<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[PFSense IPSec DFL800 (помогите настроить туннель)]]></title><description><![CDATA[<p dir="auto">Помогите настроить тоннель между PFSense 2.0 и DFL-800,<br />
пытался настроить по примеру тоннелей между dfl-800 и dfl-210 но как то не ладится.</p>
]]></description><link>https://forum.netgate.com/topic/49586/pfsense-ipsec-dfl800-помогите-настроить-туннель</link><generator>RSS for Node</generator><lastBuildDate>Mon, 13 Apr 2026 02:19:25 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/49586.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 19 Oct 2012 16:13:30 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to PFSense IPSec DFL800 (помогите настроить туннель) on Sat, 20 Oct 2012 16:20:46 GMT]]></title><description><![CDATA[<p dir="auto">все разобрался, можно закрывать</p>
]]></description><link>https://forum.netgate.com/post/360832</link><guid isPermaLink="true">https://forum.netgate.com/post/360832</guid><dc:creator><![CDATA[Scrom]]></dc:creator><pubDate>Sat, 20 Oct 2012 16:20:46 GMT</pubDate></item><item><title><![CDATA[Reply to PFSense IPSec DFL800 (помогите настроить туннель) on Fri, 19 Oct 2012 16:50:50 GMT]]></title><description><![CDATA[<p dir="auto">вот что в логе ipsec:<br />
Oct 19 22:46:03 racoon: INFO: received Vendor ID: draft-ietf-ipsec-nat-t-ike-00<br />
Oct 19 22:46:03 racoon: INFO: received Vendor ID: draft-ietf-ipsec-nat-t-ike-02<br />
Oct 19 22:46:03 racoon: INFO: received Vendor ID: draft-ietf-ipsec-nat-t-ike-02<br />
Oct 19 22:46:03 racoon: INFO: received Vendor ID: draft-ietf-ipsec-nat-t-ike-03<br />
Oct 19 22:46:03 racoon: INFO: received Vendor ID: RFC 3947<br />
Oct 19 22:46:03 racoon: [Monolit IPsec]: [91.144.190.44] INFO: Selected NAT-T version: RFC 3947<br />
Oct 19 22:46:03 racoon: INFO: NAT-D payload #-1 doesn't match<br />
Oct 19 22:46:03 racoon: INFO: NAT-D payload #0 doesn't match<br />
Oct 19 22:46:03 racoon: INFO: NAT detected: ME PEER<br />
Oct 19 22:46:03 racoon: [Monolit IPsec]: [91.144.190.44] NOTIFY: couldn't find the proper pskey, try to get one by the peer's address.<br />
Oct 19 22:46:03 racoon: ERROR: HASH mismatched<br />
Oct 19 22:46:12 racoon: [Monolit IPsec]: [91.144.190.44] WARNING: remote address mismatched. db=91.144.190.44[4500], act=91.144.190.44[500]<br />
Oct 19 22:46:12 racoon: INFO: received Vendor ID: draft-ietf-ipsec-nat-t-ike-00<br />
Oct 19 22:46:12 racoon: INFO: received Vendor ID: draft-ietf-ipsec-nat-t-ike-02<br />
Oct 19 22:46:12 racoon: INFO: received Vendor ID: draft-ietf-ipsec-nat-t-ike-02<br />
Oct 19 22:46:12 racoon: INFO: received Vendor ID: draft-ietf-ipsec-nat-t-ike-03<br />
Oct 19 22:46:12 racoon: INFO: received Vendor ID: RFC 3947<br />
Oct 19 22:46:12 racoon: [Monolit IPsec]: [91.144.190.44] INFO: Selected NAT-T version: RFC 3947<br />
Oct 19 22:46:12 racoon: INFO: NAT-D payload #-1 doesn't match<br />
Oct 19 22:46:12 racoon: INFO: NAT-D payload #0 doesn't match<br />
Oct 19 22:46:12 racoon: INFO: NAT detected: ME PEER<br />
Oct 19 22:46:12 racoon: [Monolit IPsec]: [91.144.190.44] NOTIFY: couldn't find the proper pskey, try to get one by the peer's address.<br />
Oct 19 22:46:12 racoon: ERROR: HASH mismatched<br />
Oct 19 22:46:22 racoon: ERROR: phase1 negotiation failed due to time up. be3be6e388a83b74:869a58db862b451f<br />
Oct 19 22:46:22 racoon: [Monolit IPsec]: INFO: KA remove: 95.78.164.202[4500]-&gt;91.144.190.44[4500]<br />
Oct 19 22:46:32 racoon: [Monolit IPsec]: INFO: respond new phase 1 negotiation: 95.78.164.202[500]&lt;=&gt;91.144.190.44[500]<br />
Oct 19 22:46:32 racoon: INFO: begin Aggressive mode.<br />
Oct 19 22:46:32 racoon: INFO: received Vendor ID: draft-ietf-ipsec-nat-t-ike-00<br />
Oct 19 22:46:32 racoon: INFO: received Vendor ID: draft-ietf-ipsec-nat-t-ike-02<br />
Oct 19 22:46:32 racoon: INFO: received Vendor ID: draft-ietf-ipsec-nat-t-ike-02<br />
Oct 19 22:46:32 racoon: INFO: received Vendor ID: draft-ietf-ipsec-nat-t-ike-03<br />
Oct 19 22:46:32 racoon: INFO: received Vendor ID: RFC 3947<br />
Oct 19 22:46:32 racoon: [Monolit IPsec]: [91.144.190.44] INFO: Selected NAT-T version: RFC 3947<br />
Oct 19 22:46:32 racoon: ERROR: no suitable proposal found.<br />
Oct 19 22:46:32 racoon: [Monolit IPsec]: [91.144.190.44] ERROR: failed to get valid proposal.<br />
Oct 19 22:46:32 racoon: [Monolit IPsec]: [91.144.190.44] ERROR: failed to pre-process ph1 packet [Check Phase 1 settings, lifetime, algorithm] (side: 1, status 1).<br />
Oct 19 22:46:32 racoon: [Monolit IPsec]: [91.144.190.44] ERROR: phase1 negotiation failed.</p>
]]></description><link>https://forum.netgate.com/post/360712</link><guid isPermaLink="true">https://forum.netgate.com/post/360712</guid><dc:creator><![CDATA[Scrom]]></dc:creator><pubDate>Fri, 19 Oct 2012 16:50:50 GMT</pubDate></item></channel></rss>