IPSec mit Dyndns
Verfasst: Do 16.04.2009, 13:06
Hallo,
ich habe ziemliche Probleme mit ipsec zwischen 2 Securepoints. Ich bekomme im Log immer die Meldung INVALID_ID_INFORMATION.
Eigenschaften der IPSec-Verbindung:
Auth: Secret
Firewall 1:
Entfernter Host/Gateway: firewall2.dyndns.org
Haken bei DynDns Name gesetzt
Entfernter Host/Gateway-ID: @firewall2.dyndns.org
Haken bei Dead peer Detection gesetzt
Firewall 2:
Entfernter Host/Gateway: %firewall1.dyndns.org
Entfernter Host/Gateway-ID: @firewall1.dyndns.org
Subnetze:
192.168.106.0/24
192.168.0.0/24
Auszug aus Log:
added connection description "firewall1.dom1.local__GT__firewall2.dom2.local_8"
firewall1.dom1.local__GT__firewall2.dom2.local_8 #1: initiating Main Mode
firewall1.dom1.local__GT__firewall2.dom2.local_8 #1: ignoring Vendor ID payload [strongSwan 2.8.8]
firewall1.dom1.local__GT__firewall2.dom2.local_8 #1: received Vendor ID payload [XAUTH]
firewall1.dom1.local__GT__firewall2.dom2.local_8 #1: received Vendor ID payload [Dead Peer Detection]
firewall1.dom1.local__GT__firewall2.dom2.local_8 #1: received Vendor ID payload [RFC 3947]
firewall1.dom1.local__GT__firewall2.dom2.local_8 #1: enabling possible NAT-traversal with method 3
firewall1.dom1.local__GT__firewall2.dom2.local_8 #1: NAT-Traversal: Result using RFC 3947: no NAT detected
firewall1.dom1.local__GT__firewall2.dom2.local_8 #1: ignoring informational payload, type INVALID_ID_INFORMATION
firewall1.dom1.local__GT__firewall2.dom2.local_8 #1: discarding duplicate packet already STATE_MAIN_I3
firewall1.dom1.local__GT__firewall2.dom2.local_8 #1: ignoring informational payload, type INVALID_ID_INFORMATION
firewall1.dom1.local__GT__firewall2.dom2.local_8 #1: discarding duplicate packet already STATE_MAIN_I3
firewall1.dom1.local__GT__firewall2.dom2.local_8 #1: ignoring informational payload, type INVALID_ID_INFORMATION
packet from 89.246.213.30:500: ignoring Vendor ID payload [strongSwan 2.8.8]
packet from 89.246.213.30:500: received Vendor ID payload [XAUTH]
packet from 89.246.213.30:500: received Vendor ID payload [Dead Peer Detection]
packet from 89.246.213.30:500: received Vendor ID payload [RFC 3947]
packet from 89.246.213.30:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03]
packet from 89.246.213.30:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02]
packet from 89.246.213.30:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n]
packet from 89.246.213.30:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]
firewall1.dom1.local__GT__firewall2.dom2.local_8 #2: responding to Main Mode
firewall1.dom1.local__GT__firewall2.dom2.local_8 #2: NAT-Traversal: Result using RFC 3947: no NAT detected
firewall1.dom1.local__GT__firewall2.dom2.local_8 #2: Peer ID is ID_IPV4_ADDR: '89.246.213.30'
firewall1.dom1.local__GT__firewall2.dom2.local_8 #2: no suitable connection for peer '89.246.213.30'
firewall1.dom1.local__GT__firewall2.dom2.local_8 #2: sending encrypted notification INVALID_ID_INFORMATION to 89.246.213.30:500
firewall1.dom1.local__GT__firewall2.dom2.local_8 #2: Peer ID is ID_IPV4_ADDR: '89.246.213.30'
Auf beiden Firewalls werden die DynDns-Namen in die akuelle IP aufgelöst.
Wäre schön wenn ich eine Tipp bekomme um das Problem zu beheben.
MfG Dirk
ich habe ziemliche Probleme mit ipsec zwischen 2 Securepoints. Ich bekomme im Log immer die Meldung INVALID_ID_INFORMATION.
Eigenschaften der IPSec-Verbindung:
Auth: Secret
Firewall 1:
Entfernter Host/Gateway: firewall2.dyndns.org
Haken bei DynDns Name gesetzt
Entfernter Host/Gateway-ID: @firewall2.dyndns.org
Haken bei Dead peer Detection gesetzt
Firewall 2:
Entfernter Host/Gateway: %firewall1.dyndns.org
Entfernter Host/Gateway-ID: @firewall1.dyndns.org
Subnetze:
192.168.106.0/24
192.168.0.0/24
Auszug aus Log:
added connection description "firewall1.dom1.local__GT__firewall2.dom2.local_8"
firewall1.dom1.local__GT__firewall2.dom2.local_8 #1: initiating Main Mode
firewall1.dom1.local__GT__firewall2.dom2.local_8 #1: ignoring Vendor ID payload [strongSwan 2.8.8]
firewall1.dom1.local__GT__firewall2.dom2.local_8 #1: received Vendor ID payload [XAUTH]
firewall1.dom1.local__GT__firewall2.dom2.local_8 #1: received Vendor ID payload [Dead Peer Detection]
firewall1.dom1.local__GT__firewall2.dom2.local_8 #1: received Vendor ID payload [RFC 3947]
firewall1.dom1.local__GT__firewall2.dom2.local_8 #1: enabling possible NAT-traversal with method 3
firewall1.dom1.local__GT__firewall2.dom2.local_8 #1: NAT-Traversal: Result using RFC 3947: no NAT detected
firewall1.dom1.local__GT__firewall2.dom2.local_8 #1: ignoring informational payload, type INVALID_ID_INFORMATION
firewall1.dom1.local__GT__firewall2.dom2.local_8 #1: discarding duplicate packet already STATE_MAIN_I3
firewall1.dom1.local__GT__firewall2.dom2.local_8 #1: ignoring informational payload, type INVALID_ID_INFORMATION
firewall1.dom1.local__GT__firewall2.dom2.local_8 #1: discarding duplicate packet already STATE_MAIN_I3
firewall1.dom1.local__GT__firewall2.dom2.local_8 #1: ignoring informational payload, type INVALID_ID_INFORMATION
packet from 89.246.213.30:500: ignoring Vendor ID payload [strongSwan 2.8.8]
packet from 89.246.213.30:500: received Vendor ID payload [XAUTH]
packet from 89.246.213.30:500: received Vendor ID payload [Dead Peer Detection]
packet from 89.246.213.30:500: received Vendor ID payload [RFC 3947]
packet from 89.246.213.30:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03]
packet from 89.246.213.30:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02]
packet from 89.246.213.30:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n]
packet from 89.246.213.30:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]
firewall1.dom1.local__GT__firewall2.dom2.local_8 #2: responding to Main Mode
firewall1.dom1.local__GT__firewall2.dom2.local_8 #2: NAT-Traversal: Result using RFC 3947: no NAT detected
firewall1.dom1.local__GT__firewall2.dom2.local_8 #2: Peer ID is ID_IPV4_ADDR: '89.246.213.30'
firewall1.dom1.local__GT__firewall2.dom2.local_8 #2: no suitable connection for peer '89.246.213.30'
firewall1.dom1.local__GT__firewall2.dom2.local_8 #2: sending encrypted notification INVALID_ID_INFORMATION to 89.246.213.30:500
firewall1.dom1.local__GT__firewall2.dom2.local_8 #2: Peer ID is ID_IPV4_ADDR: '89.246.213.30'
Auf beiden Firewalls werden die DynDns-Namen in die akuelle IP aufgelöst.
Wäre schön wenn ich eine Tipp bekomme um das Problem zu beheben.
MfG Dirk