J'ai suivi à la lettre le document de ElfeClair (http://forums.fr.ixus.net/viewtopic.php?p=161103#161103). Je l'ai fait par deux fois et j'arrive tout le temps au meme résultat.
Voici le schéma de mon réseau :
INTERNET ----------- RED(CABLE, DHCP) - IPCOP - GREEN(10.0.0.1) ------------- 10.0.0.0/24
Le poste client est derriere un routeur sans-fil DLink DI524.
Voici les symptômes :
SSH Sentinel me donne l'erreur suivante lors de la tentative de connexion au VPN :
- Code: Tout sélectionner
Cannot open the VPN connection. Check that the gateway is online and verify that you are using the correct authentication key.
Voici le log IKE en moderate de SSH Sentinel :
- Code: Tout sélectionner
DEBUG: 0.0.0.0:500 (Initiator) <-> x.x.x.x:500 { 447636fc 4d000012 - 00000000 00000000 [-1] / 0x00000000 } IP; Start isakmp sa negotiation
DEBUG: 0.0.0.0:500 (Initiator) <-> x.x.x.x:500 { 447636fc 4d000012 - 00000000 00000000 [-1] / 0x00000000 } IP; Version = 1.0, Input packet fields = 0000
DEBUG: 0.0.0.0:500 (Initiator) <-> x.x.x.x:500 { 447636fc 4d000012 - 00000000 00000000 [-1] / 0x00000000 } IP; Encode packet, version = 1.0, flags = 0x00000000
DEBUG: 0.0.0.0:500 (Initiator) <-> x.x.x.x:500 { 447636fc 4d000012 - 00000000 00000000 [-1] / 0x00000000 } IP; Retransmitting packet, retries = 5
DEBUG: 0.0.0.0:500 (Initiator) <-> x.x.x.x:500 { 447636fc 4d000012 - 00000000 00000000 [-1] / 0x00000000 } IP; Retransmitting packet, retries = 4
DEBUG: 0.0.0.0:500 (Initiator) <-> x.x.x.x:500 { 447636fc 4d000012 - 00000000 00000000 [-1] / 0x00000000 } IP; Retransmitting packet, retries = 3
DEBUG: 0.0.0.0:500 (Initiator) <-> x.x.x.x:500 { 447636fc 4d000012 - 00000000 00000000 [-1] / 0x00000000 } IP; Retransmitting packet, retries = 2
DEBUG: 0.0.0.0:500 (Initiator) <-> x.x.x.x:500 { 447636fc 4d000012 - 00000000 00000000 [-1] / 0x00000000 } IP; Retransmitting packet, retries = 1
DEBUG: 0.0.0.0:500 (Initiator) <-> x.x.x.x:500 { 447636fc 4d000012 - 00000000 00000000 [-1] / 0x00000000 } IP; Removing negotiation
DEBUG: 0.0.0.0:500 (Initiator) <-> x.x.x.x:500 { 447636fc 4d000012 - 00000000 00000000 [-1] / 0x00000000 } IP; Connection timed out or error, calling callback
: Phase-1 [initiator] between ipv4(udp:500,[0..3]=192.168.0.103) and ipv4(udp:500,[0..3]=x.x.x.x) failed; Timeout.
DEBUG: 0.0.0.0:500 (Initiator) <-> x.x.x.x:500 { 447636fc 4d000012 - 00000000 00000000 [-1] / 0x00000000 } IP; Deleting negotiation
Et le log de IPCOP section IPSec:
- Code: Tout sélectionner
14:32:31 pluto[9122] packet from x.x.x.x:500: ignoring Vendor ID payload [SSH Communications S ecurity IPSEC Express version 4.1.0]
14:32:31 pluto[9122] packet from x.x.x.x:500: initial Main Mode message received on x.x.x .x:500 but no connection has been authorized with policy=PSK
14:32:32 pluto[9122] packet from x.x.x.x:500: ignoring Vendor ID payload [SSH Communications S ecurity IPSEC Express version 4.1.0]
14:32:32 pluto[9122] packet from x.x.x.x:500: initial Main Mode message received on x.x.x .x:500 but no connection has been authorized with policy=PSK
14:32:34 pluto[9122] packet from x.x.x.x:500: ignoring Vendor ID payload [SSH Communications S ecurity IPSEC Express version 4.1.0]
14:32:34 pluto[9122] packet from x.x.x.x:500: initial Main Mode message received on x.x.x .x:500 but no connection has been authorized with policy=PSK
14:32:39 pluto[9122] packet from x.x.x.x:500: ignoring Vendor ID payload [SSH Communications S ecurity IPSEC Express version 4.1.0]
14:32:39 pluto[9122] packet from x.x.x.x:500: initial Main Mode message received on x.x.x .x:500 but no connection has been authorized with policy=PSK
14:32:46 pluto[9122] packet from x.x.x.x:500: ignoring Vendor ID payload [SSH Communications S ecurity IPSEC Express version 4.1.0]
14:32:46 pluto[9122] packet from x.x.x.x:500: initial Main Mode message received on x.x.x .x:500 but no connection has been authorized with policy=PSK
14:32:56 pluto[9122] packet from x.x.x.x:500: ignoring Vendor ID payload [SSH Communications S ecurity IPSEC Express version 4.1.0]
14:32:56 pluto[9122] packet from x.x.x.x:500: initial Main Mode message received on x.x.x .x:500 but no connection has been authorized with policy=PSK
La facon d'écrire "x.x.x .x" est voulu, c'est comme ca que c'est écrit dans le log : 123.123.123 .123
Dans la configuration VPN de IPCop j'ai écrit monnom.ath.cx sous "Nom d'hôte ou IP locale du RPV:"
J'ai fouillé le forum au complet, j'ai vu beaucoup de gens qui ont le meme probleme que moi mais personne qui a réussis a le regler ... alors si quelqu'un a une solution faites moi le savoir svp..
Merci