par Doc » 02 Juil 2003 12:11
bon, ben... OSCOUR!
<BR>
<BR>J'ai mis en place un MNF : ip publique + DMZ (192.168.10.0/24) + Lan (192.168.1.0/24 en NAT).
<BR>Tout roule jusque là.
<BR>
<BR>Par contre le VPN: <IMG SRC="images/smiles/icon_bawling.gif">
<BR>
<BR>J'ai suivi d'abord la doc MNF, puis j'ai recommencé avec les indications d'Eric Faure (merci à lui!). Mais rien à faire...
<BR>
<BR>J'essaye de me connecter depuis un poste Windows XP (192.168.0.21) qui est derrière un firewall qui NAT ma connexion (ip publique / 192.168.0.254).
<BR>La génération des certificats s'est bien passée, et ils ont l'air bien installé (?)
<BR>
<BR>Mes fichiers de conf sont:
<BR>
<BR>(MNF)
<BR>## /etc/ipsec.conf - FreeS/WAN IPsec configuration file
<BR>
<BR>config setup
<BR> interfaces=%defaultroute
<BR> klipsdebug=none
<BR> plutodebug=none
<BR> plutoload=%search
<BR> plutostart=%search
<BR> uniqueids=yes
<BR>
<BR>conn %default
<BR> keyingtries=1
<BR> compress=yes
<BR> disablearrivalcheck=no
<BR> authby=rsasig
<BR> leftrsasigkey=%cert
<BR> rightrsasigkey=%cert
<BR>
<BR>conn francois-net
<BR> leftsubnet=192.168.1.0/24
<BR> also=francois
<BR>
<BR>conn francois
<BR> left=%defaultroute
<BR> right=%any
<BR> rightsubnet=0/0
<BR> leftcert=firewall.pem
<BR> auto=add
<BR> pfs=yes
<BR>
<BR>
<BR># LAST LINE -- EOF
<BR>
<BR>(Windows XP)
<BR>conn resosec
<BR> left=%any
<BR> right=xxx.xxx.xxx.xxx (ip publique MNF)
<BR> rightca="E = <!-- BBcode auto-mailto start --><a href="mailto:informatique@xxx">informatique@xxx</a><!-- BBCode auto-mailto end -->
<BR>, CN = firewall,
<BR>OU = Service Informatique,
<BR>O = Assoc,
<BR>L = PARIS,
<BR>S = Ile de France,
<BR>C = FR"
<BR> network=lan
<BR> auto=start
<BR> pfs=yes
<BR>
<BR>conn resosec-net
<BR> left=%any
<BR> leftsubnet=*
<BR> right=xxx.xxx.xxx.xxx (ip publique MNF)
<BR> rightsubnet=192.168.1.0/24
<BR> rightca="E = <!-- BBcode auto-mailto start --><a href="mailto:informatique@xxx">informatique@xxx</a><!-- BBCode auto-mailto end -->
<BR>, CN = firewall,
<BR>OU = Service Informatique,
<BR>O = Assoc,
<BR>L = PARIS,
<BR>S = Ile de France,
<BR>C = FR"
<BR> network=lan
<BR> auto=start
<BR> pfs=yes
<BR>
<BR>
<BR>Lorsque je tente d'établir la connexion, le log MNF indique:
<BR>"...encrypted Informational Exchange message is invalid because it is for incomplete ISAKMP SA..."
<BR>
<BR>Le log XP indique:
<BR> 7-02: 09:56:00:600:2250 ISAKMP Header: (V1.0), len = 184
<BR> 7-02: 09:56:00:600:2250 I-COOKIE 1c91d7624fe668f9
<BR> 7-02: 09:56:00:600:2250 R-COOKIE 7ade5cfbe9c86791
<BR> 7-02: 09:56:00:600:2250 exchange: Oakley Main Mode
<BR> 7-02: 09:56:00:600:2250 flags: 0
<BR> 7-02: 09:56:00:600:2250 next payload: KE
<BR> 7-02: 09:56:00:600:2250 message ID: 00000000
<BR> 7-02: 09:56:00:600:2250 Ports S:f401 D:f401
<BR> 7-02: 09:56:00:757:2250
<BR> 7-02: 09:56:00:757:2250 Receive: (get) SA = 0x000f4808 from xxx.xxx.xxx.xxx (ip MNF)
<BR> 7-02: 09:56:00:757:2250 ISAKMP Header: (V1.0), len = 188
<BR> 7-02: 09:56:00:757:2250 I-COOKIE 1c91d7624fe668f9
<BR> 7-02: 09:56:00:757:2250 R-COOKIE 7ade5cfbe9c86791
<BR> 7-02: 09:56:00:757:2250 exchange: Oakley Main Mode
<BR> 7-02: 09:56:00:757:2250 flags: 0
<BR> 7-02: 09:56:00:757:2250 next payload: KE
<BR> 7-02: 09:56:00:757:2250 message ID: 00000000
<BR> 7-02: 09:56:00:757:2250 processing payload KE
<BR> 7-02: 09:56:00:772:2250 processing payload NONCE
<BR> 7-02: 09:56:00:772:2250 processing payload CRP
<BR> 7-02: 09:56:00:772:2250 ClearFragList
<BR> 7-02: 09:56:00:772:2250 constructing ISAKMP Header
<BR> 7-02: 09:56:00:772:2250 constructing ID
<BR> 7-02: 09:56:00:772:2250 Received no valid CRPs. Using all configured
<BR> 7-02: 09:56:00:772:2250 Looking for IPSec only cert
<BR> 7-02: 09:56:00:772:2250 failed to get chain 80092004
<BR> 7-02: 09:56:00:772:2250 Looking for any cert
<BR> 7-02: 09:56:00:772:2250 failed to get chain 80092004
<BR> 7-02: 09:56:00:772:2250 ProcessFailure: sa:000F4808 centry:00000000 status:35ee
<BR> 7-02: 09:56:00:772:2250 isadb_set_status sa:000F4808 centry:00000000 status 35ee
<BR> 7-02: 09:56:00:788:2250 Mode d'échange de clés (Mode principal)
<BR> 7-02: 09:56:00:788:2250 Adresse IP source...
<BR> 7-02: 09:56:00:788:2250 Identité basé sur le certificat. Adresse IP homologue : xxx.xxx.xxx.xxx (ip MNF)
<BR> 7-02: 09:56:00:788:2250 Moi
<BR> 7-02: 09:56:00:788:2250 IKE n'a pas trouvé de certificat ordinateur valide
<BR>
<BR> <IMG SRC="images/smiles/icon_confused.gif"> <IMG SRC="images/smiles/icon_razz.gif"> <IMG SRC="images/smiles/icon_cussing.gif">
<BR>
<BR>Bon, je vois bien qu'il y a un pb de certificat... et pourtant la génération des certificats et l'import sous XP s'est bien passé...
<BR>Ca ne serait pas un pb de ipsec.conf (NAT ??)
<BR>
<BR>OSCOUR!
<BR>Quelqu'un a une idée?
<BR>
<BR>Merci de votre aide...
Petit mais gentil...