par kinkey » 26 Août 2003 10:57
salut
<BR>-------------------------------------
<BR>recap de la config :
<BR>ipcop
<BR>- eth0 (GREEN) : 192.168.5.254/255.255.255.0 : par vers un HUB ou je suis seul dessus.
<BR>- eth1 (RED) : 192.168.6.254/255.255.255.0
<BR>
<BR>roadwarrior xp pro sp1
<BR>ip : 192.168.6.200/255.255.255.0
<BR>je suis hors reseau, l'xp est connecte direct sur ipcop par un cable croise sur le RED
<BR>-------------------------------------
<BR>bon la je craque.
<BR>j'ai suivi a la lettre le post ici <!-- BBCode auto-link start --><a href="http://forums.ixus.net/viewtopic.php?t=3913&14" target="_blank">http://forums.ixus.net/viewtopic.php?t=3913&14</a><!-- BBCode auto-link end -->
<BR>
<BR>--- ipsec.conf ipcop ---
<BR>config setup
<BR> interfaces=%defaultroute
<BR> klipsdebug=none
<BR> plutodebug=none
<BR> plutoload=%search
<BR> plutostart=%search
<BR>
<BR>conn %default
<BR> keyingtries=0
<BR>
<BR>conn clientwin
<BR> left=192.168.6.254
<BR> compress=no
<BR> leftsubnet=192.168.6.0/24
<BR> leftnexthop=%defaultroute
<BR> type=tunnel
<BR> authby=secret
<BR> pfs=yes
<BR> right=%any
<BR> rightnexthop=%defaultroute
<BR> auto=add
<BR>--- ipsec.conf ipcop ---
<BR>
<BR>--- ipsec.secrets ipcop ---
<BR>192.168.6.254 %any : PSK "abcdef"
<BR>192.168.6.254 0.0.0.0 : PSK "abcdef"
<BR>--- ipsec.secrets ipcop ---
<BR>
<BR>--- extrait de mon /var/log/messages apres un redemarrage du VPN ---
<BR>Aug 26 10:44:12 svfirw ipsec_setup: Stopping FreeS/WAN IPsec...
<BR>Aug 26 10:44:13 svfirw kernel: IPSEC EVENT: KLIPS device ipsec0 shut down.
<BR>Aug 26 10:44:13 svfirw kernel: klips_info:pfkey_cleanup: shutting down PF_KEY domain sockets.
<BR>Aug 26 10:44:13 svfirw kernel: klips_info:cleanup_module: ipsec module unloaded.
<BR>Aug 26 10:44:14 svfirw ipsec_setup: ...FreeS/WAN IPsec stopped
<BR>Aug 26 10:44:14 svfirw ipsec_setup: Starting FreeS/WAN IPsec super-freeswan-1.99_kb2c...
<BR>Aug 26 10:44:14 svfirw ipsec_setup: Using /lib/modules/2.4.21/kernel/net/ipsec/ipsec.o
<BR>Aug 26 10:44:14 svfirw kernel: klips_info:ipsec_init: KLIPS startup, FreeS/WAN IPSec version: super-freeswan-1.99_kb2c
<BR>Aug 26 10:44:14 svfirw kernel: klips_info:ipsec_alg_init: KLIPS alg v=0.7.3-1 (EALG_MAX=255, AALG_MAX=15)
<BR>Aug 26 10:44:14 svfirw kernel: klips_info:ipsec_alg_init: calling ipsec_alg_static_init()
<BR>Aug 26 10:44:14 svfirw ipsec_setup: KLIPS debug `none'
<BR>Aug 26 10:44:14 svfirw ipsec_setup: KLIPS ipsec0 on eth0 192.168.5.254/255.255.255.0 broadcast 192.168.5.255
<BR>Aug 26 10:44:14 svfirw ipsec_setup: ...FreeS/WAN IPsec started
<BR>--- extrait de mon /var/log/messages apres un redemarrage du VPN ---
<BR>
<BR>deja premiere chose bizarre il me monte ipsec0 sur eth0 qui est mon interface GREEN.
<BR>je precise aussi que j'ai ete oblige de parametre la passerelle et les dns sur ipcop :
<BR>passerelle : 192.168.5.254 j'ai essaye de mettre 192.168.6.254 mais apres plus moyen de me connecter sur ipcop en ssh ou en http. les dns sont ceux de wanadoo.
<BR>
<BR>--- extrait de /var/log/secure apres un redemarrage du vpn ---
<BR>Aug 26 10:44:12 svfirw pluto[1006]: shutting down
<BR>Aug 26 10:44:12 svfirw pluto[1006]: forgetting secrets
<BR>Aug 26 10:44:12 svfirw pluto[1006]: "clientwin": deleting connection
<BR>Aug 26 10:44:12 svfirw pluto[1006]: shutting down interface ipsec0/eth0 192.168.5.254
<BR>Aug 26 10:44:14 svfirw ipsec__plutorun: Starting Pluto subsystem...
<BR>Aug 26 10:44:14 svfirw pluto[1342]: Starting Pluto (FreeS/WAN Version super-freeswan-1.99_kb2c)
<BR>Aug 26 10:44:14 svfirw pluto[1342]: including X.509 patch (Version 0.9.15)
<BR>Aug 26 10:44:14 svfirw pluto[1342]: including NAT-Traversal patch (Version 0.5a) [disabled]
<BR>Aug 26 10:44:14 svfirw pluto[1342]: ike_alg_register_enc: Activating OAKLEY_AES_CBC: Ok (ret=0)
<BR>Aug 26 10:44:14 svfirw pluto[1342]: ike_alg_register_enc: Activating OAKLEY_BLOWFISH_CBC: Ok (ret=0)
<BR>Aug 26 10:44:14 svfirw pluto[1342]: ike_alg_register_enc: Activating OAKLEY_CAST_CBC: Ok (ret=0)
<BR>Aug 26 10:44:14 svfirw pluto[1342]: ike_alg_register_enc: Activating OAKLEY_SERPENT_CBC: Ok (ret=0)
<BR>Aug 26 10:44:14 svfirw pluto[1342]: ike_alg_register_hash: Activating OAKLEY_SHA2_256: Ok (ret=0)
<BR>Aug 26 10:44:14 svfirw pluto[1342]: ike_alg_register_hash: Activating OAKLEY_SHA2_512: Ok (ret=0)
<BR>Aug 26 10:44:14 svfirw pluto[1342]: ike_alg_register_enc: Activating OAKLEY_TWOFISH_CBC: Ok (ret=0)
<BR>Aug 26 10:44:14 svfirw pluto[1342]: ike_alg_register_enc: Activating OAKLEY_SSH_PRIVATE_65289: Ok (ret=0)
<BR>Aug 26 10:44:14 svfirw pluto[1342]: Changing to directory '/etc/ipsec.d/cacerts'
<BR>Aug 26 10:44:14 svfirw pluto[1342]: Warning: empty directory
<BR>Aug 26 10:44:14 svfirw pluto[1342]: Changing to directory '/etc/ipsec.d/crls'
<BR>Aug 26 10:44:14 svfirw pluto[1342]: Warning: empty directory
<BR>Aug 26 10:44:14 svfirw pluto[1342]: could not open my default X.509 cert file '/etc/x509cert.der'
<BR>Aug 26 10:44:14 svfirw pluto[1342]: OpenPGP certificate file '/etc/pgpcert.pgp' not found
<BR>Aug 26 10:44:15 svfirw pluto[1342]: | from whack: got --esp=3des
<BR>Aug 26 10:44:15 svfirw pluto[1342]: | from whack: got --ike=3des
<BR>Aug 26 10:44:15 svfirw pluto[1342]: added connection description "clientwin"
<BR>Aug 26 10:44:15 svfirw pluto[1342]: listening for IKE messages
<BR>Aug 26 10:44:15 svfirw pluto[1342]: adding interface ipsec0/eth0 192.168.5.254
<BR>Aug 26 10:44:15 svfirw pluto[1342]: loading secrets from "/etc/ipsec.secrets"
<BR>--- extrait de /var/log/secure apres un redemarrage du vpn ---
<BR>
<BR>maintenant cote XP
<BR>alors la c le fin du fin <IMG SRC="images/smiles/icon_boxe2.gif">
<BR>--- ipsec.conf XP ---
<BR>conn clientwin
<BR>left=192.168.6.254
<BR>leftsubnet=192.168.6.0/24
<BR>right=%any
<BR>presharedkey=abcdef
<BR>network=auto
<BR>auto=start
<BR>pfs=yes
<BR>--- ipsec.conf XP ---
<BR>
<BR>quand je lance ipsec.exe j'ai le message suivants :
<BR>C:Program FilesSupport Tools>ipsec
<BR>IPSec Version 2.2.0 (c) 2001-2003 M...
<BR>Getting running Config ...
<BR>Microsoft's Windows XP identified
<BR>Setting up IPSec ...
<BR>
<BR> Deactivating old policy...
<BR> Removing old policy...
<BR>
<BR>Connection clientwin :
<BR>Could not identify my own Interface
<BR>
<BR>bien sur histoire de compliquer la chose pas de trace de quoi que ce sois dans les log <IMG SRC="images/smiles/icon_frown.gif">
<BR>
<BR>si par hasard quelqu'un avait le courage de ce pancher sur le prb, sa serait cool <IMG SRC="images/smiles/icon_help.gif">