Re: site-to-site vpn 4.0 to cisco 3000

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: c l <lahrcm@...>
Cc: <misc@...>
Date: Sunday, February 25, 2007 - 9:53 pm

The man page for isakpd.conf indeed sheds some light, there's an
example in that page that show's how to specify lifetimes for both
phases...

[General]
Default-phase-1-lifetime= 3600,60:86400
Default-phase-2-lifetime= 1200,60:86400

At this point, if the lifetimes indeed agree, then I myself would be
a little puzzled over why the proposal would be rejected. Both
endpoints are configured to use the peer address as the ID? At first
blush, your settings seem all kosher.

I would agree, though, that it certainly appears that there must
still be some sort of inconsistency between the proposals.

Another suggestion...

It appears that you've been trying to initiate the VPN from one end,
perhaps the OpenBSD end. Probably by sending a ping from the 1st
site to the 2nd. Restart both ends to clear out any SAs that have
been negotiated and try to ping from the -other- end in order to see
what happens when the VPN negotiation is initiated the opposite
direction. The log entries might show something useful.

Also, did the OpenBSD logs show any detail of the failure from the
last attempts apart from the mismatched SA queries?

Bill

On Feb 25, 2007, at 14:48, c l wrote:

> Hello, thanks for the reply, it helped if I'm not mistaken. I

--
William Bloom
williambloom@mac.com

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
site-to-site vpn 4.0 to cisco 3000, c l, (Sun Feb 25, 1:23 pm)
Re: site-to-site vpn 4.0 to cisco 3000, William Bloom, (Sun Feb 25, 5:02 pm)
Re: site-to-site vpn 4.0 to cisco 3000, c l, (Sun Feb 25, 5:48 pm)
Re: site-to-site vpn 4.0 to cisco 3000, William Bloom, (Sun Feb 25, 10:16 pm)
Re: site-to-site vpn 4.0 to cisco 3000, William Bloom, (Sun Feb 25, 9:53 pm)
Re: site-to-site vpn 4.0 to cisco 3000 SOLVED, Claer, (Mon Feb 26, 5:02 am)
Re: site-to-site vpn 4.0 to cisco 3000 SOLVED, William Bloom, (Sun Feb 25, 10:19 pm)