Hallo Leute,
muss mich noch einmal zu Wort melden.
Wie es scheint habe ich nun endlich eine Phase 1 Verbindung zwischen beiden Geräten hinbekommen
Allerdings komme ich nun über die Phase 2 nicht hinaus.
Irgendetwas stimmt mit den IPSEC-Proposalen noch nicht.
"IKE info: NOTIFY received of type NO_PROPOSAL_CHOSEN for peer MICHAEL"
Ich habe schon vorsichtig versucht manuell in der Lancom-VPN-Konfiguration etwas zu verändern, leider ohne Ergebnis.
Weis jemand an welchen Rad ich drehen muss?
root@LANCOM_1:/
> trace + vpn
VPN :
VPN-Status ON
VPN-Packet ON
root@LANCOM_1:/
>
[VPN-Status] 2006/04/02 12:28:20,650
VPN: connecting to MICHAEL (89.49.19.230)
[VPN-Status] 2006/04/02 12:28:20,660
VPN: installing ruleset for MICHAEL (89.49.19.230)
[VPN-Status] 2006/04/02 12:28:20,680
VPN: ruleset installed for MICHAEL (89.49.19.230)
[VPN-Status] 2006/04/02 12:28:20,680
VPN: start IKE negotiation for MICHAEL (89.49.19.230)
[VPN-Status] 2006/04/02 12:28:20,690
VPN: rulesets installed
[VPN-Packet] 2006/04/02 12:28:20,690
for send: 10.0.0.28->192.168.1.1 60 ICMP ECHOREQUEST
[VPN-Packet] 2006/04/02 12:28:20,690
no sa available: give up, should be retransmitted
[VPN-Status] 2006/04/02 12:28:20,700
IKE info: Phase-1 negotiation started for peer MICHAEL rule isakmp-peer-MICHAEL
using AGGRESSIVE mode
[VPN-Packet] 2006/04/02 12:28:21,680
for send: 10.0.0.28->192.168.1.1 60 ICMP ECHOREQUEST
[VPN-Packet] 2006/04/02 12:28:21,680
no sa available: give up, should be retransmitted
[VPN-Status] 2006/04/02 12:28:22,300
IKE info: phase-1 proposal failed: remote No 1 encryption algorithm = 3DES_CBC <
-> local No 1 encryption algorithm = AES_CBC
IKE info: phase-1 proposal failed: remote No 1 encryption algorithm = 3DES_CBC <
-> local No 2 encryption algorithm = AES_CBC
IKE info: phase-1 proposal failed: remote No 1 encryption algorithm = 3DES_CBC <
-> local No 3 encryption algorithm = BLOWFISH_CBC
IKE info: phase-1 proposal failed: remote No 1 encryption algorithm = 3DES_CBC <
-> local No 4 encryption algorithm = BLOWFISH_CBC
IKE info: Phase-1 remote proposal 1 for peer MICHAEL matched with local proposal
5
[VPN-Status] 2006/04/02 12:28:22,450
IKE info: Phase-1 [inititiator] for peer MICHAEL between initiator id LANCOM_1,
responder id MICHAEL done
IKE info: SA ISAKMP for peer MICHAEL encryption 3des-cbc authentication md5
IKE info: life time ( 108000 sec/ 0 kb)
[VPN-Packet] 2006/04/02 12:28:22,680
for send: 10.0.0.28->192.168.1.1 60 ICMP ECHOREQUEST
[VPN-Packet] 2006/04/02 12:28:22,680
no sa available: give up, should be retransmitted
[VPN-Status] 2006/04/02 12:28:22,860
IKE info: NOTIFY received of type NO_PROPOSAL_CHOSEN for peer MICHAEL
[VPN-Status] 2006/04/02 12:28:22,860
VPN: Error: IPSEC-I-No-proposal-matched (0x3102) for MICHAEL (89.49.19.230)
[VPN-Status] 2006/04/02 12:28:22,860
IKE info: Delete Notification received for Phase-1 SA isakmp-peer-MICHAEL peer M
ICHAEL cookies [60c45c276736d6c4 8e1ad42943b073e2]
[VPN-Status] 2006/04/02 12:28:22,860
IKE info: Phase-1 SA removed: peer MICHAEL rule MICHAEL removed
[VPN-Status] 2006/04/02 12:28:22,870
VPN: MICHAEL (89.49.19.230) disconnected
[VPN-Status] 2006/04/02 12:28:22,870
VPN: Disconnect info: remote-disconnected (0x4301) for MICHAEL (89.49.19.230)
Schon mal dánke und noch einen schönen Nachmittag.