par beuzz » 02 Déc 2003 19:50
Bonjour à tous .. <IMG SRC="images/smiles/icon_wink.gif">
<BR>
<BR>Malgre vos différents docs qui m'ont été bien utile je ne m'en sors tjs pas avec mon vpn sur ma mnf avec un client XP
<BR>
<BR>Pour commencer sur la mnf, au démarrage d'ipsce j'ai :
<BR>déc 2 18:26:33 vpn ipsec_setup: WARNING: eth1 has route filtering turned on, KLIPS may not work
<BR>déc 2 18:26:33 vpn ipsec_setup: (/proc/sys/net/ipv4/conf/eth1/rp_filter = `1', should be 0)
<BR>déc 2 18:26:33 vpn ipsec_setup: ...FreeS/WAN IPsec started
<BR>
<BR>Cela peut il être à l'origine de mon problème ?? J'ai pourtant autorisé le traffic vpn à passer ! ,( ..
<BR>
<BR>Mes zones sont :
<BR>1 lan eth0 detect
<BR>2 wan eth1 detect
<BR>3 dmz eth2 detect
<BR>4 vpn ipsec0 detect
<BR>
<BR>
<BR>Coté XP ..
<BR>l'initialisation d'ipsec est Ok
<BR>pi j'ai 180 lignes de logs incompréhensibles (j'ai mis le mode2)
<BR>puis j'ai :
<BR>
<BR>12-02: 18:37:03:845:554 Adresse IP sourceXX.XX.XXX.XX(ipfixe du client : semble ok)
<BR>Masque d'adresse IP source 255.255.255.255 (pas bon c 0 à la fin ..)
<BR>Adresse IP de destination XX.XX.XX.XXX(ip fixe de la mnf : ok)
<BR>Masque d'adresse IP de destination 255.255.255.255 (pas bon c 240 pour subnet public et 0 pour le subnet local)
<BR>Protocole 0
<BR>Port source 0
<BR>Port de destination 0
<BR>Adresse locale IKE
<BR>Adresse homologue IKE
<BR>
<BR>12-02: 18:37:03:845:554
<BR>12-02: 18:37:03:845:554 Moi
<BR>
<BR>12-02: 18:37:03:845:554 SA IKE supprimée avant que l'établissement ait été terminé
<BR>
<BR>12-02: 18:37:03:845:554 0x0 0x0
<BR>12-02: 18:37:03:845:554 isadb_set_status InitiateEvent 00000474: Setting Status 35f0
<BR>12-02: 18:37:03:845:554 Clearing sa 000EEA08 InitiateEvent 00000474
<BR>12-02: 18:37:03:845:554 constructing ISAKMP Header
<BR>12-02: 18:37:03:845:554 constructing DELETE. MM 000EEA08
<BR>12-02: 18:37:03:845:554
<BR>12-02: 18:37:03:845:554 Sending: SA = 0x000EEA08 to XX.XX.XX.XX (IPPUBLIC MNF):Type 1
<BR>12-02: 18:37:03:845:554 ISAKMP Header: (V1.0), len = 56
<BR>12-02: 18:37:03:845:554 I-COOKIE 4516ed0bee3eede6
<BR>12-02: 18:37:03:845:554 R-COOKIE 0000000000000000
<BR>12-02: 18:37:03:845:554 exchange: ISAKMP Informational Exchange
<BR>12-02: 18:37:03:845:554 flags: 0
<BR>12-02: 18:37:03:845:554 next payload: DELETE
<BR>12-02: 18:37:03:845:554 message ID: d96c0aab
<BR>12-02: 18:37:03:861:2c0 CloseNegHandle 00000474
<BR>12-02: 18:37:03:861:554 WSASendTo error 10061
<BR>12-02: 18:37:03:861:2c0 SE cookie 4516ed0bee3eede6
<BR>12-02: 18:37:03:877:a24 isadb_schedule_kill_oldPolicy_sas: f8b19a3a-e31b-4d76-bb055219b34721ef 4
<BR>12-02: 18:37:03:877:f0c isadb_schedule_kill_oldPolicy_sas: 7ce927f3-944d-43a4-9cc3c4ceb4b20ce1 3
<BR>12-02: 18:37:03:877:2c0 isadb_schedule_kill_oldPolicy_sas: a44a9e03-0876-48e3-8b24bf5ed78a6d07 2
<BR>12-02: 18:37:03:877:554 entered kill_old_policy_sas
<BR>12-02: 18:37:03:877:554 entered kill_old_policy_sas
<BR>12-02: 18:37:03:877:bc8 entered kill_old_policy_sas
<BR>12-02: 18:37:03:892:a24 isadb_schedule_kill_oldPolicy_sas: 075bc9e4-c009-4d53-a1364a012f6fb19a 1
<BR>12-02: 18:37:03:892:bc8 entered kill_old_policy_sas
<BR>
<BR>si vous comprenez qqchose je veux bien votre avis éclairé ! ..
<BR>
<BR>Ma conf IPSEC coté XP :
<BR>conn %default
<BR> dial=Free ADSL
<BR>
<BR>conn fix
<BR> right=%any
<BR> left=XX.XX.XX.XX (IPPUBLIQUE MNF)
<BR> leftsubnet=192.168.1.0/24 (SUBNET LAN)
<BR> rightca="C=FR, S=France, L=Paris, ..."
<BR> network=auto
<BR> auto=start
<BR> pfs=yes
<BR>
<BR>coté MNF :
<BR>
<BR>config setup
<BR> interfaces=%defaultroute
<BR> klipsdebug=none
<BR> plutodebug=none
<BR> plutoload=%search
<BR> plutostart=%search
<BR> uniqueids=yes
<BR>
<BR>conn %default
<BR> keyingtries=1
<BR> compress=yes
<BR> disablearrivalcheck=no
<BR> authby=rsasig
<BR> leftrsasigkey=%cert
<BR> rightrsasigkey=%cert
<BR>
<BR>conn fix
<BR> left=%defaultroute
<BR> leftsubnet=192.168.1.0/24
<BR> right=%any
<BR> leftcert=monvpn.pem
<BR> auto=add
<BR> pfs=yes
<BR>
<BR>Qu'en pensez vous paske moi <IMG SRC="images/smiles/icon_cussing.gif">
<BR>
<BR>i need <IMG SRC="images/smiles/icon_help.gif">
<BR>
<BR>