Re: [Users] Connecting to freeswan with PGPNet client using Certificates

From: Andreas Steffen (andreas.steffen_at_strongsec.net)
Date: Thu Jan 09 2003 - 22:18:09 CET


In order to help you I need your ipsec.conf and the output of

   ipsec auto --status

after the connections have been loaded.

Regards

Andreas

Chris Ehlers wrote:
> I have set up PGPNet (v 7.0.3) as instructed in
> http://www.evolvedatacom.nl/freeswan.html and restarted my freeswan (see
> below) but the server does not seem to accept the isakmp... what could the
> problem be?
>
> Jan 8 18:16:33 vpn1 pluto[22652]: shutting down
> Jan 8 18:16:33 vpn1 pluto[22652]: forgetting secrets
> Jan 8 18:16:33 vpn1 pluto[22652]: "roadwarrior-test": deleting connection
> Jan 8 18:16:33 vpn1 pluto[22652]: shutting down interface ipsec0/eth0
> ip.address.of.vpn1
> Jan 8 18:16:34 vpn1 ipsec__plutorun: Starting Pluto subsystem...
> Jan 8 18:16:34 vpn1 pluto[22994]: Starting Pluto (FreeS/WAN Version 1.99)
> Jan 8 18:16:34 vpn1 pluto[22994]: including X.509 patch (Version 0.9.15)
> Jan 8 18:16:34 vpn1 pluto[22994]: Changing to directory
> '/etc/ipsec.d/cacerts'
> Jan 8 18:16:34 vpn1 pluto[22994]: loaded cacert file 'cacert.pem' (1273
> bytes)
> Jan 8 18:16:34 vpn1 pluto[22994]: Changing to directory '/etc/ipsec.d/crls'
> Jan 8 18:16:34 vpn1 pluto[22994]: loaded crl file 'crl.pem' (516 bytes)
> Jan 8 18:16:34 vpn1 pluto[22994]: loaded my default X.509 cert file
> '/etc/x509cert.der' (949 bytes)
> Jan 8 18:16:35 vpn1 pluto[22994]: loaded host cert file
> '/etc/ipsec.d/client-cert.pem' (3632 bytes)
> Jan 8 18:16:35 vpn1 pluto[22994]: loaded host cert file
> '/etc/ipsec.d/freeswan-cert.pem' (3652 bytes)
> Jan 8 18:16:35 vpn1 pluto[22994]: added connection description
> "roadwarrior-test"
> Jan 8 18:16:35 vpn1 pluto[22994]: listening for IKE messages
> Jan 8 18:16:35 vpn1 pluto[22994]: adding interface ipsec0/eth0
> ip.address.of.vpn1
> Jan 8 18:16:35 vpn1 pluto[22994]: loading secrets from "/etc/ipsec.secrets"
> Jan 8 18:16:35 vpn1 pluto[22994]: loaded private key file
> '/etc/ipsec.d/private/freeswan-priv.pem' (1671 bytes)
> Jan 8 18:17:13 vpn1 pluto[22994]: packet from client.ip.add:500: ignoring
> Vendor ID payload
> Jan 8 18:17:13 vpn1 pluto[22994]: packet from client.ip.add:500: initial
> Main Mode message received on ip.address.of.vpn1:500 but
> no connection has been authorized
> Jan 8 18:17:17 vpn1 pluto[22994]: packet from client.ip.add:500: ignoring
> Vendor ID payload
> Jan 8 18:17:17 vpn1 pluto[22994]: packet from client.ip.add:500: initial
> Main Mode message received on ip.address.of.vpn1:500 but
> no connection has been authorized
> Jan 8 18:17:23 vpn1 pluto[22994]: packet from client.ip.add:500: ignoring
> Vendor ID payload
> Jan 8 18:17:23 vpn1 pluto[22994]: packet from client.ip.add:500: initial
> Main Mode message received on ip.address.of.vpn1:500 but
> no connection has been authorized
> Jan 8 18:17:32 vpn1 pluto[22994]: packet from client.ip.add:500: ignoring
> Vendor ID payload
> Jan 8 18:17:32 vpn1 pluto[22994]: packet from client.ip.add:500: initial
> Main Mode message received on ip.address.of.vpn1:500 but
> no connection has been authorized
>
> Kind Regards
> Christiaan Ehlers
>
> N B Khan and N G Edwards were appointed Joint Administrators of Mosaic UK
> Limited on 2 December 2002. The Administrators act as agents of the company
> and contract without personal liability.
> _______________________________________________
> Users mailing list
> Users_at_lists.freeswan.org
> http://lists.freeswan.org/mailman/listinfo/users

-- 
=======================================================================
Andreas Steffen                   e-mail: andreas.steffen_at_strongsec.com
strongSec GmbH                    home:   http://www.strongsec.com
Alter Zürichweg 20                phone:  +41 1 730 80 64
CH-8952 Schlieren (Switzerland)   fax:    +41 1 730 80 65
==========================================[strong internet security]===
_______________________________________________
Users mailing list
Users_at_lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users


This archive was generated by hypermail 2.1.5 : Sat Jan 11 2003 - 05:21:13 CET