I am install penes wan in one ip statick <br><br>server vpn <===>Zyxel 643 <===>internet<===>client winxp(roadwarrior)<br> <br>the zyxel 643 forward por 500, 1701 and 4500<br>
<br>my <a href="http://ipsec.com">ipsec.com</a> is:<br>version 2.0<br><br>config setup<br> interfaces=%defaultroute<br> #interfaces="ipsec0=eth0"<br> nat_traversal=no<br> #uniqueids=yes
<br> klipsdebug=all<br> plutodebug=none<br> #plutoload=%search<br> #plutostart=%search<br> #plutodebug="control parsing"<br> #virtual_private=%v4:<a href="http://10.0.0.0/8,%v4:172.16.0.0/12,%v4:192.168.0.0/16,%v4:192.168.3.0/24"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "10.0.0.0" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious:
10.0.0.0/8,%v4:172.16.0.0/12,%v4:192.168.0.0/16,%v4:192.168.3.0/24</a><br><br>conn %default<br> #keyingtries=0<br> keyingtries=3<br> #compress=yes<br> disablearrivalcheck=no<br> ikelifetime=20m
<br> keylife=60m<br> rekey=no<br> #authby=rsasig<br> authby=secret|rsasig<br> leftrsasigkey=%cert<br> rightrsasigkey=%cert<br><br>conn roadwarrior-l2tp<br> type=transport<br>
#type=tunnel<br> left=<a href="http://192.168.1.2"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "192.168.1.2" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 192.168.1.2</a><br> #leftnexthop=<a href="http://201.230.129.43"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "201.230.129.43" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 201.230.129.43</a><br> leftcert=server.pem<br> #leftprotoport=17/1701
<br> leftprotoport=17/%any<br> right=%any<br> #rightnexthop=%defaultroute<br> #rightprotoport=17/1701<br> rightprotoport=17/%any<br> #rightsubnet=<a href="http://0.0.0.0/0"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "0.0.0.0" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 0.0.0.0/0
</a><br> pfs=no<br> auto=add<br><br>i am probe of diferent shape but no work<br>with it is confiugration the error the ipsec:<br><br><p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span>
<span style="font-size: 10pt;" lang="EN-US">10:58:47</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
packet from xxx.xxx.xxx.xxx:500: ignoring Vendor ID payload [MS NT5
ISAKMPOAKLEY 00000004]</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:47</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
packet from xxx.xxx.xxx.xxx:500: ignoring Vendor ID payload [FRAGMENTATION]</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:47</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
packet from xxx.xxx.xxx.xxx:500: received Vendor ID payload
[draft-ietf-ipsec-nat-t-ike-02_n] meth=106, but port floating is off</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:47</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
packet from xxx.xxx.xxx.xxx:500: ignoring Vendor ID payload
[Vid-Initial-Contact]</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:47</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[1] xxx.xxx.xxx.xxx #1: responding to Main Mode
from unknown peer xxx.xxx.xxx.xxx</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:47</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[1] xxx.xxx.xxx.xxx #1: transition from state
STATE_MAIN_R0 to state STATE_MAIN_R1</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:47</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[1] xxx.xxx.xxx.xxx #1: STATE_MAIN_R1: sent MR1,
expecting MI2</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:48</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
packet from xxx.xxx.xxx.xxx:500: ignoring Vendor ID payload [MS NT5
ISAKMPOAKLEY 00000004]</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:48</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
packet from xxx.xxx.xxx.xxx:500: ignoring Vendor ID payload [FRAGMENTATION]</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:48</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
packet from xxx.xxx.xxx.xxx:500: received Vendor ID payload
[draft-ietf-ipsec-nat-t-ike-02_n] meth=106, but port floating is off</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:48</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
packet from xxx.xxx.xxx.xxx:500: ignoring Vendor ID payload
[Vid-Initial-Contact]</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:48</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[1] xxx.xxx.xxx.xxx #2: responding to Main Mode
from unknown peer xxx.xxx.xxx.xxx</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:48</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[1] xxx.xxx.xxx.xxx #2: transition from state
STATE_MAIN_R0 to state STATE_MAIN_R1</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:48</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[1] xxx.xxx.xxx.xxx #2: STATE_MAIN_R1: sent MR1,
expecting MI2</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:49</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[1] xxx.xxx.xxx.xxx #1: transition from state
STATE_MAIN_R1 to state STATE_MAIN_R2</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:49</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[1] xxx.xxx.xxx.xxx #1: STATE_MAIN_R2: sent MR2,
expecting MI3</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:49</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[1] xxx.xxx.xxx.xxx #1: discarding duplicate
packet; already STATE_MAIN_R2</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:50</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[1] xxx.xxx.xxx.xxx #1: Main mode peer ID is
ID_IPV4_ADDR: '<a href="http://192.168.1.2"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "192.168.1.2" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 192.168.1.2</a>'</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:50</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[1] xxx.xxx.xxx.xxx #1: switched from
"roadwarrior-l2tp" to "roadwarrior-l2tp"</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:50</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[2] xxx.xxx.xxx.xxx #1: transition from state
STATE_MAIN_R2 to state STATE_MAIN_R3</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:50</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[2] xxx.xxx.xxx.xxx #1: STATE_MAIN_R3: sent MR3,
ISAKMP SA established {auth=OAKLEY_PRESHARED_KEY cipher=oakley_3des_cbc_192
prf=oakley_sha group=modp2048}</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:51</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[2] xxx.xxx.xxx.xxx #1: cannot respond to IPsec SA
request because no connection is known for
<a href="http://201.230.129.43/32===192.168.1.2[C=PE"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "201.230.129.43" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 201.230.129.43/32===192.168.1.2[C=PE</a>, ST=xxxx, L=xxxxx, O=xxxxxx, OU=Server
Principal VPN, CN=xxxxxx.xxx, E=<a href="mailto:postmaster@costadelsolperu.com">postmaster@costadelsolperu.com</a>]:17/%any...xxx.xxx.xxx.xxx[<a href="http://192.168.1.2"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "192.168.1.2" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious: 192.168.1.2</a>]:17/%any===<a href="http://192.168.1.2/32"></b></font><font color="red"><b>MailScanner has detected a possible fraud attempt from "192.168.1.2" claiming to be</b></font> <font color="red"><b>MailScanner warning: numerical links are often malicious:
192.168.1.2/32</a></span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:51</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[2] xxx.xxx.xxx.xxx #1: sending encrypted
notification INVALID_ID_INFORMATION to xxx.xxx.xxx.xxx:500</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:51</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[2] xxx.xxx.xxx.xxx #1: Quick Mode I1 message is
unacceptable because it uses a previously used Message ID 0x9c2cc2e5 (perhaps
this is a duplicated packet)</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:51</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[2] xxx.xxx.xxx.xxx #1: sending encrypted
notification INVALID_MESSAGE_ID to xxx.xxx.xxx.xxx:500</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:53</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[2] xxx.xxx.xxx.xxx #1: Quick Mode I1 message is
unacceptable because it uses a previously used Message ID 0x9c2cc2e5 (perhaps
this is a duplicated packet)</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:53</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[2] xxx.xxx.xxx.xxx #1: sending encrypted
notification INVALID_MESSAGE_ID to xxx.xxx.xxx.xxx:500</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:57</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[2] xxx.xxx.xxx.xxx #1: Quick Mode I1 message is
unacceptable because it uses a previously used Message ID 0x9c2cc2e5 (perhaps
this is a duplicated packet)</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:58:57</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[2] xxx.xxx.xxx.xxx #1: sending encrypted
notification INVALID_MESSAGE_ID to xxx.xxx.xxx.xxx:500</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:59:05</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[2] xxx.xxx.xxx.xxx #1: Quick Mode I1 message is
unacceptable because it uses a previously used Message ID 0x9c2cc2e5 (perhaps
this is a duplicated packet)</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:59:05</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[2] xxx.xxx.xxx.xxx #1: sending encrypted
notification INVALID_MESSAGE_ID to xxx.xxx.xxx.xxx:500</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:59:21</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[2] xxx.xxx.xxx.xxx #1: Quick Mode I1 message is
unacceptable because it uses a previously used Message ID 0x9c2cc2e5 (perhaps
this is a duplicated packet)</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:59:21</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[2] xxx.xxx.xxx.xxx #1: sending encrypted
notification INVALID_MESSAGE_ID to xxx.xxx.xxx.xxx:500</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:59:53</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[2] xxx.xxx.xxx.xxx #1: received Delete SA payload:
deleting </span><span style="font-size: 10pt;" lang="EN-US">ISAKMP</span><span style="font-size: 10pt;" lang="EN-US"> </span><span style="font-size: 10pt;" lang="EN-US">State</span><span style="font-size: 10pt;" lang="EN-US">
#1</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:59:53</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[2] xxx.xxx.xxx.xxx: deleting connection
"roadwarrior-l2tp" instance with peer xxx.xxx.xxx.xxx
{isakmp=#0/ipsec=#0}</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:59:53</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
packet from xxx.xxx.xxx.xxx:500: received and ignored informational message</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:59:58</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[1] xxx.xxx.xxx.xxx #2: max number of
retransmissions (2) reached STATE_MAIN_R1</span></p>
<p class="MsoNormal"><span style="font-size: 10pt;" lang="EN-US">Jul 21 </span><span style="font-size: 10pt;" lang="EN-US">10:59:58</span><span style="font-size: 10pt;" lang="EN-US"> fw pluto[2246]:
"roadwarrior-l2tp"[1] xxx.xxx.xxx.xxx: deleting connection
"roadwarrior-l2tp" instance with peer xxx.xxx.xxx.xxx
{isakmp=#0/ipsec=#0}</span></p>
any help???<br>