ich versuche gerade gemäß dem KB-Artikel ein Site2Site VPN zwischen der Digitalisierungsbox und einem LC 1781A einzurichten.
Habe mich (hoffentlich) genau an die Anleitung gehalten, aber der VPN baut nicht auf.
Ein tr # vpn-status zeigt:
Code: Alles auswählen
root@1781A:/
> tr # vpn-st @ DIGIBOX
VPN-Status ON @ DIGIBOX
[VPN-Status] 2016/11/25 10:14:07,378
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE sent for Phase-1 SA to peer DIGIBOX, sequence nr 0x27aba8c
[VPN-Status] 2016/11/25 10:14:07,408
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE_ACK for peer DIGIBOX Seq-Nr 0x27aba8c, expected 0x27aba8c
[VPN-Status] 2016/11/25 10:14:16,937
IKE info: Delete Notification received for Phase-1 SA isakmp-peer-DIGIBOX peer DIGIBOX cookies [0xca779a1321615b97 0x515063a03de6d89a]
[VPN-Status] 2016/11/25 10:14:16,937
IKE info: Phase-1 SA removed: peer DIGIBOX rule DIGIBOX removed
[VPN-Status] 2016/11/25 10:14:16,939
vpn-maps[24], remote: DIGIBOX, idle, static-name
[VPN-Status] 2016/11/25 10:14:16,939
vpn-maps[24], remote: DIGIBOX, idle, static-name
[VPN-Status] 2016/11/25 10:14:25,548
IKE info: The remote peer DIGIBOX supports NAT-T in draft mode
IKE info: The remote peer DIGIBOX supports NAT-T in draft mode
IKE info: The remote server 80.147.207.100:871 (UDP) peer DIGIBOX id <no_id> supports draft-ietf-ipsec-isakmp-xauth
IKE info: The remote server 80.147.207.100:871 (UDP) peer DIGIBOX id <no_id> negotiated rfc-3706-dead-peer-detection
[VPN-Status] 2016/11/25 10:14:25,549
IKE info: phase-1 proposal failed: remote No 1 encryption algorithm = 3DES_CBC <-> local No 1 encryption algorithm = AES_CBC
IKE info: phase-1 proposal failed: remote No 1 encryption algorithm = 3DES_CBC <-> local No 2 encryption algorithm = AES_CBC
IKE info: phase-1 proposal failed: remote No 1 encryption algorithm = 3DES_CBC <-> local No 3 encryption algorithm = AES_CBC
IKE info: phase-1 proposal failed: remote No 1 encryption algorithm = 3DES_CBC <-> local No 4 encryption algorithm = BLOWFISH_CBC
IKE info: phase-1 proposal failed: remote No 1 encryption algorithm = 3DES_CBC <-> local No 5 encryption algorithm = BLOWFISH_CBC
IKE info: phase-1 proposal failed: remote No 1 hash algorithm = MD5 <-> local No 6 hash algorithm = SHA1
IKE info: Phase-1 remote proposal 1 for peer DIGIBOX matched with local proposal 7
[VPN-Status] 2016/11/25 10:14:25,716
IKE info: Phase-1 [responder] got INITIAL-CONTACT from peer DIGIBOX (80.147.207.100)
[VPN-Status] 2016/11/25 10:14:25,717
IKE info: Phase-1 SA Rekeying Timeout (Soft-Event) for peer DIGIBOX set to 25920 seconds (Responder)
[VPN-Status] 2016/11/25 10:14:25,717
IKE info: Phase-1 SA Timeout (Hard-Event) for peer DIGIBOX set to 28800 seconds (Responder)
[VPN-Status] 2016/11/25 10:14:25,717
Phase-1 [responder] for peer DIGIBOX initiator id digibox.test, responder id lancom.test
initiator cookie: 0xFC1175AB0DE3BEE3, responder cookie: 0xEABEA2EC9958F9D9
NAT-T enabled in mode draft. We are not behind a nat, the remote side is behind a nat
SA ISAKMP for peer DIGIBOX encryption 3des-cbc authentication MD5
life time soft 11/25/2016 17:26:25 (in 25920 sec) / 0 kb
life time hard 11/25/2016 18:14:25 (in 28800 sec) / 0 kb
[VPN-Status] 2016/11/25 10:14:37,718
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE sent for Phase-1 SA to peer DIGIBOX, sequence nr 0x44492503
[VPN-Status] 2016/11/25 10:14:37,748
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE_ACK for peer DIGIBOX Seq-Nr 0x44492503, expected 0x44492503
[VPN-Status] 2016/11/25 10:15:37,749
IKE info: ISAKMP_NOTIFY_DPD_R_U_THERE sent for Phase-1 SA to peer DIGIBOX, sequence nr 0x44492504
[VPN-Status] 2016/11/25 10:15:37,779
IKE info: NOTIFY received of type ISAKMP_NOTIFY_DPD_R_U_THERE_ACK for peer DIGIBOX Seq-Nr 0x44492504, expected 0x44492504
Code: Alles auswählen
Rule #7 ikev1 192.168.41.0/255.255.255.0:0 <-> 192.168.51.0/255.255.255.0:0 any
Name: DIGIBOX
Unique Id: ipsec-0-DIGIBOX-pr0-l0-r0
Flags: aggressive-mode
Local Network: IPV4_ADDR_SUBNET(any:0, 192.168.41.0/255.255.255.0)
Local Gateway: IPV4_ADDR(any:0, [öffentliche IP am LANCOM])
Remote Gateway: IPV4_ADDR(any:0, [öffentliche IP an Digibox])
Remote Network: IPV4_ADDR_SUBNET(any:0, 192.168.51.0/255.255.255.0)
Danke Euch!
hyperjojo