• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Mobile IPsec, Shrew Soft VPN client, errors

IPsec
4
8
12.1k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B
    Burnout
    last edited by May 30, 2010, 11:07 AM

    Hello,

    I'm trying to connect my Shrew Soft VPN client (v2.1.5 on Ubuntu Linux) to a pfsense firewall (v1.2.3). The client seems to make a tunnel, but there is no traffic passed. On the pfsense I 've got this errors:

    May 30 08:36:17 racoon: ERROR: 1.2.3.4 give up to get IPsec-SA due to time up to wait.
    May 30 08:35:47 racoon: [Unknown Gateway/Dynamic]: ERROR: such policy does not already exist: "192.168.1.0/24[0] 192.168.1.102/32[0] proto=any dir=out"
    May 30 08:35:47 racoon: [Unknown Gateway/Dynamic]: ERROR: such policy does not already exist: "192.168.1.102/32[0] 192.168.1.0/24[0] proto=any dir=in"
    May 30 08:35:47 racoon: ERROR: pfkey ADD failed: Invalid argument
    May 30 08:35:47 racoon: ERROR: pfkey UPDATE failed: Invalid argument
    May 30 08:35:47 racoon: WARNING: authtype mismatched: my:hmac-sha peer:hmac-md5
    May 30 08:35:47 racoon: WARNING: trns_id mismatched: my:CAST peer:AES
    May 30 08:35:47 racoon: WARNING: trns_id mismatched: my:CAST peer:AES
    May 30 08:35:47 racoon: WARNING: trns_id mismatched: my:BLOWFISH peer:AES
    May 30 08:35:47 racoon: WARNING: trns_id mismatched: my:BLOWFISH peer:AES
    May 30 08:35:47 racoon: WARNING: trns_id mismatched: my:3DES peer:AES
    May 30 08:35:47 racoon: WARNING: trns_id mismatched: my:3DES peer:AES
    May 30 08:35:47 racoon: [Unknown Gateway/Dynamic]: INFO: Update the generated policy : 192.168.1.102/32[0] 192.168.1.0/24[0] proto=any dir=in
    May 30 08:35:47 racoon: INFO: respond new phase 2 negotiation: 192.168.254.2[0]<=>1.2.3.4[0]
    May 30 08:35:47 racoon: [Unknown Gateway/Dynamic]: INFO: ISAKMP-SA established 192.168.254.2[500]-1.2.3.4[500] spi:3d046701f9be9b8g:8eea6b8f6c1b95f9
    May 30 08:35:47 racoon: INFO: received Vendor ID: CISCO-UNITY
    May 30 08:35:47 racoon: INFO: received Vendor ID: DPD
    May 30 08:35:47 racoon: INFO: received broken Microsoft ID: FRAGMENTATION
    May 30 08:35:47 racoon: INFO: received Vendor ID: RFC 3947
    May 30 08:35:47 racoon: INFO: received Vendor ID: draft-ietf-ipsec-nat-t-ike-03
    May 30 08:35:47 racoon: INFO: received Vendor ID: draft-ietf-ipsec-nat-t-ike-02
    May 30 08:35:47 racoon: INFO: received Vendor ID: draft-ietf-ipsec-nat-t-ike-01
    May 30 08:35:47 racoon: INFO: received Vendor ID: draft-ietf-ipsec-nat-t-ike-00
    May 30 08:35:47 racoon: INFO: begin Aggressive mode.

    I can't find any solution on the internet for this error messages. Does somebody have a fix for this please?

    Kind regards,

    Burnout

    1 Reply Last reply Reply Quote 0
    • B
      Burnout
      last edited by May 30, 2010, 11:54 AM

      Ok, it seems that there is a VPN connection. (even with the errors in the log)

      But, I only can ping the pfsense box and my own assigned VPN ip. No other IP in the subnet behind the pfsense box is reachable. That sounds like a routing problem to me. Weird, because the routes seem ok.

      Has anybody an idea?

      (this problem is happening both on Linux and Windows)

      1 Reply Last reply Reply Quote 0
      • J
        jimp Rebel Alliance Developer Netgate
        last edited by Jun 1, 2010, 12:45 PM

        Is this pfSense box the gateway for things inside of the network? Did you add firewall rules to allow the traffic you want under Firewall > Rules on the IPsec tab?

        You can probably confirm via packet capture where the traffic is or is not going.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • B
          Burnout
          last edited by Jun 1, 2010, 6:24 PM

          @jimp:

          Is this pfSense box the gateway for things inside of the network? Did you add firewall rules to allow the traffic you want under Firewall > Rules on the IPsec tab?

          Yeah, the pfsense is the gateway. Rules are set. :)

          I'll check out the traffic capture feature.

          1 Reply Last reply Reply Quote 0
          • N
            Neferites
            last edited by Jun 2, 2010, 1:40 PM

            Hi burnout, i can't help you, but i think you can help me.
            I actually try to mount a tunnel between a pfsense and a mobile with shrew.
            My problem : tunnel is not mount.
            i don't understand why, cause have follow this tuto :
            http://doc.pfsense.org/index.php/IPsec_Road_Warrior/Mobile_Client_How-To
            What's your config ?
            Thanks a lot.

            1 Reply Last reply Reply Quote 0
            • B
              Burnout
              last edited by Jun 3, 2010, 2:14 PM

              @Neferites:

              Hi burnout, i can't help you, but i think you can help me.
              I actually try to mount a tunnel between a pfsense and a mobile with shrew.
              My problem : tunnel is not mount.
              i don't understand why, cause have follow this tuto :
              http://doc.pfsense.org/index.php/IPsec_Road_Warrior/Mobile_Client_How-To
              What's your config ?
              Thanks a lot.

              Hello Neferites,

              I figured out the configuration isn't too hard. You can change multiple parameters (to "auto" for example) and it still will work. Can this be a firewall problem?

              My problem is that nothing 's routed to my VPN client from the network I'm connecting to. Altough the route tables are (or should be) correct.

              Kind regards,

              Burn

              1 Reply Last reply Reply Quote 0
              • N
                Neferites
                last edited by Jun 4, 2010, 7:47 AM Jun 4, 2010, 7:38 AM

                Hi,

                I think my routes are correct cause ssh, and ping are ok.

                But can't establish a tunnel between pfsense and my laptop.

                Work on virtualbox, with this network :

                192.168.1.2 <–----->192.168.1.1 eth1| 172.16.0.1 eth2 <---------->172.1.0.2 eth1 | 10.0.0.2 eth0 <-------> 10.0.0.1 WAN | 192.168.0.1 LAN <-------> 192.168.0.2
                laptop                                  gateway                                                                gateway                                                      pfsense                                      computer on lan

                i can ping laptop with computer on lan, connect with ssh on pfsense who use port forwarding to redirect on computer.

                I try ipsec connection in agressive mode, with preshared key, using 3des and sha1.

                But can't connect with ipsec...

                An idea ?

                Nef

                1 Reply Last reply Reply Quote 0
                • M
                  MaxHeadroom
                  last edited by Jun 22, 2010, 2:33 PM

                  @Neferites
                  because ipsec is not Nat-t enabled on pfsense 1.2.3  try openvpn

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.