salut,
<BR>bon j'suis largué pour la mise en place d'un vpn avec ipcop 1.3 et des roadwarrior XP pro ou 2000 sp3. j'ai suivi le howto qui va bien, mais meme la ca marche pas.
<BR>
<BR>shema de mon reseau :
<BR>reseau A : 192.168.5.0/24 contient ipcop et tout le reste du lan
<BR>reseau B : 192.168.6.0/24 contient les roadwarrior
<BR>
<BR>avant la mise en production je simule internet par hub.
<BR>
<BR>reseau B ------- HUB --------- reseau A
<BR>
<BR>maintenant mes fichiers de config :
<BR>cote ipcop :
<BR>
- Code: Tout sélectionner
<BR>ipsec.conf
<BR>-----------
<BR>conn warrior
<BR> compress=no
<BR> left=192.168.6.254
<BR> leftsubnet=192.168.5.0/24
<BR> leftnexthop=%defaultroute
<BR> type=tunnel
<BR> pfs=yes
<BR> right=%any
<BR> rightsubnet=
<BR> rightnexthop=%defaultroute
<BR> auto=add
<BR>-----------
<BR>
<BR>ipsec.secret
<BR>--------------
<BR>192.168.6.254 0.0.0.0 : PSK "abcdef"
<BR>192.168.6.254 %any : PSK "abcdef"
<BR>--------------
<BR>
<BR>
<BR>Maintenant cote Xp pro SP1
<BR>
- Code: Tout sélectionner
<BR>ipsec.conf
<BR>-----------
<BR>conn warrior
<BR> left=192.168.6.254
<BR> leftsubnet=192.168.5.0/24
<BR> right=%any
<BR> presharedkey=abcdef
<BR> network=auto
<BR> auto=start
<BR> pfs=yes
<BR>------------
<BR>
<BR>
<BR>Voila pour la config maintenant le resultat :
<BR>quand je lance ipsec cote xp, ca me renvoie pas de message d'erreur, au contraire cote ipcop pas de message d'erreur aussi <IMG SRC="images/smiles/icon_frown.gif"> extrait du dernier du fichier secure apres un redemarrage d'ipsec (ipsec setup restart)
<BR>
- Code: Tout sélectionner
<BR>Jul 29 14:36:43 svfirw ipsec__plutorun: Starting Pluto subsystem...
<BR>Jul 29 14:36:43 svfirw pluto[6839]: Starting Pluto (FreeS/WAN Version super-freeswan-1.99_kb2c)
<BR>Jul 29 14:36:43 svfirw pluto[6839]: including X.509 patch (Version 0.9.15)
<BR>Jul 29 14:36:43 svfirw pluto[6839]: including NAT-Traversal patch (Version 0.5a) [disabled]
<BR>Jul 29 14:36:43 svfirw pluto[6839]: ike_alg_register_enc: Activating OAKLEY_AES_CBC: Ok (ret=0)
<BR>Jul 29 14:36:43 svfirw pluto[6839]: ike_alg_register_enc: Activating OAKLEY_BLOWFISH_CBC: Ok (ret=0)
<BR>Jul 29 14:36:43 svfirw pluto[6839]: ike_alg_register_enc: Activating OAKLEY_CAST_CBC: Ok (ret=0)
<BR>Jul 29 14:36:43 svfirw pluto[6839]: ike_alg_register_enc: Activating OAKLEY_SERPENT_CBC: Ok (ret=0)
<BR>Jul 29 14:36:43 svfirw pluto[6839]: ike_alg_register_hash: Activating OAKLEY_SHA2_256: Ok (ret=0)
<BR>Jul 29 14:36:43 svfirw pluto[6839]: ike_alg_register_hash: Activating OAKLEY_SHA2_512: Ok (ret=0)
<BR>Jul 29 14:36:43 svfirw pluto[6839]: ike_alg_register_enc: Activating OAKLEY_TWOFISH_CBC: Ok (ret=0)
<BR>Jul 29 14:36:43 svfirw pluto[6839]: ike_alg_register_enc: Activating OAKLEY_SSH_PRIVATE_65289: Ok (ret=0)
<BR>Jul 29 14:36:43 svfirw pluto[6839]: Changing to directory '/etc/ipsec.d/cacerts'
<BR>Jul 29 14:36:43 svfirw pluto[6839]: Warning: empty directory
<BR>Jul 29 14:36:43 svfirw pluto[6839]: Changing to directory '/etc/ipsec.d/crls'
<BR>Jul 29 14:36:43 svfirw pluto[6839]: Warning: empty directory
<BR>Jul 29 14:36:43 svfirw pluto[6839]: could not open my default X.509 cert file '/etc/x509cert.der'
<BR>Jul 29 14:36:43 svfirw pluto[6839]: OpenPGP certificate file '/etc/pgpcert.pgp' not found
<BR>Jul 29 14:36:43 svfirw pluto[6839]: | from whack: got --esp=3des
<BR>Jul 29 14:36:43 svfirw pluto[6839]: | from whack: got --ike=3des
<BR>Jul 29 14:36:43 svfirw pluto[6839]: added connection description "roadwarrior"
<BR>Jul 29 14:36:43 svfirw pluto[6839]: listening for IKE messages
<BR>Jul 29 14:36:43 svfirw pluto[6839]: adding interface ipsec0/eth0 192.168.5.254
<BR>Jul 29 14:36:43 svfirw pluto[6839]: loading secrets from "/etc/ipsec.secrets"
<BR>
<BR>
<BR>j'continu dans le bizzard quand je fais un ping sur 192.168.5.254 a partir d'xp alors que je n'est pas lance ipsec, il me repond : negociation securite ip et si je fais la meme manip ca ping normalement, mais je ne peux pas ping 192.168.5.254 (hote introuvable)...
<BR>
<BR>j'ai le choix ou je me tire une balle ou je saute par le fenetre <IMG SRC="images/smiles/icon_smile.gif">