<div class="gmail_quote"><br><br>It was true. The point was "virtual_private"<br>Now I have the following configuration, working in both Vista and XP.<br>What is the decision that virtual_private parameters is needed for. Can you give some information?
<div class="Ih2E3d"><br><br><br>***********<br>ipsec.conf:<br><br>version 2.0<br><br>config setup<br></div> interfaces="ipsec0=ppp0"<div class="Ih2E3d"><br> klipsdebug=none<br> plutodebug=none
<br> nat_traversal=yes<br> uniqueids=yes
<br></div><div class="Ih2E3d"> virtual_private=%v4:<a href="http://10.0.0.0/8,%25v4:172.16.0.0/12,%25v4:192.168.0.0/16,%25v4" target="_blank">10.0.0.0/8,%v4:172.16.0.0/12,%v4:192.168.0.0/16,%v4</a>:<br>!172.19.32.0/24
<br><br></div>conn %default<br> auto=add<br>
<br>conn labris.l2tp<br> authby=secret<div class="Ih2E3d"><br> left=EXTERNALIP<br> leftprotoport=17/1701<br></div> right=%any<br> rightprotoport=17/1701<br> auth=esp<br> auto=add
<br> keyingtries=3
<br> pfs=no<br> rekey=no<br> rightid=%any<br> rightsubnet=vhost:%no,%priv<br><br>************<br>ipsec.secrets:<br><br>EXTERNALIP %any : PSK "somepassword"<div><div class="Wj3C7c"><br>
<br><br><div class="gmail_quote">
On Dec 23, 2007 6:49 PM, Jacco de Leeuw <<a href="mailto:jacco2@dds.nl" target="_blank">jacco2@dds.nl</a>> wrote:<br><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">
<div>Oguz Yilmaz wrote:<br><br>> Openswan logs says "no connection is known".<br><br></div>The issue seems to be that the client is behind NAT but you forgot<br>to add a parameter virtual_private to config setup. That's what the
<br>"no connection is known for" error says. Add something like this<br>to your config setup section:<br><br>virtual_private=%v4:<a href="http://10.0.0.0/8,%25v4:172.16.0.0/12,%25v4:192.168.0.0/16,%25v4:%21172.19.32.0/24" target="_blank">
10.0.0.0/8,%v4:172.16.0.0/12,%v4:192.168.0.0/16,%v4:!172.19.32.0/24</a><br><br>> interfaces=""<br><br>Huh? If you leave this parameter out, Openswan will use the interface<br>that has the default gateway, which is probably what you want.
<br><div><br>> conn b-labris.l2tp-zcert<br></div><div>> auth=esp<br>> esp=3des-md5-96<br><br></div>I would suggest to leave these two parameters out. Openswan has good defaults.
<br><br>> leftnexthop=EXTERNALIPDEFGW<br><br>If you leave this parameter out too, it will default to the IP address<br>of the default gateway.<br><br>> rightid=%any<br><br>I would also suggest rightca=%same
<br><div><br>> EXTERNALIP %any : RSA vpn-anahtari.key "labris"<br>> : RSA vpn-anahtari.key "labris"<br><br></div>Change your password :-)<br><br>Jacco<br><font color="#888888">--<br>
Jacco de Leeuw mailto:<a href="mailto:jacco2@dds.nl" target="_blank">jacco2@dds.nl</a><br>Zaandam, The Netherlands <a href="http://www.jacco2.dds.nl/" target="_blank">http://www.jacco2.dds.nl
</a><br></font>
</blockquote></div><br>
</div></div></div><br><br>