Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Astaro Gateway Products > VPN: Site to Site and Remote Access

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 01-06-2009, 07:18 PM
Junior Member
 
Join Date: Jan 2009
Posts: 4
Default VPN problems

I'm trying to connect with a Cisco VPN client using a IPSEC VPN. Intially I tried using pre-shared keys and I got the

unsupported exchange type ISAKMP_XCHG_AGGR

error message which I believe is an issue with the Cisco client. The fix was to use certs which I have now setup. However I am now getting the following error message

| protocol/port in Phase 1 ID Payload is 17/0. accepted with port_floating NAT-T
2009:01:06-21:13:00 (none) pluto[5473]: "D_Gateway_0"[2] 90.204.48.233 #4: Peer ID is ID_DER_ASN1_DN: 'C=uk, L=London, O=Private, CN=***x, E=***@***.com'
2009:01:06-21:13:00 (none) pluto[5473]: "D_Gateway_0"[2] 90.204.48.233 #4: self-signed cacert rejected
2009:01:06-21:13:00 (none) pluto[5473]: "D_Gateway_0"[2] 90.204.48.233 #4: crl not found
2009:01:06-21:13:00 (none) pluto[5473]: "D_Gateway_0"[2] 90.204.48.233 #4: certificate status unknown
2009:01:06-21:13:00 (none) pluto[5473]: "D_Gateway_0"[2] 90.204.48.233 #4: no suitable connection for peer 'C=uk, L=London, O=Private, CN=***x, E=***x@hotmail.com'
2009:01:06-21:13:00 (none) pluto[5473]: "D_Gateway_0"[2] 90.204.48.233 #4: sending encrypted notification INVALID_ID_INFORMATION to 90.204.48.233:500
2009:01:06-21:13:06 (none) pluto[5473]: "D_Gateway_0"[2] 90.204.48.233 #4: ignoring Delete SA payload: ISAKMP SA not established
2009:01:06-21:13:15 (none) pluto[5473]: ERROR: asynchronous network error report on eth0 for message to 90.204.48.233 port 500, complainant 90.204.48.233: Connection refused [errno 111, origin ICMP type 3 code 3 (not authenticated)]

Any ideas?
Reply With Quote
  #2 (permalink)  
Old 01-07-2009, 03:07 PM
Junior Member
 
Join Date: Jan 2009
Posts: 4
Default

After looking at this a bit longer I think this is an issue with asynchronous routing
Reply With Quote
  #3 (permalink)  
Old 01-08-2009, 05:04 PM
Jack Daniel's Avatar
Moderator
 
Join Date: Jul 2008
Location: Cape Cod, Mass, US
Posts: 355
Default

What version of ASG software are you using? Connections from Cisco IPSec VPN clients is not supported in the current (7.305) release, but will be include in 7.400 (available as beta, now 7.380).
__________________
Are you Linkedin to Astaro? http://www.linkedin.com/e/gis/139679/189D6C60EC64

Random Rants from an InfoSec Curmudgeon, UnCommon Sense Security Blog http://blog.uncommonsensesecurity.com
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 10:42 PM.

 

Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.