par milo_guy » 20 Jan 2004 16:23
j'ai regarder les log d'ipcop et voici ce qu'il me sort:
<BR>
<BR>Jan 20 17:10:55 ipcop ipsec__plutorun: Starting Pluto subsystem...
<BR>Jan 20 17:10:55 ipcop pluto[1534]: Starting Pluto (FreeS/WAN Version super-freeswan-1.99_kb2c)
<BR>Jan 20 17:10:55 ipcop pluto[1534]: including X.509 patch (Version 0.9.15)
<BR>Jan 20 17:10:55 ipcop pluto[1534]: including NAT-Traversal patch (Version 0.5a) [disabled]
<BR>Jan 20 17:10:55 ipcop pluto[1534]: ike_alg_register_enc: Activating OAKLEY_AES_CBC: Ok (ret=0)
<BR>Jan 20 17:10:55 ipcop pluto[1534]: ike_alg_register_enc: Activating OAKLEY_BLOWFISH_CBC: Ok (ret=0)
<BR>Jan 20 17:10:55 ipcop pluto[1534]: ike_alg_register_enc: Activating OAKLEY_CAST_CBC: Ok (ret=0)
<BR>Jan 20 17:10:55 ipcop pluto[1534]: ike_alg_register_enc: Activating OAKLEY_SERPENT_CBC: Ok (ret=0)
<BR>Jan 20 17:10:55 ipcop pluto[1534]: ike_alg_register_hash: Activating OAKLEY_SHA2_256: Ok (ret=0)
<BR>Jan 20 17:10:55 ipcop pluto[1534]: ike_alg_register_hash: Activating OAKLEY_SHA2_512: Ok (ret=0)
<BR>Jan 20 17:10:55 ipcop pluto[1534]: ike_alg_register_enc: Activating OAKLEY_TWOFISH_CBC: Ok (ret=0)
<BR>Jan 20 17:10:55 ipcop pluto[1534]: ike_alg_register_enc: Activating OAKLEY_SSH_PRIVATE_65289: Ok (ret=0)
<BR>Jan 20 17:10:55 ipcop pluto[1534]: Changing to directory '/etc/ipsec.d/cacerts'
<BR>Jan 20 17:10:55 ipcop pluto[1534]: Warning: empty directory
<BR>Jan 20 17:10:55 ipcop pluto[1534]: Changing to directory '/etc/ipsec.d/crls'
<BR>Jan 20 17:10:55 ipcop pluto[1534]: Warning: empty directory
<BR>Jan 20 17:10:55 ipcop pluto[1534]: could not open my default X.509 cert file '/etc/x509cert.der'
<BR>Jan 20 17:10:55 ipcop pluto[1534]: OpenPGP certificate file '/etc/pgpcert.pgp' not found
<BR>Jan 20 17:10:56 ipcop pluto[1534]: | from whack: got --esp=3des
<BR>Jan 20 17:10:56 ipcop pluto[1534]: | from whack: got --ike=3des
<BR>Jan 20 17:10:56 ipcop pluto[1534]: added connection description "vpnnetinfo"
<BR>Jan 20 17:10:56 ipcop pluto[1534]: listening for IKE messages
<BR>Jan 20 17:10:56 ipcop pluto[1534]: adding interface ipsec0/eth1 195.242.162.5
<BR>Jan 20 17:10:56 ipcop pluto[1534]: loading secrets from "/etc/ipsec.secrets"
<BR>Jan 20 17:10:57 ipcop pluto[1534]: "vpnnetinfo" #1: initiating Main Mode
<BR>Jan 20 17:10:57 ipcop pluto[1534]: "vpnnetinfo" #1: ignoring Vendor ID payload [MS NT5 ISAKMPOAKLEY 00000003]
<BR>Jan 20 17:10:57 ipcop pluto[1534]: "vpnnetinfo" #1: Peer ID is ID_IPV4_ADDR: '195.242.162.6'
<BR>Jan 20 17:10:57 ipcop pluto[1534]: "vpnnetinfo" #1: ISAKMP SA established
<BR>Jan 20 17:10:57 ipcop pluto[1534]: "vpnnetinfo" #2: initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS+DISABLEARRIVALCHECK
<BR>Jan 20 17:10:57 ipcop pluto[1534]: "vpnnetinfo" #1: ignoring informational payload, type NO_PROPOSAL_CHOSEN
<BR>Jan 20 17:10:57 ipcop pluto[1534]: "vpnnetinfo" #1: received Delete SA payload: deleting ISAKMP State #1
<BR>Jan 20 17:11:07 ipcop pluto[1534]: packet from 195.242.162.6:500: ignoring informational payload, type INVALID_COOKIE
<BR>
<BR>
<BR>donc si je comprend bien le log, il m'identifie correctement "ISAKMP SA established" mais au moment d'ouvrir le tunnel, il stop tout.
<BR>
<BR>si vous avez deja vu ce prob quelque part.
<BR>