Re: IPSEC help

2007-11-29 Thread Shoichi Sakane
Hi, I don't see detail thing of this thread totally. I just found the notify message type 0x1c, which is CERTIFICATE-UNAVAILABLE. The point is that he got success with pre-shared key. I think that the problem is probably that he uses a self-signed certificate, and the windows machine just

Re: IPSEC help

2007-11-20 Thread john decot
Hi, I have checked with different mode that obey and found error no valid proposal and again i change lifetime too in bsd server. But I can't found where should i have to change those parameter in remote windows ipsec box. Could you please suggest me. Thankyou, Regards, John

Re: IPSEC help

2007-11-20 Thread VANHULLEBUS Yvan
On Tue, Nov 20, 2007 at 02:57:17AM -0800, john decot wrote: Hi, I have checked with different mode that obey and found error no valid proposal and again i change lifetime too in bsd server. But I can't found where should i have to change those parameter in remote

Re: IPSEC help

2007-11-20 Thread VANHULLEBUS Yvan
On Tue, Nov 20, 2007 at 08:46:28AM -0800, john decot wrote: Hi, I have change life time in both side i.e 28800 sec but unlucky again. [ 2007-11-20 20:27:31: ERROR: ignore information because ISAKMP-SA has not been established yet. Do a tcpdump/wireshark and have a look at what's in

Re: IPSEC help

2007-11-19 Thread VANHULLEBUS Yvan
On Sat, Nov 17, 2007 at 01:06:32AM -0800, john decot wrote: Hi , Hi. As per suggestion, The following are the logs generated by racoon : [] 2007-11-17 13:46:22: INFO: received broken Microsoft ID: MS NT5 ISAKMPOAKLEY 2007-11-17 13:46:22: INFO: received Vendor ID: FRAGMENTATION

Re: IPSEC help

2007-11-17 Thread john decot
Hi , As per suggestion, The following are the logs generated by racoon : 2007-11-17 13:46:19: INFO: @(#)ipsec-tools 0.6.6 (http://ipsec-tools.sourceforge.net) 2007-11-17 13:46:19: INFO: @(#)This product linked OpenSSL 0.9.7e-p1 25 Oct 2004 (http://www.openssl.org/) 2007-11-17

Re: IPSEC help

2007-11-15 Thread Bjoern Engels
Hi John, On Thu, Nov 15, 2007 at 03:14:04AM -0800, john decot wrote: I am new to ipsec and trying to connect my bsd server with win 2000. I have succeeded to tunnel using pre-shared key. But regarding certificate , I failed to get success. The following are configuration :