3173 daemon.info racoon: ERROR: failed to get sainfo.
Oct 12 12:51:13 dnt3173 daemon.info racoon: ERROR: failed to get sainfo.
Oct 12 12:51:13 dnt3173 daemon.info racoon: ERROR: failed to pre-process packet.
Nomos