login
Header Space

 
 

Re: ipsec vpn netgear DG834 : openbsd 4.2 (new thread)

Score:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: <misc@...>
Date: Tuesday, November 27, 2007 - 7:56 am

Hi,

here my 50 cent:

tcpdump looks good, obsd maschine receives first message of phase 1 exchange
and sends a suitable response.

your netgear log says, that no response to first message is received.

this means, response from isakmpd gets lost, either in local pf or in netgear
( dont know if they have some sort packet filter ) or somewhere in between .

you could distinguish there two possibilities by either

tcpdump -lenvvi pflog0 # watch out for packets to if_A that are blocked

or

tcpdump -lenvvi <external if> ip host if_A   ( you should see exactly one
message in and one message out )

Once we know whether the packets really leave openBSD, we can do further
analysis.



Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: ipsec vpn netgear DG834 : openbsd 4.2 (new thread), Christoph Leser, (Tue Nov 27, 8:02 am)
Re: ipsec vpn netgear DG834 : openbsd 4.2 (new thread), Christoph Leser, (Tue Nov 27, 7:56 am)
speck-geostationary