Re: isakmpd -- NCP IPsec client: peer proposed invalid phase 2 IDs

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Prabhu Gurumurthy
Date: Friday, June 27, 2008 - 10:16 am

I do not know whether Windows XP native IPsec stack supports AES, I know it only 
supports upto 3des. With OpenBSD, the default is AES (128), that is why IKE is 
giving you NO_PROPOSAL_CHOSEN. Change you settings to include 3des and sha1 (or 
md5 may be) and you would get quick mode working.

Prabhu
-

Harald Dunkel wrote:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: isakmpd -- NCP IPsec client: peer proposed invalid pha ..., Prabhu Gurumurthy, (Fri Jun 27, 10:16 am)