IPsec: problems after upgrade 4.8 to 4.9

Helge Oldach helge.oldach at atosorigin.com
Sun Mar 21 23:21:42 PST 2004


Holger Eitzenberger:
>	(*) ERROR: ipsec_doi.c:440:print_ph1mismatched(): rejected dh_group:
>DB(prop#1:trns#1):Peer(prop#0:trns#0) = 1024-bit MODP group:1536-bit MODP
>group

>        proposal {
>            encryption_algorithm 3des;
>            hash_algorithm md5;
>            authentication_method rsasig;
>            dh_group 2;

Try changing the last line to

>            dh_group 5;

or more verbosely to

>            dh_group modp1536;

Helge


More information about the freebsd-net mailing list