vpn trouble

ralf at dzie-ciuch.pl ralf at dzie-ciuch.pl
Tue Jun 22 15:12:07 UTC 2010


Hi,

Thanks for help

I new on it and I never use VPN, only I have to do it.
Please tell me how to check peer's log? I dont know how to check it?

Have I change my racoon.conf exchange to aggressive, main?

I forgot send last time - on the other side is cisco router, maybe this is
important

Regards 
Ralf

On Tue, 22 Jun 2010 16:35:43 +0200, VANHULLEBUS Yvan <vanhu at FreeBSD.org>
wrote:
> On Tue, Jun 22, 2010 at 03:59:50PM +0200, ralf at dzie-ciuch.pl wrote:
>> 
>> Hi,
> 
> Hi.
> 
> 
>> I try to configure VPN over my server and my client
> [....]
> 
> According to your racoon's debug (and confirmed by tcpdump), racoon
> tries to initiate a phase1 negociation, but never gets any answer from
> peer, so you may start by checking peer's logs, and/or compare both
> configurations.
> 
> [....]
>>     exchange_mode main, aggressive; # For Firewall-1 Aggressive mode
> 
> If that comment in your racoon.conf is right, this is probably your
> (first ?) configuration issue: as initiator, racoon will use the first
> listed mode, so it will try a main mode negociation here.
> 
> Note that, if you have complete access to configurations, aggressive
> mode has a lower security level than main mode, so should be avoided
> when main mode can also be used !
> 
> 
> Yvan.
> _______________________________________________
> freebsd-net at freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-net
> To unsubscribe, send any mail to "freebsd-net-unsubscribe at freebsd.org"


More information about the freebsd-net mailing list