VPN-туннель между Watchguard и FreeBSD 8.1
Добавлено: 2011-02-05 19:52:28
Здравствуйте. Помогите, пожалуйста, решить проблему. Пытаюсь настроить VPN-туннель между Watchguard и FreeBSD 8.1. Соединение, как мне кажется, устанавливается, но передать пакеты не получается. Вот лог racoon (ipsec-tools 0.7.3)
Код: Выделить всё
Feb 5 16:28:30 bershadmoloko racoon: 2011-02-05 16:28:30: INFO: @(#)ipsec-tools 0.7.3 (http://ipsec-tools.sourceforge.net)
Feb 5 16:28:30 bershadmoloko racoon: 2011-02-05 16:28:30: INFO: @(#)This product linked OpenSSL 0.9.8n 24 Mar 2010 (http://www.openssl.org/)
Feb 5 16:28:30 bershadmoloko racoon: 2011-02-05 16:28:30: INFO: Reading configuration from "/usr/local/etc/racoon/racoon.conf"
Feb 5 16:28:30 bershadmoloko racoon: 2011-02-05 16:28:30: INFO: 111.111.111.111[500] used as isakmp port (fd=5)
Feb 5 16:28:30 bershadmoloko racoon: 2011-02-05 16:28:30: INFO: 111.111.111.111[500] used for NAT-T
Feb 5 16:28:37 bershadmoloko racoon: 2011-02-05 16:28:37: INFO: IPsec-SA request for 222.222.222.222 queued due to no phase1 found.
Feb 5 16:28:37 bershadmoloko racoon: 2011-02-05 16:28:37: ERROR: unknown AF: 0
Feb 5 16:28:37 bershadmoloko racoon: 2011-02-05 16:28:37: INFO: initiate new phase 1 negotiation: 111.111.111.111[500]<=>222.222.222.222[500]
Feb 5 16:28:37 bershadmoloko racoon: 2011-02-05 16:28:37: INFO: begin Identity Protection mode.
Feb 5 16:28:37 bershadmoloko racoon: phase1(ident I msg1): 0.000265
Feb 5 16:28:37 bershadmoloko racoon: 2011-02-05 16:28:37: INFO: received Vendor ID: draft-ietf-ipsra-isakmp-xauth-06.txt
Feb 5 16:28:37 bershadmoloko racoon: 2011-02-05 16:28:37: INFO: received Vendor ID: DPD
Feb 5 16:28:37 bershadmoloko racoon: oakley_dh_generate(MODP1024): 0.006358
Feb 5 16:28:37 bershadmoloko racoon: phase1(ident I msg2): 0.006533
Feb 5 16:28:37 bershadmoloko racoon: oakley_dh_compute(MODP1024): 0.006267
Feb 5 16:28:37 bershadmoloko racoon: alg_oakley_hmacdef_one(hmac_sha1 size=24): 0.000018
Feb 5 16:28:37 bershadmoloko racoon: alg_oakley_hmacdef_one(hmac_sha1 size=145): 0.000006
Feb 5 16:28:37 bershadmoloko racoon: alg_oakley_hmacdef_one(hmac_sha1 size=165): 0.000006
Feb 5 16:28:37 bershadmoloko racoon: alg_oakley_hmacdef_one(hmac_sha1 size=165): 0.000006
Feb 5 16:28:37 bershadmoloko racoon: alg_oakley_hmacdef_one(hmac_sha1 size=1): 0.000005
Feb 5 16:28:37 bershadmoloko racoon: alg_oakley_hmacdef_one(hmac_sha1 size=20): 0.000006
Feb 5 16:28:37 bershadmoloko racoon: alg_oakley_hmacdef_one(hmac_sha1 size=328): 0.000007
Feb 5 16:28:37 bershadmoloko racoon: alg_oakley_encdef_encrypt(3des klen=192 size=40): 0.000043
Feb 5 16:28:37 bershadmoloko racoon: phase1(ident I msg3): 0.006518
Feb 5 16:28:37 bershadmoloko racoon: alg_oakley_encdef_decrypt(3des klen=192 size=40): 0.000010
Feb 5 16:28:37 bershadmoloko racoon: alg_oakley_hmacdef_one(hmac_sha1 size=328): 0.000013
Feb 5 16:28:37 bershadmoloko racoon: oakley_validate_auth(pre-shared key): 0.000033
Feb 5 16:28:37 bershadmoloko racoon: phase1(ident R msg3): 0.000083
Feb 5 16:28:37 bershadmoloko racoon: phase1(Identity Protection): 0.082813
Feb 5 16:28:37 bershadmoloko racoon: alg_oakley_hmacdef_one(hmac_sha1 size=32): 0.000008
Feb 5 16:28:37 bershadmoloko racoon: alg_oakley_encdef_encrypt(3des klen=192 size=56): 0.000011
Feb 5 16:28:37 bershadmoloko racoon: 2011-02-05 16:28:37: INFO: ISAKMP-SA established 111.111.111.111[500]-222.222.222.222[500] spi:f015a4d27d3df491:5d5201049c5a5b28
Feb 5 16:28:38 bershadmoloko racoon: 2011-02-05 16:28:38: INFO: initiate new phase 2 negotiation: 111.111.111.111[500]<=>222.222.222.222[500]
Feb 5 16:28:38 bershadmoloko racoon: oakley_dh_generate(MODP1024): 0.006361
Feb 5 16:28:38 bershadmoloko racoon: alg_oakley_hmacdef_one(hmac_sha1 size=240): 0.000007
Feb 5 16:28:38 bershadmoloko racoon: alg_oakley_encdef_encrypt(3des klen=192 size=264): 0.000017
Feb 5 16:28:38 bershadmoloko racoon: phase2(quick I msg1): 0.006460
Feb 5 16:28:38 bershadmoloko racoon: alg_oakley_encdef_decrypt(3des klen=192 size=40): 0.000007
Feb 5 16:28:38 bershadmoloko racoon: alg_oakley_hmacdef_one(hmac_sha1 size=20): 0.000006
Feb 5 16:28:38 bershadmoloko racoon: 2011-02-05 16:28:38: ERROR: fatal INVALID-ID-INFORMATION notify messsage, phase1 should be deleted.
Feb 5 16:28:58 bershadmoloko racoon: 2011-02-05 16:28:58: ERROR: 222.222.222.222 give up to get IPsec-SA due to time up to wait.