Versuch 3x 1711+ VPN mit VPN zu verbinden...

Forum zum Thema allgemeinen Fragen zu VPN

Moderator: Lancom-Systems Moderatoren

Antworten
Tjaden
Beiträge: 5
Registriert: 04 Dez 2008, 01:05

Versuch 3x 1711+ VPN mit VPN zu verbinden...

Beitrag von Tjaden »

So vorweg, dass ist mein erster Versuch sowas auf die Beine zu stellen, nach nun 2 Tagen erfolglosem suchen, testen ec. mal dieser Post... :?

Nun, ich habe 3 Lancom 1711+ VPN welche sich per VPN verbinden sollen...

Es gibt Gerät A, B, C...


A = 192.168.99.7 / 255.255.255.0
(dynamische IP, Verbindung über DynDns)

B = 192.168.100.8 / 255.255.255.0 (LAN1, Eth1-3) & 192.168.0.1 / 255.255.255.0 (LAN4, Eth4, privater Modus)
(feste IP, Verbindung über Domain)

C = 192.168.252.4 / 255.255.255.0
(feste IP, Verbindung über Domain)

So, da Gerät A weit weg kommt, hab ich dies zur Zeit zu Hause zum vorinstallieren...

nun, angedacht war, Gerät A verbindet sich mit B & C, Gerät B verbindet sich mit A & C und Gerät C verbindet sich mit A & B...

Nun, zur Zeit hab ich nur Gerät A & B und versuch damit ein VPN aufzubauen, nunja, mit wenig erfolg zur Zeit...

Nun, da ich zur Zeit so quasi Hilflos dreinschau, hab ich mal ein VPN-Status Trace gemacht, mit der Hoffnung jemand könnte mich erleuchten, irgendwie tappe ich total im dunklen...

Hier das Trace...

Code: Alles auswählen

[VPN-Status] 2008/12/04 01:24:58,190
VPN: connecting to LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:24:58,210
VPN: start dynamic VPN negotiation for LC1711VPN_MG (217.7.225.1) via ICMP/UDP

[VPN-Status] 2008/12/04 01:24:58,210
VPN: create dynamic VPN V2 authentication packet for LC1711VPN_MG (217.7.225.1)
     DNS: 192.168.99.7, 0.0.0.0
     NBNS: 192.168.99.7, 0.0.0.0
     polling address: 192.168.99.7

[VPN-Status] 2008/12/04 01:24:58,210
VPN: installing ruleset for LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:24:58,220
VPN: ruleset installed for LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:24:58,220
VPN: start IKE negotiation for LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:24:58,250
VPN: rulesets installed

[VPN-Status] 2008/12/04 01:24:58,250
VPN: received dynamic VPN V2 authentication packet from LC1711VPN_MG (217.7.225.1)
     DNS: 192.168.100.8, 0.0.0.0
     NBNS: 192.168.100.8, 0.0.0.0
     polling address: 192.168.100.8

[VPN-Status] 2008/12/04 01:24:58,250
IKE info: Phase-1 negotiation started for peer LC1711VPN_MG rule isakmp-peer-LC1711VPN_MG using MAIN mode

[VPN-Status] 2008/12/04 01:24:58,280
IKE info: The remote server 217.7.225.1:500 peer LC1711VPN_MG id <no_id> is Enigmatec IPSEC version 1.5.1
IKE info: The remote server 217.7.225.1:500 peer LC1711VPN_MG id <no_id> negotiated rfc-3706-dead-peer-detection

[VPN-Status] 2008/12/04 01:24:58,280
IKE info: Phase-1 remote proposal 1 for peer LC1711VPN_MG matched with local proposal 1

[VPN-Status] 2008/12/04 01:24:58,320
IKE info: The remote server 217.7.225.1:500 peer LC1711VPN_MG id <no_id> is Enigmatec IPSEC version 1.5.1
IKE info: The remote server 217.7.225.1:500 peer LC1711VPN_MG id <no_id> negotiated rfc-3706-dead-peer-detection

[VPN-Status] 2008/12/04 01:24:58,320
IKE info: Phase-1 remote proposal 1 for peer LC1711VPN_MG matched with local proposal 1

[VPN-Status] 2008/12/04 01:24:58,680
IKE info: Phase-1 [responder] for peer LC1711VPN_MG between initiator id  217.7.225.1, responder id  88.77.0.27 done
IKE info: SA ISAKMP for peer LC1711VPN_MG encryption aes-cbc authentication md5
IKE info: life time ( 108000 sec/ 0 kb)

[VPN-Status] 2008/12/04 01:24:58,680
IKE info: Phase-1 SA Rekeying Timeout (Soft-Event) for peer LC1711VPN_MG set to 97200 seconds (Responder)

[VPN-Status] 2008/12/04 01:24:58,690
IKE info: Phase-1 SA Timeout (Hard-Event) for peer LC1711VPN_MG set to 108000 seconds (Responder)

[VPN-Status] 2008/12/04 01:24:58,690
IKE info: Phase-1 [inititiator] for peer LC1711VPN_MG between initiator id  88.77.0.27, responder id  217.7.225.1 done
IKE info: SA ISAKMP for peer LC1711VPN_MG encryption aes-cbc authentication md5
IKE info: life time ( 108000 sec/ 0 kb)

[VPN-Status] 2008/12/04 01:24:58,690
IKE info: Phase-1 SA Rekeying Timeout (Soft-Event) for peer LC1711VPN_MG set to 86400 seconds (Initiator)

[VPN-Status] 2008/12/04 01:24:58,690
IKE info: Phase-1 SA Timeout (Hard-Event) for peer LC1711VPN_MG set to 108000 seconds (Initiator)

[VPN-Status] 2008/12/04 01:24:58,760
IKE info: Phase-2 failed for peer LC1711VPN_MG: no rule matches the phase-2 ids  192.168.0.0/255.255.255.0 <->  192.168.99.0/255.255.255.0
IKE log: 012458 Default message_negotiate_sa: no compatible proposal found
IKE log: 012458 Default dropped message from 217.7.225.1 port 500 due to notification type NO_PROPOSAL_CHOSEN
IKE info: dropped message from peer LC1711VPN_MG 217.7.225.1 port 500 due to notification type NO_PROPOSAL_CHOSEN

[VPN-Status] 2008/12/04 01:24:58,770
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:24:58,770
IKE info: Phase-2 remote proposal 1 for peer LC1711VPN_MG matched with local proposal 1

[VPN-Status] 2008/12/04 01:24:58,940
IKE info: Phase-2 failed for peer LC1711VPN_MG: no rule matches the phase-2 ids  0.0.0.0/0.0.0.0 <->  192.168.99.0/255.255.255.0
IKE log: 012458 Default message_negotiate_sa: no compatible proposal found
IKE log: 012458 Default dropped message from 217.7.225.1 port 500 due to notification type NO_PROPOSAL_CHOSEN
IKE info: dropped message from peer LC1711VPN_MG 217.7.225.1 port 500 due to notification type NO_PROPOSAL_CHOSEN

[VPN-Status] 2008/12/04 01:24:58,940
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:24:58,940
IKE info: Phase-2 failed for peer LC1711VPN_MG: no rule matches the phase-2 ids  0.0.0.0/0.0.0.0 <->  192.168.99.0/255.255.255.0
IKE log: 012458 Default message_negotiate_sa: no compatible proposal found
IKE log: 012458 Default dropped message from 217.7.225.1 port 500 due to notification type NO_PROPOSAL_CHOSEN
IKE info: dropped message from peer LC1711VPN_MG 217.7.225.1 port 500 due to notification type NO_PROPOSAL_CHOSEN

[VPN-Status] 2008/12/04 01:24:58,950
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:24:58,950
IKE info: NOTIFY received of type NO_PROPOSAL_CHOSEN for peer LC1711VPN_MG

[VPN-Status] 2008/12/04 01:24:58,950
VPN: Error: IPSEC-I-No-proposal-matched (0x3102) for LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:24:58,950
IKE info: Phase-2 SA Rekeying Timeout (Soft-Event) for peer LC1711VPN_MG set to 1600 seconds (Initiator)

[VPN-Status] 2008/12/04 01:24:58,950
IKE info: Phase-2 SA Timeout (Hard-Event) for peer LC1711VPN_MG set to 2000 seconds (Initiator)

[VPN-Status] 2008/12/04 01:24:58,960
IKE info: Phase-2 [inititiator] done with 2 SAS for peer LC1711VPN_MG rule ipsec-1-LC1711VPN_MG-pr0-l0-r0
IKE info: rule:' ipsec 192.168.99.0/255.255.255.0 <-> 192.168.100.0/255.255.255.0 '
IKE info: SA ESP [0x3130bc8d]  alg AES keylength 128 +hmac HMAC_MD5 outgoing
IKE info: SA ESP [0x306cf193]  alg AES keylength 128 +hmac HMAC_MD5 incoming
IKE info: life soft( 1600 sec/160000 kb) hard (2000 sec/200000 kb)
IKE info: tunnel between src: 88.77.0.27 dst: 217.7.225.1  

[VPN-Status] 2008/12/04 01:24:59,120
IKE info: Phase-2 SA Rekeying Timeout (Soft-Event) for peer LC1711VPN_MG set to 1600 seconds (Initiator)

[VPN-Status] 2008/12/04 01:24:59,120
IKE info: Phase-2 SA Timeout (Hard-Event) for peer LC1711VPN_MG set to 2000 seconds (Initiator)

[VPN-Status] 2008/12/04 01:24:59,130
IKE info: Phase-2 [inititiator] done with 2 SAS for peer LC1711VPN_MG rule ipsec-1-LC1711VPN_MG-pr0-l0-r0
IKE info: rule:' ipsec 192.168.99.0/255.255.255.0 <-> 192.168.100.0/255.255.255.0 '
IKE info: SA ESP [0x7c45eff3]  alg AES keylength 128 +hmac HMAC_MD5 outgoing
IKE info: SA ESP [0x08f7d5a4]  alg AES keylength 128 +hmac HMAC_MD5 incoming
IKE info: life soft( 1600 sec/160000 kb) hard (2000 sec/200000 kb)
IKE info: tunnel between src: 88.77.0.27 dst: 217.7.225.1  

[VPN-Status] 2008/12/04 01:25:00,130
VPN: LC1711VPN_MG (217.7.225.1) connected, set poll timer to 30 sec

[VPN-Status] 2008/12/04 01:25:05,130
VPN: poll timeout for LC1711VPN_MG (217.7.225.1)
send poll frame to 192.168.100.8

[VPN-Status] 2008/12/04 01:25:05,170
VPN: Poll reply from LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:25:05,240
IKE info: NOTIFY received of type NO_PROPOSAL_CHOSEN for peer LC1711VPN_MG

[VPN-Status] 2008/12/04 01:25:05,260
VPN: Error: IPSEC-I-No-proposal-matched (0x3102) for LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:25:06,250
IKE info: Phase-2 failed for peer LC1711VPN_MG: no rule matches the phase-2 ids  192.168.0.0/255.255.255.0 <->  192.168.99.0/255.255.255.0
IKE log: 012506 Default message_negotiate_sa: no compatible proposal found
IKE log: 012506 Default dropped message from 217.7.225.1 port 500 due to notification type NO_PROPOSAL_CHOSEN
IKE info: dropped message from peer LC1711VPN_MG 217.7.225.1 port 500 due to notification type NO_PROPOSAL_CHOSEN

[VPN-Status] 2008/12/04 01:25:06,250
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:25:06,250
IKE info: Phase-2 failed for peer LC1711VPN_MG: no rule matches the phase-2 ids  0.0.0.0/0.0.0.0 <->  192.168.99.0/255.255.255.0
IKE log: 012506 Default message_negotiate_sa: no compatible proposal found
IKE log: 012506 Default dropped message from 217.7.225.1 port 500 due to notification type NO_PROPOSAL_CHOSEN
IKE info: dropped message from peer LC1711VPN_MG 217.7.225.1 port 500 due to notification type NO_PROPOSAL_CHOSEN

[VPN-Status] 2008/12/04 01:25:06,260
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:25:06,260
IKE info: Phase-2 failed for peer LC1711VPN_MG: no rule matches the phase-2 ids  0.0.0.0/0.0.0.0 <->  192.168.99.0/255.255.255.0
IKE log: 012506 Default message_negotiate_sa: no compatible proposal found
IKE log: 012506 Default dropped message from 217.7.225.1 port 500 due to notification type NO_PROPOSAL_CHOSEN
IKE info: dropped message from peer LC1711VPN_MG 217.7.225.1 port 500 due to notification type NO_PROPOSAL_CHOSEN

[VPN-Status] 2008/12/04 01:25:06,270
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:25:14,330
IKE info: NOTIFY received of type NO_PROPOSAL_CHOSEN for peer LC1711VPN_MG

[VPN-Status] 2008/12/04 01:25:14,330
VPN: Error: IPSEC-I-No-proposal-matched (0x3102) for LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:25:15,340
IKE info: Phase-2 failed for peer LC1711VPN_MG: no rule matches the phase-2 ids  192.168.0.0/255.255.255.0 <->  192.168.99.0/255.255.255.0
IKE log: 012515 Default message_negotiate_sa: no compatible proposal found
IKE log: 012515 Default dropped message from 217.7.225.1 port 500 due to notification type NO_PROPOSAL_CHOSEN
IKE info: dropped message from peer LC1711VPN_MG 217.7.225.1 port 500 due to notification type NO_PROPOSAL_CHOSEN

[VPN-Status] 2008/12/04 01:25:15,340
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:25:15,350
IKE info: Phase-2 failed for peer LC1711VPN_MG: no rule matches the phase-2 ids  0.0.0.0/0.0.0.0 <->  192.168.99.0/255.255.255.0
IKE log: 012515 Default message_negotiate_sa: no compatible proposal found
IKE log: 012515 Default dropped message from 217.7.225.1 port 500 due to notification type NO_PROPOSAL_CHOSEN
IKE info: dropped message from peer LC1711VPN_MG 217.7.225.1 port 500 due to notification type NO_PROPOSAL_CHOSEN

[VPN-Status] 2008/12/04 01:25:15,350
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:25:15,350
IKE info: Phase-2 failed for peer LC1711VPN_MG: no rule matches the phase-2 ids  0.0.0.0/0.0.0.0 <->  192.168.99.0/255.255.255.0
IKE log: 012515 Default message_negotiate_sa: no compatible proposal found
IKE log: 012515 Default dropped message from 217.7.225.1 port 500 due to notification type NO_PROPOSAL_CHOSEN
IKE info: dropped message from peer LC1711VPN_MG 217.7.225.1 port 500 due to notification type NO_PROPOSAL_CHOSEN

[VPN-Status] 2008/12/04 01:25:15,360
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:25:25,420
IKE info: NOTIFY received of type NO_PROPOSAL_CHOSEN for peer LC1711VPN_MG

[VPN-Status] 2008/12/04 01:25:25,420
VPN: Error: IPSEC-I-No-proposal-matched (0x3102) for LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:25:26,430
IKE info: Phase-2 failed for peer LC1711VPN_MG: no rule matches the phase-2 ids  192.168.0.0/255.255.255.0 <->  192.168.99.0/255.255.255.0
IKE log: 012526 Default message_negotiate_sa: no compatible proposal found
IKE log: 012526 Default dropped message from 217.7.225.1 port 500 due to notification type NO_PROPOSAL_CHOSEN
IKE info: dropped message from peer LC1711VPN_MG 217.7.225.1 port 500 due to notification type NO_PROPOSAL_CHOSEN

[VPN-Status] 2008/12/04 01:25:26,430
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:25:26,430
IKE info: Phase-2 failed for peer LC1711VPN_MG: no rule matches the phase-2 ids  0.0.0.0/0.0.0.0 <->  192.168.99.0/255.255.255.0
IKE log: 012526 Default message_negotiate_sa: no compatible proposal found
IKE log: 012526 Default dropped message from 217.7.225.1 port 500 due to notification type NO_PROPOSAL_CHOSEN
IKE info: dropped message from peer LC1711VPN_MG 217.7.225.1 port 500 due to notification type NO_PROPOSAL_CHOSEN

[VPN-Status] 2008/12/04 01:25:26,440
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:25:26,440
IKE info: Phase-2 failed for peer LC1711VPN_MG: no rule matches the phase-2 ids  0.0.0.0/0.0.0.0 <->  192.168.99.0/255.255.255.0
IKE log: 012526 Default message_negotiate_sa: no compatible proposal found
IKE log: 012526 Default dropped message from 217.7.225.1 port 500 due to notification type NO_PROPOSAL_CHOSEN
IKE info: dropped message from peer LC1711VPN_MG 217.7.225.1 port 500 due to notification type NO_PROPOSAL_CHOSEN

[VPN-Status] 2008/12/04 01:25:26,450
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:25:35,130
VPN: poll timeout for LC1711VPN_MG (217.7.225.1)
remote site answered during intervall
send poll frame to 192.168.100.8

[VPN-Status] 2008/12/04 01:25:35,170
VPN: Poll reply from LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:25:58,450
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE sent for Phase-1 SA to peer LC1711VPN_MG, sequence nr 0x15155659

[VPN-Status] 2008/12/04 01:25:58,490
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE_ACK for peer LC1711VPN_MG Seq-Nr 0x15155659, expected 0x15155659

[VPN-Status] 2008/12/04 01:25:59,500
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE for peer LC1711VPN_MG Seq-Nr 0x7a2b5f69, expected 0x7a2b5f69

[VPN-Status] 2008/12/04 01:25:59,500
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE_ACK sent for Phase-1 SA to peer LC1711VPN_MG, sequence nr 0x7a2b5f69

[VPN-Status] 2008/12/04 01:26:05,130
VPN: poll timeout for LC1711VPN_MG (217.7.225.1)
remote site answered during intervall
send poll frame to 192.168.100.8

[VPN-Status] 2008/12/04 01:26:05,170
VPN: Poll reply from LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:26:35,130
VPN: poll timeout for LC1711VPN_MG (217.7.225.1)
remote site answered during intervall
send poll frame to 192.168.100.8

[VPN-Status] 2008/12/04 01:26:35,170
VPN: Poll reply from LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:26:58,510
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE sent for Phase-1 SA to peer LC1711VPN_MG, sequence nr 0x1515565a

[VPN-Status] 2008/12/04 01:26:58,550
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE_ACK for peer LC1711VPN_MG Seq-Nr 0x1515565a, expected 0x1515565a

[VPN-Status] 2008/12/04 01:26:58,570
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE for peer LC1711VPN_MG Seq-Nr 0x7a2b5f6a, expected 0x7a2b5f6a

[VPN-Status] 2008/12/04 01:26:58,570
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE_ACK sent for Phase-1 SA to peer LC1711VPN_MG, sequence nr 0x7a2b5f6a

[VPN-Status] 2008/12/04 01:27:05,130
VPN: poll timeout for LC1711VPN_MG (217.7.225.1)
remote site answered during intervall
send poll frame to 192.168.100.8

[VPN-Status] 2008/12/04 01:27:05,170
VPN: Poll reply from LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:27:35,130
VPN: poll timeout for LC1711VPN_MG (217.7.225.1)
remote site answered during intervall
send poll frame to 192.168.100.8

[VPN-Status] 2008/12/04 01:27:35,170
VPN: Poll reply from LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:27:58,580
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE sent for Phase-1 SA to peer LC1711VPN_MG, sequence nr 0x1515565b

[VPN-Status] 2008/12/04 01:27:58,610
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE for peer LC1711VPN_MG Seq-Nr 0x7a2b5f6b, expected 0x7a2b5f6b

[VPN-Status] 2008/12/04 01:27:58,610
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE_ACK sent for Phase-1 SA to peer LC1711VPN_MG, sequence nr 0x7a2b5f6b

[VPN-Status] 2008/12/04 01:27:58,620
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE_ACK for peer LC1711VPN_MG Seq-Nr 0x1515565b, expected 0x1515565b

[VPN-Status] 2008/12/04 01:28:05,130
VPN: poll timeout for LC1711VPN_MG (217.7.225.1)
remote site answered during intervall
send poll frame to 192.168.100.8

[VPN-Status] 2008/12/04 01:28:05,170
VPN: Poll reply from LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:28:35,130
VPN: poll timeout for LC1711VPN_MG (217.7.225.1)
remote site answered during intervall
send poll frame to 192.168.100.8

[VPN-Status] 2008/12/04 01:28:35,170
VPN: Poll reply from LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:28:58,630
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE sent for Phase-1 SA to peer LC1711VPN_MG, sequence nr 0x1515565c

[VPN-Status] 2008/12/04 01:28:58,660
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE for peer LC1711VPN_MG Seq-Nr 0x7a2b5f6c, expected 0x7a2b5f6c

[VPN-Status] 2008/12/04 01:28:58,660
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE_ACK sent for Phase-1 SA to peer LC1711VPN_MG, sequence nr 0x7a2b5f6c

[VPN-Status] 2008/12/04 01:28:58,680
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE_ACK for peer LC1711VPN_MG Seq-Nr 0x1515565c, expected 0x1515565c

[VPN-Status] 2008/12/04 01:29:05,130
VPN: poll timeout for LC1711VPN_MG (217.7.225.1)
remote site answered during intervall
send poll frame to 192.168.100.8

[VPN-Status] 2008/12/04 01:29:05,170
VPN: Poll reply from LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:29:35,130
VPN: poll timeout for LC1711VPN_MG (217.7.225.1)
remote site answered during intervall
send poll frame to 192.168.100.8

[VPN-Status] 2008/12/04 01:29:35,170
VPN: Poll reply from LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:29:58,680
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE sent for Phase-1 SA to peer LC1711VPN_MG, sequence nr 0x1515565d

[VPN-Status] 2008/12/04 01:29:58,710
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE for peer LC1711VPN_MG Seq-Nr 0x7a2b5f6d, expected 0x7a2b5f6d

[VPN-Status] 2008/12/04 01:29:58,710
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE_ACK sent for Phase-1 SA to peer LC1711VPN_MG, sequence nr 0x7a2b5f6d

[VPN-Status] 2008/12/04 01:29:58,730
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE_ACK for peer LC1711VPN_MG Seq-Nr 0x1515565d, expected 0x1515565d

[VPN-Status] 2008/12/04 01:30:05,130
VPN: poll timeout for LC1711VPN_MG (217.7.225.1)
remote site answered during intervall
send poll frame to 192.168.100.8

[VPN-Status] 2008/12/04 01:30:05,170
VPN: Poll reply from LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:30:35,130
VPN: poll timeout for LC1711VPN_MG (217.7.225.1)
remote site answered during intervall
send poll frame to 192.168.100.8

[VPN-Status] 2008/12/04 01:30:35,170
VPN: Poll reply from LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:30:58,730
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE sent for Phase-1 SA to peer LC1711VPN_MG, sequence nr 0x1515565e

[VPN-Status] 2008/12/04 01:30:58,760
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE for peer LC1711VPN_MG Seq-Nr 0x7a2b5f6e, expected 0x7a2b5f6e

[VPN-Status] 2008/12/04 01:30:58,760
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE_ACK sent for Phase-1 SA to peer LC1711VPN_MG, sequence nr 0x7a2b5f6e

[VPN-Status] 2008/12/04 01:30:58,770
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE_ACK for peer LC1711VPN_MG Seq-Nr 0x1515565e, expected 0x1515565e

[VPN-Status] 2008/12/04 01:31:05,130
VPN: poll timeout for LC1711VPN_MG (217.7.225.1)
remote site answered during intervall
send poll frame to 192.168.100.8

[VPN-Status] 2008/12/04 01:31:05,170
VPN: Poll reply from LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:31:35,130
VPN: poll timeout for LC1711VPN_MG (217.7.225.1)
remote site answered during intervall
send poll frame to 192.168.100.8

[VPN-Status] 2008/12/04 01:31:35,180
VPN: Poll reply from LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:31:58,770
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE sent for Phase-1 SA to peer LC1711VPN_MG, sequence nr 0x1515565f

[VPN-Status] 2008/12/04 01:31:58,800
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE for peer LC1711VPN_MG Seq-Nr 0x7a2b5f6f, expected 0x7a2b5f6f

[VPN-Status] 2008/12/04 01:31:58,800
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE_ACK sent for Phase-1 SA to peer LC1711VPN_MG, sequence nr 0x7a2b5f6f

[VPN-Status] 2008/12/04 01:31:58,820
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE_ACK for peer LC1711VPN_MG Seq-Nr 0x1515565f, expected 0x1515565f

[VPN-Status] 2008/12/04 01:32:05,130
VPN: poll timeout for LC1711VPN_MG (217.7.225.1)
remote site answered during intervall
send poll frame to 192.168.100.8

[VPN-Status] 2008/12/04 01:32:05,170
VPN: Poll reply from LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:32:35,130
VPN: poll timeout for LC1711VPN_MG (217.7.225.1)
remote site answered during intervall
send poll frame to 192.168.100.8

[VPN-Status] 2008/12/04 01:32:35,170
VPN: Poll reply from LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:32:58,820
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE sent for Phase-1 SA to peer LC1711VPN_MG, sequence nr 0x15155660

[VPN-Status] 2008/12/04 01:32:58,850
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE for peer LC1711VPN_MG Seq-Nr 0x7a2b5f70, expected 0x7a2b5f70

[VPN-Status] 2008/12/04 01:32:58,850
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE_ACK sent for Phase-1 SA to peer LC1711VPN_MG, sequence nr 0x7a2b5f70

[VPN-Status] 2008/12/04 01:32:58,860
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE_ACK for peer LC1711VPN_MG Seq-Nr 0x15155660, expected 0x15155660

[VPN-Status] 2008/12/04 01:33:05,130
VPN: poll timeout for LC1711VPN_MG (217.7.225.1)
remote site answered during intervall
send poll frame to 192.168.100.8

[VPN-Status] 2008/12/04 01:33:05,170
VPN: Poll reply from LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:33:35,130
VPN: poll timeout for LC1711VPN_MG (217.7.225.1)
remote site answered during intervall
send poll frame to 192.168.100.8

[VPN-Status] 2008/12/04 01:33:35,170
VPN: Poll reply from LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:33:58,860
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE sent for Phase-1 SA to peer LC1711VPN_MG, sequence nr 0x15155661

[VPN-Status] 2008/12/04 01:33:58,890
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE for peer LC1711VPN_MG Seq-Nr 0x7a2b5f71, expected 0x7a2b5f71

[VPN-Status] 2008/12/04 01:33:58,890
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE_ACK sent for Phase-1 SA to peer LC1711VPN_MG, sequence nr 0x7a2b5f71

[VPN-Status] 2008/12/04 01:33:58,900
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE_ACK for peer LC1711VPN_MG Seq-Nr 0x15155661, expected 0x15155661

[VPN-Status] 2008/12/04 01:34:05,130
VPN: poll timeout for LC1711VPN_MG (217.7.225.1)
remote site answered during intervall
send poll frame to 192.168.100.8

[VPN-Status] 2008/12/04 01:34:05,170
VPN: Poll reply from LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:34:35,130
VPN: poll timeout for LC1711VPN_MG (217.7.225.1)
remote site answered during intervall
send poll frame to 192.168.100.8

[VPN-Status] 2008/12/04 01:34:35,170
VPN: Poll reply from LC1711VPN_MG (217.7.225.1)

[VPN-Status] 2008/12/04 01:34:58,900
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE sent for Phase-1 SA to peer LC1711VPN_MG, sequence nr 0x15155662

[VPN-Status] 2008/12/04 01:34:58,930
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE for peer LC1711VPN_MG Seq-Nr 0x7a2b5f72, expected 0x7a2b5f72

[VPN-Status] 2008/12/04 01:34:58,930
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE_ACK sent for Phase-1 SA to peer LC1711VPN_MG, sequence nr 0x7a2b5f72

[VPN-Status] 2008/12/04 01:34:58,940
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE_ACK for peer LC1711VPN_MG Seq-Nr 0x15155662, expected 0x15155662

[VPN-Status] 2008/12/04 01:35:05,130
VPN: poll timeout for LC1711VPN_MG (217.7.225.1)
remote site answered during intervall
send poll frame to 192.168.100.8

[VPN-Status] 2008/12/04 01:35:05,170
VPN: Poll reply from LC1711VPN_MG (217.7.225.1)
Zur Info: Ab und an gibt es mal keine Fehler und dann kann ich von B alle Geräte in A anpingen, aber von A nur einige Geräte von B...

Dann bekomm ich von A nach B Zugriff auf einen Server (FTP, HTTP, HTTPS, Datei-Druckerfreigabe...) aber dann gibt es welche, die erreiche ich nicht per Ping oder HTTP (von A aus)...
Von B kann ich dann zwar alles anpingen, aber Dienste verwenden ist ein NOGO.... :(


Bye Christian

Bye Christian
Tjaden
Beiträge: 5
Registriert: 04 Dez 2008, 01:05

Beitrag von Tjaden »

Hmm, das VPN an sich läuft nun zwischen den 3 LC711, aber ich hab dennoch immer wieder Fehler, mit welchen ich nichts anfangen kann...

Code: Alles auswählen

[TraceStarted] 2008/12/06 00:33:50,000
Used config:
# Trace config 
trace + VPN-Status 
 
# Show commands 
show bootlog  
 
[ShowCmd] 2008/12/06 00:33:50,000
Result of command: "show bootlog "
Boot log (344 Bytes):

****

01/01/1900 00:00:01  System boot after internal watchdog reset

DEVICE:           LANCOM 1711 VPN
HW-RELEASE:       C
VERSION:          7.58.0045 / 14.11.2008

****

12/04/2008 16:23:20  System boot after manual boot request

DEVICE:           LANCOM 1711 VPN
HW-RELEASE:       C
VERSION:          7.58.0045 / 14.11.2008

[Sysinfo] 2008/12/06 00:33:50,000
Result of command: "sysinfo"

DEVICE:           LANCOM 1711 VPN
HW-RELEASE:       C
SERIAL-NUMBER:    120241800010
MAC-ADDRESS:      00a057146b48
IP-ADDRESS:       192.168.100.8
IP-NETMASK:       255.255.255.0
INTRANET-ADDRESS: 0.0.0.0
INTRANETMASK:     0.0.0.0
VERSION:          7.58.0045 / 14.11.2008
NAME:             LC1711VPN_MG
CONFIG-STATUS:    1056;0
FIRMWARE-STATUS:  1;1.3;1.2;7.54.16062008.2;7.58.14112008.3
LANCAPI-PORT:     75
HW-MASK:          00000000000000000000000000000011
FEATUREWORD:      00000000000000000000000100011101
REGISTERED-WORD:  00000000000000000000000100011101
FEATURE-LIST:     00/F/00000000
FEATURE-LIST:     02/F/00000000
FEATURE-LIST:     03/F/00000000
FEATURE-LIST:     04/F/00000000
FEATURE-LIST:     08/F/00000000
TIME:             00335006122008
HTTP-PORT:        80
HTTPS-PORT:       443
[VPN-Status] 2008/12/06 00:33:54,650
IKE info: NOTIFY received of type NO_PROPOSAL_CHOSEN for peer LC1711VPN_TF

[VPN-Status] 2008/12/06 00:33:54,650
VPN: Error: IPSEC-I-No-proposal-matched (0x3102) for LC1711VPN_TF (88.78.125.139)

[VPN-Status] 2008/12/06 00:33:54,650
IKE info: NOTIFY received of type NO_PROPOSAL_CHOSEN for peer LC1711VPN_TF

[VPN-Status] 2008/12/06 00:33:54,650
VPN: Error: IPSEC-I-No-proposal-matched (0x3102) for LC1711VPN_TF (88.78.125.139)

[VPN-Status] 2008/12/06 00:33:54,660
IKE info: NOTIFY received of type NO_PROPOSAL_CHOSEN for peer LC1711VPN_TF

[VPN-Status] 2008/12/06 00:33:54,660
VPN: Error: IPSEC-I-No-proposal-matched (0x3102) for LC1711VPN_TF (88.78.125.139)

[VPN-Status] 2008/12/06 00:33:58,540
VPN: connection for LC1711VPN_FUE (212.114.251.224) timed out: no response

[VPN-Status] 2008/12/06 00:33:58,540
VPN: Error: IFC-I-Connection-timeout-IKE-IPSEC (0x1106) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:33:58,540
VPN: disconnecting LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:33:58,540
VPN: Error: (unknown) (0x0117) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:33:58,560
IKE info: Delete Notificaton sent for Phase-1 SA to peer LC1711VPN_FUE

[VPN-Status] 2008/12/06 00:33:58,560
IKE info: Phase-1 SA removed: peer LC1711VPN_FUE rule LC1711VPN_FUE removed

[VPN-Status] 2008/12/06 00:33:58,560
IKE info: Delete Notificaton sent for Phase-1 SA to peer LC1711VPN_FUE

[VPN-Status] 2008/12/06 00:33:58,560
IKE info: Phase-1 SA removed: peer LC1711VPN_FUE rule LC1711VPN_FUE removed

[VPN-Status] 2008/12/06 00:33:58,590
VPN: LC1711VPN_FUE (212.114.251.224) disconnected

[VPN-Status] 2008/12/06 00:33:58,590
VPN: Disconnect info: remote-disconnected (0x4301) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:33:58,610
VPN: selecting next remote gateway using strategy eFirst for LC1711VPN_FUE
     => no remote gateway selected

[VPN-Status] 2008/12/06 00:33:58,610
VPN: selecting first remote gateway using strategy eFirst for LC1711VPN_FUE
     => CurrIdx=0, IpStr=>212.114.251.224<, IpAddr=212.114.251.224, IpTtl=0s

[VPN-Status] 2008/12/06 00:33:58,610
VPN: installing ruleset for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:33:58,620
VPN: LC1711VPN_FUE (212.114.251.224) disconnected

[VPN-Status] 2008/12/06 00:33:58,620
IKE log: 003358 Default message_recv: invalid cookie(s) f8ad939817933414 5c96d8a5af271ee8

[VPN-Status] 2008/12/06 00:33:58,620
IKE log: 003358 Default dropped message from 212.114.251.224 port 500 due to notification type INVALID_COOKIE

[VPN-Status] 2008/12/06 00:33:58,620
IKE info: dropped message from peer unknown 212.114.251.224 port 500 due to notification type INVALID_COOKIE

[VPN-Status] 2008/12/06 00:33:58,620
IKE log: 003358 Default message_recv: invalid cookie(s) bdb95921a4df7752 3ac7a2b0e43b0f9a

[VPN-Status] 2008/12/06 00:33:58,620
IKE log: 003358 Default dropped message from 212.114.251.224 port 500 due to notification type INVALID_COOKIE

[VPN-Status] 2008/12/06 00:33:58,630
IKE info: dropped message from peer unknown 212.114.251.224 port 500 due to notification type INVALID_COOKIE

[VPN-Status] 2008/12/06 00:33:58,630
VPN: rulesets installed

[VPN-Status] 2008/12/06 00:33:59,610
VPN: connecting to LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:33:59,630
VPN: start dynamic VPN negotiation for LC1711VPN_FUE (212.114.251.224) via ICMP/UDP

[VPN-Status] 2008/12/06 00:33:59,630
VPN: create dynamic VPN V2 authentication packet for LC1711VPN_FUE (212.114.251.224)
     DNS: 192.168.100.8, 0.0.0.0
     NBNS: 192.168.100.8, 0.0.0.0
     polling address: 192.168.100.8

[VPN-Status] 2008/12/06 00:33:59,630
VPN: installing ruleset for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:33:59,640
VPN: ruleset installed for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:33:59,640
VPN: start IKE negotiation for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:33:59,670
VPN: rulesets installed

[VPN-Status] 2008/12/06 00:33:59,670
VPN: received dynamic VPN V2 authentication packet from LC1711VPN_FUE (212.114.251.224)
     DNS: 192.168.252.3, 0.0.0.0
     NBNS: 192.168.252.3, 0.0.0.0
     polling address: 192.168.252.3

[VPN-Status] 2008/12/06 00:33:59,670
IKE info: Phase-1 negotiation started for peer LC1711VPN_FUE rule isakmp-peer-LC1711VPN_FUE using MAIN mode

[VPN-Status] 2008/12/06 00:33:59,700
IKE info: The remote server 212.114.251.224:500 peer LC1711VPN_FUE id <no_id> is Enigmatec IPSEC version 1.5.1
IKE info: The remote server 212.114.251.224:500 peer LC1711VPN_FUE id <no_id> negotiated rfc-3706-dead-peer-detection

[VPN-Status] 2008/12/06 00:33:59,700
IKE info: Phase-1 remote proposal 1 for peer LC1711VPN_FUE matched with local proposal 1

[VPN-Status] 2008/12/06 00:33:59,740
IKE info: The remote server 212.114.251.224:500 peer LC1711VPN_FUE id <no_id> is Enigmatec IPSEC version 1.5.1
IKE info: The remote server 212.114.251.224:500 peer LC1711VPN_FUE id <no_id> negotiated rfc-3706-dead-peer-detection

[VPN-Status] 2008/12/06 00:33:59,740
IKE info: Phase-1 remote proposal 1 for peer LC1711VPN_FUE matched with local proposal 1

[VPN-Status] 2008/12/06 00:34:00,110
IKE info: Phase-1 [responder] for peer LC1711VPN_FUE between initiator id  212.114.251.224, responder id  217.7.225.1 done
IKE info: SA ISAKMP for peer LC1711VPN_FUE encryption aes-cbc authentication md5
IKE info: life time ( 108000 sec/ 0 kb)

[VPN-Status] 2008/12/06 00:34:00,110
IKE info: Phase-1 SA Rekeying Timeout (Soft-Event) for peer LC1711VPN_FUE set to 97200 seconds (Responder)

[VPN-Status] 2008/12/06 00:34:00,120
IKE info: Phase-1 SA Timeout (Hard-Event) for peer LC1711VPN_FUE set to 108000 seconds (Responder)

[VPN-Status] 2008/12/06 00:34:00,130
IKE info: Phase-1 [inititiator] for peer LC1711VPN_FUE between initiator id  217.7.225.1, responder id  212.114.251.224 done
IKE info: SA ISAKMP for peer LC1711VPN_FUE encryption aes-cbc authentication md5
IKE info: life time ( 108000 sec/ 0 kb)

[VPN-Status] 2008/12/06 00:34:00,140
IKE info: Phase-1 SA Rekeying Timeout (Soft-Event) for peer LC1711VPN_FUE set to 86400 seconds (Initiator)

[VPN-Status] 2008/12/06 00:34:00,140
IKE info: Phase-1 SA Timeout (Hard-Event) for peer LC1711VPN_FUE set to 108000 seconds (Initiator)

[VPN-Status] 2008/12/06 00:34:00,200
IKE log: 003400 Default message_parse_payloads: invalid next payload type <Unknown 106> in payload of type 8

[VPN-Status] 2008/12/06 00:34:00,200
IKE log: 003400 Default dropped message from 212.114.251.224 port 500 due to notification type INVALID_PAYLOAD_TYPE

[VPN-Status] 2008/12/06 00:34:00,200
IKE info: dropped message from peer LC1711VPN_FUE 212.114.251.224 port 500 due to notification type INVALID_PAYLOAD_TYPE

[VPN-Status] 2008/12/06 00:34:00,220
IKE log: 003400 Default message_parse_payloads: reserved field non-zero: 22

[VPN-Status] 2008/12/06 00:34:00,220
IKE log: 003400 Default dropped message from 212.114.251.224 port 500 due to notification type PAYLOAD_MALFORMED

[VPN-Status] 2008/12/06 00:34:00,220
IKE info: dropped message from peer LC1711VPN_FUE 212.114.251.224 port 500 due to notification type PAYLOAD_MALFORMED

[VPN-Status] 2008/12/06 00:34:00,240
IKE log: 003400 Default message_parse_payloads: reserved field non-zero: 8b

[VPN-Status] 2008/12/06 00:34:00,240
IKE log: 003400 Default dropped message from 212.114.251.224 port 500 due to notification type PAYLOAD_MALFORMED

[VPN-Status] 2008/12/06 00:34:00,240
IKE info: dropped message from peer LC1711VPN_FUE 212.114.251.224 port 500 due to notification type PAYLOAD_MALFORMED

[VPN-Status] 2008/12/06 00:34:00,260
IKE log: 003400 Default message_parse_payloads: invalid next payload type <Unknown 119> in payload of type 8

[VPN-Status] 2008/12/06 00:34:00,260
IKE log: 003400 Default dropped message from 212.114.251.224 port 500 due to notification type INVALID_PAYLOAD_TYPE

[VPN-Status] 2008/12/06 00:34:00,260
IKE info: dropped message from peer LC1711VPN_FUE 212.114.251.224 port 500 due to notification type INVALID_PAYLOAD_TYPE

[VPN-Status] 2008/12/06 00:34:00,280
IKE info: NOTIFY received of type PAYLOAD_MALFORMED for peer LC1711VPN_FUE

[VPN-Status] 2008/12/06 00:34:00,280
IKE info: NOTIFY received of type PAYLOAD_MALFORMED for peer LC1711VPN_FUE

[VPN-Status] 2008/12/06 00:34:00,280
IKE info: NOTIFY received of type PAYLOAD_MALFORMED for peer LC1711VPN_FUE

[VPN-Status] 2008/12/06 00:34:00,290
IKE info: NOTIFY received of type PAYLOAD_MALFORMED for peer LC1711VPN_FUE

[VPN-Status] 2008/12/06 00:34:04,280
VPN: poll timeout for LC1711VPN_TF (88.78.125.139)
remote site answered during intervall
send poll frame to 192.168.99.7

[VPN-Status] 2008/12/06 00:34:04,290
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE sent for Phase-1 SA to peer LC1711VPN_FUE, sequence nr 0x6d3e365

[VPN-Status] 2008/12/06 00:34:04,330
VPN: Poll reply from LC1711VPN_TF (88.78.125.139)

[VPN-Status] 2008/12/06 00:34:04,350
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE_ACK for peer LC1711VPN_FUE Seq-Nr 0x6d3e365, expected 0x6d3e365

[VPN-Status] 2008/12/06 00:34:13,350
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE for peer LC1711VPN_FUE Seq-Nr 0x6d3e365, expected 0x6d3e365

[VPN-Status] 2008/12/06 00:34:13,360
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE_ACK sent for Phase-1 SA to peer LC1711VPN_FUE, sequence nr 0x6d3e365

[VPN-Status] 2008/12/06 00:34:15,680
VPN: starting external DNS resolution for LC1711VPN_TF
     IpStr=>TF-Steco.DynDNS.org<, IpAddr(old)=88.78.125.139, IpTtl(old)=60s

[VPN-Status] 2008/12/06 00:34:15,710
VPN: external DNS resolution for LC1711VPN_TF
     IpStr=>TF-Steco.DynDNS.org<, IpAddr(old)=88.78.125.139, IpTtl(old)=60s
     IpStr=>TF-Steco.DynDNS.org<, IpAddr(new)=88.78.125.139, IpTtl(new)=60s

[VPN-Status] 2008/12/06 00:34:28,370
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE sent for Phase-1 SA to peer LC1711VPN_TF, sequence nr 0x54708942

[VPN-Status] 2008/12/06 00:34:28,420
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE_ACK for peer LC1711VPN_TF Seq-Nr 0x54708942, expected 0x54708942

[VPN-Status] 2008/12/06 00:34:28,430
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE for peer LC1711VPN_TF Seq-Nr 0x6905e73f, expected 0x6905e73f

[VPN-Status] 2008/12/06 00:34:28,430
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE_ACK sent for Phase-1 SA to peer LC1711VPN_TF, sequence nr 0x6905e73f

[VPN-Status] 2008/12/06 00:34:29,670
VPN: connection for LC1711VPN_FUE (212.114.251.224) timed out: no response

[VPN-Status] 2008/12/06 00:34:29,670
VPN: Error: IFC-I-Connection-timeout-IKE-IPSEC (0x1106) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:29,670
VPN: disconnecting LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:29,670
VPN: Error: (unknown) (0x0117) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:29,690
IKE info: Delete Notificaton sent for Phase-1 SA to peer LC1711VPN_FUE

[VPN-Status] 2008/12/06 00:34:29,690
IKE info: Phase-1 SA removed: peer LC1711VPN_FUE rule LC1711VPN_FUE removed

[VPN-Status] 2008/12/06 00:34:29,690
IKE info: Delete Notificaton sent for Phase-1 SA to peer LC1711VPN_FUE

[VPN-Status] 2008/12/06 00:34:29,690
IKE info: Phase-1 SA removed: peer LC1711VPN_FUE rule LC1711VPN_FUE removed

[VPN-Status] 2008/12/06 00:34:29,720
VPN: LC1711VPN_FUE (212.114.251.224) disconnected

[VPN-Status] 2008/12/06 00:34:29,720
VPN: Disconnect info: remote-disconnected (0x4301) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:29,740
VPN: selecting next remote gateway using strategy eFirst for LC1711VPN_FUE
     => no remote gateway selected

[VPN-Status] 2008/12/06 00:34:29,740
VPN: selecting first remote gateway using strategy eFirst for LC1711VPN_FUE
     => CurrIdx=0, IpStr=>212.114.251.224<, IpAddr=212.114.251.224, IpTtl=0s

[VPN-Status] 2008/12/06 00:34:29,740
VPN: installing ruleset for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:29,740
VPN: LC1711VPN_FUE (212.114.251.224) disconnected

[VPN-Status] 2008/12/06 00:34:29,750
IKE log: 003429 Default message_recv: invalid cookie(s) b1d1333212441f74 35e4df3a0b9cbb03

[VPN-Status] 2008/12/06 00:34:29,750
IKE log: 003429 Default dropped message from 212.114.251.224 port 500 due to notification type INVALID_COOKIE

[VPN-Status] 2008/12/06 00:34:29,750
IKE info: dropped message from peer unknown 212.114.251.224 port 500 due to notification type INVALID_COOKIE

[VPN-Status] 2008/12/06 00:34:29,750
IKE log: 003429 Default message_recv: invalid cookie(s) 339c44fbe5081d6b 768968e81bcbdc41

[VPN-Status] 2008/12/06 00:34:29,750
IKE log: 003429 Default dropped message from 212.114.251.224 port 500 due to notification type INVALID_COOKIE

[VPN-Status] 2008/12/06 00:34:29,750
IKE info: dropped message from peer unknown 212.114.251.224 port 500 due to notification type INVALID_COOKIE

[VPN-Status] 2008/12/06 00:34:29,760
VPN: rulesets installed

[VPN-Status] 2008/12/06 00:34:30,740
VPN: connecting to LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:30,760
VPN: start dynamic VPN negotiation for LC1711VPN_FUE (212.114.251.224) via ICMP/UDP

[VPN-Status] 2008/12/06 00:34:30,760
VPN: create dynamic VPN V2 authentication packet for LC1711VPN_FUE (212.114.251.224)
     DNS: 192.168.100.8, 0.0.0.0
     NBNS: 192.168.100.8, 0.0.0.0
     polling address: 192.168.100.8

[VPN-Status] 2008/12/06 00:34:30,760
VPN: installing ruleset for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:30,760
VPN: received dynamic VPN V2 authentication packet from LC1711VPN_FUE (212.114.251.224)
     DNS: 192.168.252.3, 0.0.0.0
     NBNS: 192.168.252.3, 0.0.0.0
     polling address: 192.168.252.3

[VPN-Status] 2008/12/06 00:34:30,770
VPN: ruleset installed for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:30,770
VPN: start IKE negotiation for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:30,800
VPN: rulesets installed

[VPN-Status] 2008/12/06 00:34:30,800
IKE info: Phase-1 negotiation started for peer LC1711VPN_FUE rule isakmp-peer-LC1711VPN_FUE using MAIN mode

[VPN-Status] 2008/12/06 00:34:30,820
IKE info: The remote server 212.114.251.224:500 peer LC1711VPN_FUE id <no_id> is Enigmatec IPSEC version 1.5.1
IKE info: The remote server 212.114.251.224:500 peer LC1711VPN_FUE id <no_id> negotiated rfc-3706-dead-peer-detection

[VPN-Status] 2008/12/06 00:34:30,820
IKE info: Phase-1 remote proposal 1 for peer LC1711VPN_FUE matched with local proposal 1

[VPN-Status] 2008/12/06 00:34:30,870
IKE info: The remote server 212.114.251.224:500 peer LC1711VPN_FUE id <no_id> is Enigmatec IPSEC version 1.5.1
IKE info: The remote server 212.114.251.224:500 peer LC1711VPN_FUE id <no_id> negotiated rfc-3706-dead-peer-detection

[VPN-Status] 2008/12/06 00:34:30,870
IKE info: Phase-1 remote proposal 1 for peer LC1711VPN_FUE matched with local proposal 1

[VPN-Status] 2008/12/06 00:34:31,250
IKE info: Phase-1 [responder] for peer LC1711VPN_FUE between initiator id  212.114.251.224, responder id  217.7.225.1 done
IKE info: SA ISAKMP for peer LC1711VPN_FUE encryption aes-cbc authentication md5
IKE info: life time ( 108000 sec/ 0 kb)

[VPN-Status] 2008/12/06 00:34:31,250
IKE info: Phase-1 SA Rekeying Timeout (Soft-Event) for peer LC1711VPN_FUE set to 97200 seconds (Responder)

[VPN-Status] 2008/12/06 00:34:31,260
IKE info: Phase-1 SA Timeout (Hard-Event) for peer LC1711VPN_FUE set to 108000 seconds (Responder)

[VPN-Status] 2008/12/06 00:34:31,260
IKE info: Phase-1 [inititiator] for peer LC1711VPN_FUE between initiator id  217.7.225.1, responder id  212.114.251.224 done
IKE info: SA ISAKMP for peer LC1711VPN_FUE encryption aes-cbc authentication md5
IKE info: life time ( 108000 sec/ 0 kb)

[VPN-Status] 2008/12/06 00:34:31,260
IKE info: Phase-1 SA Rekeying Timeout (Soft-Event) for peer LC1711VPN_FUE set to 86400 seconds (Initiator)

[VPN-Status] 2008/12/06 00:34:31,260
IKE info: Phase-1 SA Timeout (Hard-Event) for peer LC1711VPN_FUE set to 108000 seconds (Initiator)

[VPN-Status] 2008/12/06 00:34:31,340
IKE info: Phase-2 remote proposal 1 for peer LC1711VPN_FUE matched with local proposal 1

[VPN-Status] 2008/12/06 00:34:31,510
IKE info: Phase-2 failed for peer LC1711VPN_FUE: no rule matches the phase-2 ids  0.0.0.0/0.0.0.0 <->  192.168.200.0/255.255.255.0
IKE log: 003431 Default message_negotiate_sa: no compatible proposal found
IKE log: 003431 Default dropped message from 212.114.251.224 port 500 due to notification type NO_PROPOSAL_CHOSEN
IKE info: dropped message from peer LC1711VPN_FUE 212.114.251.224 port 500 due to notification type NO_PROPOSAL_CHOSEN

[VPN-Status] 2008/12/06 00:34:31,520
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:31,520
IKE info: Phase-2 remote proposal 1 for peer LC1711VPN_FUE matched with local proposal 1

[VPN-Status] 2008/12/06 00:34:31,520
IKE info: Phase-2 failed for peer LC1711VPN_FUE: no rule matches the phase-2 ids  0.0.0.0/0.0.0.0 <->  192.168.100.0/255.255.255.0
IKE log: 003431 Default message_negotiate_sa: no compatible proposal found
IKE log: 003431 Default dropped message from 212.114.251.224 port 500 due to notification type NO_PROPOSAL_CHOSEN
IKE info: dropped message from peer LC1711VPN_FUE 212.114.251.224 port 500 due to notification type NO_PROPOSAL_CHOSEN

[VPN-Status] 2008/12/06 00:34:31,530
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:31,530
IKE info: NOTIFY received of type NO_PROPOSAL_CHOSEN for peer LC1711VPN_FUE

[VPN-Status] 2008/12/06 00:34:31,530
VPN: Error: IPSEC-I-No-proposal-matched (0x3102) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:31,530
IKE info: NOTIFY received of type NO_PROPOSAL_CHOSEN for peer LC1711VPN_FUE

[VPN-Status] 2008/12/06 00:34:31,530
VPN: Error: IPSEC-I-No-proposal-matched (0x3102) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:31,540
IKE info: NOTIFY received of type NO_PROPOSAL_CHOSEN for peer LC1711VPN_FUE

[VPN-Status] 2008/12/06 00:34:31,540
VPN: Error: IPSEC-I-No-proposal-matched (0x3102) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:31,540
IKE info: Phase-2 SA Rekeying Timeout (Soft-Event) for peer LC1711VPN_FUE set to 1800 seconds (Responder)

[VPN-Status] 2008/12/06 00:34:31,540
IKE info: Phase-2 SA Timeout (Hard-Event) for peer LC1711VPN_FUE set to 2000 seconds (Responder)

[VPN-Status] 2008/12/06 00:34:31,540
IKE info: Phase-2 [responder] done with 2 SAS for peer LC1711VPN_FUE rule ipsec-1-LC1711VPN_FUE-pr0-l0-r0
IKE info: rule:' ipsec 192.168.200.0/255.255.255.0 <-> 192.168.252.0/255.255.255.0 '
IKE info: SA ESP [0x4d9982fa]  alg AES keylength 128 +hmac HMAC_MD5 outgoing
IKE info: SA ESP [0x3404ae80]  alg AES keylength 128 +hmac HMAC_MD5 incoming
IKE info: life soft( 1800 sec/180000 kb) hard (2000 sec/200000 kb)
IKE info: tunnel between src: 217.7.225.1 dst: 212.114.251.224  

[VPN-Status] 2008/12/06 00:34:31,870
IKE info: Phase-2 SA Rekeying Timeout (Soft-Event) for peer LC1711VPN_FUE set to 1800 seconds (Responder)

[VPN-Status] 2008/12/06 00:34:31,870
IKE info: Phase-2 SA Timeout (Hard-Event) for peer LC1711VPN_FUE set to 2000 seconds (Responder)

[VPN-Status] 2008/12/06 00:34:31,870
IKE info: Phase-2 [responder] done with 2 SAS for peer LC1711VPN_FUE rule ipsec-2-LC1711VPN_FUE-pr0-l0-r0
IKE info: rule:' ipsec 192.168.100.0/255.255.255.0 <-> 192.168.252.0/255.255.255.0 '
IKE info: SA ESP [0x666b2c86]  alg AES keylength 128 +hmac HMAC_MD5 outgoing
IKE info: SA ESP [0x32aeb182]  alg AES keylength 128 +hmac HMAC_MD5 incoming
IKE info: life soft( 1800 sec/180000 kb) hard (2000 sec/200000 kb)
IKE info: tunnel between src: 217.7.225.1 dst: 212.114.251.224  

[VPN-Status] 2008/12/06 00:34:31,880
IKE info: Phase-2 SA Rekeying Timeout (Soft-Event) for peer LC1711VPN_FUE set to 1800 seconds (Responder)

[VPN-Status] 2008/12/06 00:34:31,880
IKE info: Phase-2 SA Timeout (Hard-Event) for peer LC1711VPN_FUE set to 2000 seconds (Responder)

[VPN-Status] 2008/12/06 00:34:31,880
IKE info: Phase-2 [responder] done with 2 SAS for peer LC1711VPN_FUE rule ipsec-2-LC1711VPN_FUE-pr0-l0-r0
IKE info: rule:' ipsec 192.168.100.0/255.255.255.0 <-> 192.168.252.0/255.255.255.0 '
IKE info: SA ESP [0x2e17d394]  alg AES keylength 128 +hmac HMAC_MD5 outgoing
IKE info: SA ESP [0x1c652c5d]  alg AES keylength 128 +hmac HMAC_MD5 incoming
IKE info: life soft( 1800 sec/180000 kb) hard (2000 sec/200000 kb)
IKE info: tunnel between src: 217.7.225.1 dst: 212.114.251.224  

[VPN-Status] 2008/12/06 00:34:32,890
VPN: LC1711VPN_FUE (212.114.251.224) connected, set poll timer to 30 sec

[VPN-Status] 2008/12/06 00:34:34,280
VPN: poll timeout for LC1711VPN_TF (88.78.125.139)
remote site answered during intervall
send poll frame to 192.168.99.7

[VPN-Status] 2008/12/06 00:34:34,330
VPN: Poll reply from LC1711VPN_TF (88.78.125.139)

[VPN-Status] 2008/12/06 00:34:37,890
VPN: poll timeout for LC1711VPN_FUE (212.114.251.224)
send poll frame to 192.168.252.3

[VPN-Status] 2008/12/06 00:34:37,940
VPN: Poll reply from LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:38,900
IKE info: Phase-2 failed for peer LC1711VPN_FUE: no rule matches the phase-2 ids  0.0.0.0/0.0.0.0 <->  192.168.200.0/255.255.255.0
IKE log: 003438 Default message_negotiate_sa: no compatible proposal found
IKE log: 003438 Default dropped message from 212.114.251.224 port 500 due to notification type NO_PROPOSAL_CHOSEN
IKE info: dropped message from peer LC1711VPN_FUE 212.114.251.224 port 500 due to notification type NO_PROPOSAL_CHOSEN

[VPN-Status] 2008/12/06 00:34:38,930
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:38,930
IKE info: Phase-2 failed for peer LC1711VPN_FUE: no rule matches the phase-2 ids  0.0.0.0/0.0.0.0 <->  192.168.100.0/255.255.255.0
IKE log: 003438 Default message_negotiate_sa: no compatible proposal found
IKE log: 003438 Default dropped message from 212.114.251.224 port 500 due to notification type NO_PROPOSAL_CHOSEN
IKE info: dropped message from peer LC1711VPN_FUE 212.114.251.224 port 500 due to notification type NO_PROPOSAL_CHOSEN

[VPN-Status] 2008/12/06 00:34:38,930
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:39,020
IKE info: NOTIFY received of type NO_PROPOSAL_CHOSEN for peer LC1711VPN_FUE

[VPN-Status] 2008/12/06 00:34:39,020
VPN: Error: IPSEC-I-No-proposal-matched (0x3102) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:39,020
IKE info: NOTIFY received of type NO_PROPOSAL_CHOSEN for peer LC1711VPN_FUE

[VPN-Status] 2008/12/06 00:34:39,030
VPN: Error: IPSEC-I-No-proposal-matched (0x3102) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:39,030
IKE info: NOTIFY received of type NO_PROPOSAL_CHOSEN for peer LC1711VPN_FUE

[VPN-Status] 2008/12/06 00:34:39,030
VPN: Error: IPSEC-I-No-proposal-matched (0x3102) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:47,020
IKE info: Phase-2 failed for peer LC1711VPN_FUE: no rule matches the phase-2 ids  0.0.0.0/0.0.0.0 <->  192.168.200.0/255.255.255.0
IKE log: 003447 Default message_negotiate_sa: no compatible proposal found
IKE log: 003447 Default dropped message from 212.114.251.224 port 500 due to notification type NO_PROPOSAL_CHOSEN
IKE info: dropped message from peer LC1711VPN_FUE 212.114.251.224 port 500 due to notification type NO_PROPOSAL_CHOSEN

[VPN-Status] 2008/12/06 00:34:47,020
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:47,040
IKE info: Phase-2 failed for peer LC1711VPN_FUE: no rule matches the phase-2 ids  0.0.0.0/0.0.0.0 <->  192.168.100.0/255.255.255.0
IKE log: 003447 Default message_negotiate_sa: no compatible proposal found
IKE log: 003447 Default dropped message from 212.114.251.224 port 500 due to notification type NO_PROPOSAL_CHOSEN
IKE info: dropped message from peer LC1711VPN_FUE 212.114.251.224 port 500 due to notification type NO_PROPOSAL_CHOSEN

[VPN-Status] 2008/12/06 00:34:47,040
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:47,090
IKE info: NOTIFY received of type NO_PROPOSAL_CHOSEN for peer LC1711VPN_FUE

[VPN-Status] 2008/12/06 00:34:47,090
VPN: Error: IPSEC-I-No-proposal-matched (0x3102) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:47,090
IKE info: NOTIFY received of type NO_PROPOSAL_CHOSEN for peer LC1711VPN_FUE

[VPN-Status] 2008/12/06 00:34:47,090
VPN: Error: IPSEC-I-No-proposal-matched (0x3102) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:47,100
IKE info: NOTIFY received of type NO_PROPOSAL_CHOSEN for peer LC1711VPN_FUE

[VPN-Status] 2008/12/06 00:34:47,100
VPN: Error: IPSEC-I-No-proposal-matched (0x3102) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:58,100
IKE info: Phase-2 failed for peer LC1711VPN_FUE: no rule matches the phase-2 ids  0.0.0.0/0.0.0.0 <->  192.168.200.0/255.255.255.0
IKE log: 003458 Default message_negotiate_sa: no compatible proposal found
IKE log: 003458 Default dropped message from 212.114.251.224 port 500 due to notification type NO_PROPOSAL_CHOSEN
IKE info: dropped message from peer LC1711VPN_FUE 212.114.251.224 port 500 due to notification type NO_PROPOSAL_CHOSEN

[VPN-Status] 2008/12/06 00:34:58,100
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:58,120
IKE info: Phase-2 failed for peer LC1711VPN_FUE: no rule matches the phase-2 ids  0.0.0.0/0.0.0.0 <->  192.168.100.0/255.255.255.0
IKE log: 003458 Default message_negotiate_sa: no compatible proposal found
IKE log: 003458 Default dropped message from 212.114.251.224 port 500 due to notification type NO_PROPOSAL_CHOSEN
IKE info: dropped message from peer LC1711VPN_FUE 212.114.251.224 port 500 due to notification type NO_PROPOSAL_CHOSEN

[VPN-Status] 2008/12/06 00:34:58,120
VPN: Error: IPSEC-R-No-rule-matched-IDs (0x3201) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:58,160
IKE info: NOTIFY received of type NO_PROPOSAL_CHOSEN for peer LC1711VPN_FUE

[VPN-Status] 2008/12/06 00:34:58,160
VPN: Error: IPSEC-I-No-proposal-matched (0x3102) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:58,160
IKE info: NOTIFY received of type NO_PROPOSAL_CHOSEN for peer LC1711VPN_FUE

[VPN-Status] 2008/12/06 00:34:58,160
VPN: Error: IPSEC-I-No-proposal-matched (0x3102) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:34:58,170
IKE info: NOTIFY received of type NO_PROPOSAL_CHOSEN for peer LC1711VPN_FUE

[VPN-Status] 2008/12/06 00:34:58,170
VPN: Error: IPSEC-I-No-proposal-matched (0x3102) for LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:35:04,280
VPN: poll timeout for LC1711VPN_TF (88.78.125.139)
remote site answered during intervall
send poll frame to 192.168.99.7

[VPN-Status] 2008/12/06 00:35:04,330
VPN: Poll reply from LC1711VPN_TF (88.78.125.139)

[VPN-Status] 2008/12/06 00:35:07,890
VPN: poll timeout for LC1711VPN_FUE (212.114.251.224)
remote site answered during intervall
send poll frame to 192.168.252.3

[VPN-Status] 2008/12/06 00:35:07,980
VPN: Poll reply from LC1711VPN_FUE (212.114.251.224)

[VPN-Status] 2008/12/06 00:35:16,710
VPN: starting external DNS resolution for LC1711VPN_TF
     IpStr=>TF-Steco.DynDNS.org<, IpAddr(old)=88.78.125.139, IpTtl(old)=60s

[VPN-Status] 2008/12/06 00:35:16,740
VPN: external DNS resolution for LC1711VPN_TF
     IpStr=>TF-Steco.DynDNS.org<, IpAddr(old)=88.78.125.139, IpTtl(old)=60s
     IpStr=>TF-Steco.DynDNS.org<, IpAddr(new)=88.78.125.139, IpTtl(new)=60s

[VPN-Status] 2008/12/06 00:35:28,170
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE sent for Phase-1 SA to peer LC1711VPN_TF, sequence nr 0x54708943

[VPN-Status] 2008/12/06 00:35:28,220
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE_ACK for peer LC1711VPN_TF Seq-Nr 0x54708943, expected 0x54708943

[VPN-Status] 2008/12/06 00:35:28,230
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE for peer LC1711VPN_TF Seq-Nr 0x6905e740, expected 0x6905e740

[VPN-Status] 2008/12/06 00:35:28,230
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE_ACK sent for Phase-1 SA to peer LC1711VPN_TF, sequence nr 0x6905e740

[VPN-Status] 2008/12/06 00:35:31,240
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE sent for Phase-1 SA to peer LC1711VPN_FUE, sequence nr 0x7da6b861

[VPN-Status] 2008/12/06 00:35:31,250
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE for peer LC1711VPN_FUE Seq-Nr 0x6eba783e, expected 0x6eba783e

[VPN-Status] 2008/12/06 00:35:31,250
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE_ACK sent for Phase-1 SA to peer LC1711VPN_FUE, sequence nr 0x6eba783e

[VPN-Status] 2008/12/06 00:35:31,290
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE_ACK for peer LC1711VPN_FUE Seq-Nr 0x7da6b861, expected 0x7da6b861

[VPN-Status] 2008/12/06 00:35:34,280
VPN: poll timeout for LC1711VPN_TF (88.78.125.139)
remote site answered during intervall
send poll frame to 192.168.99.7

[VPN-Status] 2008/12/06 00:35:34,330
VPN: Poll reply from LC1711VPN_TF (88.78.125.139)

[VPN-Status] 2008/12/06 00:35:37,890
VPN: poll timeout for LC1711VPN_FUE (212.114.251.224)
remote site answered during intervall
send poll frame to 192.168.252.3

[VPN-Status] 2008/12/06 00:35:37,940
VPN: Poll reply from LC1711VPN_FUE (212.114.251.224)
[TraceStopped] 2008/12/06 00:36:01,000
Used config:
# Trace config 
trace + VPN-Status 
 
# Show commands 
show bootlog  
 
Komischerweise kommen die Verbindungen trotz Fehler zustande und funtionieren soweit auch tadellos, aber diese Fehler die einfach nicht aus dem Monitor verschwinden wollen lassen mir keine Ruhe...

Hat keiner irgendeine Idee an was das liegen könnte?

Bye Christian
Du hast keine ausreichende Berechtigung, um die Dateianhänge dieses Beitrags anzusehen.
Oliver
Beiträge: 50
Registriert: 20 Okt 2008, 12:21

Beitrag von Oliver »

Wenn die Geräte verunden sind, dann gehen wir mal die Checkliste durch:
Routing Tabellen editiert?
Firewall Regeln erstellt? (LAN A darf alles an LAN B schicken und umgekehrt?)
Antworten