<div>Hello,</div>
<div> </div>
<div>I'm new at linux and openswan and committed to learn as much as I can learn.</div>
<div> </div>
<div>For the future use, I've been testing to make a VPN connection between openswan 2.4.0, kernel 2.6.13 and mobile WinXP SP2 clients. </div>
<div> </div>
<div>I followed Nat Carlson's instructions; I set the CA and created the certificates and transferred a certificate to a WinXP client. Setting openswan box and CA at linux box went smoothly. </div>
<div>But I am lost at the Windows side. I added the certificate to the windows using MMC, downloaded ipsec.exe and ipseccmd.exe. I typed the ipsec and I got this error message;</div>
<div> </div>
<div>
<p><strong>C:\ipsec>ipsec<br>IPSec Version 2.2.0 (c) 2001-2003 Marcus Mueller<br>Getting running Config ...<br>Microsoft's Windows XP identified<br>Setting up IPSec ...</strong></p>
<p><strong> Deactivating old policy...<br> Removing old policy...</strong></p>
<p><strong>Connection roadwarrior:<br> MyTunnel : <a href="http://192.168.1.63"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "192.168.1.63" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 192.168.1.63</a><br> MyNet : <a href="http://192.168.1.63/255.255.255.255"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "192.168.1.63" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 192.168.1.63/255.255.255.255</a><br> PartnerTunnel:
<a href="http://192.168.1.55"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "192.168.1.55" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 192.168.1.55</a><br> PartnerNet : <a href="http://192.168.1.55/255.255.255.255"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "192.168.1.55" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 192.168.1.55/255.255.255.255</a><br> CA (ID) : C=CA,ST=Ontario,L=Toronto,O=Springboard Retail
</strong></p>
<p><strong> PFS : y<br> Auto : start<br> Auth.Mode : MD5<br> Rekeying : 3600S/50000K<br>Error 0xcbbb0012 occurred:</strong></p>
<p><strong>The authentication method specified is invalid or unsupported.</strong></p>
<p><br><strong>POTF_VERSION<br>USAGE:</strong></p>
<p>......</p>
<p> </p>
<p>What does "<strong>The authentication method specified is invalid or unsupported"</strong> mean?</p>
<p>here is my ipsec.conf at the windows machine,</p>
<p><strong>conn roadwarrior<br> left=%any<br> right=<a href="http://192.168.1.55"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "192.168.1.55" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 192.168.1.55</a><br> rightca="C=CA,ST=Ontario,L=Toronto,O=Springboard Retail,CN=can,emailAddress=<a href="mailto:can@springboardnetworks.com">
can@springboardnetworks.com</a>"<br> network=auto<br> auto=start<br> pfs=yes</strong></p>
<p><strong>conn roadwarrior-net<br> left=%any<br> right=<a href="http://192.168.1.55"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "192.168.1.55" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 192.168.1.55</a><br> rightsubnet=<a href="http://192.168.1.1/24"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "192.168.1.1" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 192.168.1.1/24</a><br> rightca="C=CA,ST=Ontario,L=Toronto,O=Springboard Retail, CN=can,emailAddress=
<a href="mailto:can@springboardnetworks.com">can@springboardnetworks.com</a>"<br> network=auto<br> auto=start<br> pfs=yes</strong></p>
<p><strong></strong> </p>
<p><a href="http://192.168.1.55"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "192.168.1.55" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 192.168.1.55</a> is a gateway that has a LAN behind which includes openswan VPN server and its UDP 500 port open. <a href="http://192.168.1.63"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "192.168.1.63" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 192.168.1.63</a> is WinXP client IP address.
</p>
<p>I think my problem is , at least for now, at the windows side. </p>
<p>Can anyone help me to instruct what to do with ipsec.exe, ipsec.conf and ipseccmd.exe at the windows to get the VPN work?</p>
<p>Thank you very much?</p>
<p>Can Akalin</p></div>