<div>This is all that i could say, windows mobile say only that is impossibile to connect to network:</div>
<div> </div>
<div>10:24:13.581013 IP 172.31.1.194.isakmp > 172.31.1.190.isakmp: isakmp: phase 1 I ident<br>10:24:13.582465 IP 172.31.1.190.isakmp > 172.31.1.194.isakmp: isakmp: phase 1 R ident<br>10:24:18.582216 arp who-has <a href="http://172.31.1.194">172.31.1.194</a> tell <a href="http://172.31.1.190">172.31.1.190</a><br>
10:24:18.904019 arp reply <a href="http://172.31.1.194">172.31.1.194</a> is-at 00:09:2d:da:cb:cc (oui Unknown)<br>10:24:22.587450 IP 172.31.1.194.isakmp > 172.31.1.190.isakmp: isakmp: phase 1 I ident<br>10:24:22.671162 IP 172.31.1.190.isakmp > 172.31.1.194.isakmp: isakmp: phase 1 R ident<br>
10:24:26.014066 IP 172.31.1.194.isakmp > 172.31.1.190.isakmp: isakmp: phase 2/others I inf[E]<br>10:24:26.015237 IP 172.31.1.190.isakmp > 172.31.1.194.isakmp: isakmp: phase 2/others R inf<br>10:24:26.387174 IP 172.31.1.194.isakmp > 172.31.1.190.isakmp: isakmp: phase 2/others I inf[E]<br>
10:24:26.686534 IP <a href="http://172.31.1.194">172.31.1.194</a> > <a href="http://172.31.1.190">172.31.1.190</a>: ICMP <a href="http://172.31.1.194">172.31.1.194</a> udp port isakmp unreachable, length 76<br>10:24:32.686003 IP 172.31.1.190.isakmp > 172.31.1.194.isakmp: isakmp: phase 1 R ident<br>
10:24:32.830541 IP <a href="http://172.31.1.194">172.31.1.194</a> > <a href="http://172.31.1.190">172.31.1.190</a>: ICMP <a href="http://172.31.1.194">172.31.1.194</a> udp port isakmp unreachable, length 156<br>10:24:52.829565 IP 172.31.1.190.isakmp > 172.31.1.194.isakmp: isakmp: phase 1 R ident<br>
10:24:52.899268 IP <a href="http://172.31.1.194">172.31.1.194</a> > <a href="http://172.31.1.190">172.31.1.190</a>: ICMP <a href="http://172.31.1.194">172.31.1.194</a> udp port isakmp unreachable, length 156</div>
<div> </div>
<div>ipsec.conf</div>
<div>version 2.0</div>
<p>config setup<br> interfaces=%defaultroute<br> virtual_private=%v4:<a href="http://10.0.0.0/8,%v4:172.16.0.0/12,%v4:192.168.0.0/16,%v4:!172.31.1.0/24">10.0.0.0/8,%v4:172.16.0.0/12,%v4:192.168.0.0/16,%v4:!172.31.1.0/24</a><br>
klipsdebug=none<br> plutodebug=none</p>
<p>conn %default<br> keyingtries=3<br> compress=yes<br> disablearrivalcheck=no<br> authby=rsasig<br> leftrsasigkey=%cert<br> rightrsasigkey=%cert<br> keyexchange=ike<br> ikelifetime=240m<br>
keylife=60m</p>
<p>conn roadwarrior-l2tp<br> leftprotoport=17/1701<br> rightprotoport=17/1701<br> also=roadwarrior</p>
<p>conn roadwarrior<br> left=<a href="http://172.31.1.190">172.31.1.190</a><br> leftcert=pubblica.pem<br> right=%any<br> auto=add<br> pfs=no</p>
<p>conn roadwarrior-all<br> leftsubnet=<a href="http://0.0.0.0/0">0.0.0.0/0</a><br> also=roadwarrior</p>
<p>conn roadwarrior-l2tp-updatedwin<br> leftprotoport=17/1701<br> rightprotoport=17/1701<br> also=roadwarrior</p>
<p>conn block<br> auto=ignore</p>
<p>conn private<br> auto=ignore</p>
<p>conn private-or-clear<br> auto=ignore</p>
<p>conn clear-or-private<br> auto=ignore</p>
<p>conn clear<br> auto=ignore</p>
<p>conn packetdefault<br> auto=ignore</p>
<p><br><br> </p>
<div class="gmail_quote">On Feb 18, 2008 9:35 PM, Paul Wouters <<a href="mailto:paul@xelerance.com">paul@xelerance.com</a>> wrote:<br>
<blockquote class="gmail_quote" style="PADDING-LEFT: 1ex; MARGIN: 0px 0px 0px 0.8ex; BORDER-LEFT: #ccc 1px solid">On Mon, 18 Feb 2008, Denis Beltramo wrote:<br><br>The best you can hope for is a misconfiguration. Do you have any logs on<br>
the mobile device?<br><br>Paul<br><br>> Date: Mon, 18 Feb 2008 17:44:59 +0100<br>> From: Denis Beltramo <<a href="mailto:denis@denisio.net">denis@denisio.net</a>><br>> To: <<a href="mailto:users@openswan.org">users@openswan.org</a>><br>
> Subject: [Openswan Users] Problem with OpenSwan and windows mobile 6.0<br>
<div>
<div></div>
<div class="Wj3C7c">><br>> Hello,<br>><br>> I havve this problem, i have a server with openswan and l2tpd, i have<br>> configured and tested: between linux and linux work, between linux openswan<br>> and windows xp home sp2 work, but between linux openswan server and windows<br>
> mobile 6 don't work.<br>> this is ipsec barf output:<br>> Feb 18 19:01:08 testradiu2 pluto[31465]: "roadwarrior"[2] <a href="http://172.31.1.194/" target="_blank">172.31.1.194</a> #2:<br>> responding to Main Mode from unknown peer <a href="http://172.31.1.194/" target="_blank">172.31.1.194</a><br>
> Feb 18 19:01:08 testradiu2 pluto[31465]: "roadwarrior"[2] <a href="http://172.31.1.194/" target="_blank">172.31.1.194</a> #2:<br>> transition from state STATE_MAIN_R0 to state STATE_MAIN_R1<br>> Feb 18 19:01:08 testradiu2 pluto[31465]: "roadwarrior"[2] <a href="http://172.31.1.194/" target="_blank">172.31.1.194</a> #2:<br>
> STATE_MAIN_R1: sent MR1, expecting MI2<br>> Feb 18 19:01:17 testradiu2 pluto[31465]: "roadwarrior"[2] <a href="http://172.31.1.194/" target="_blank">172.31.1.194</a> #2:<br>> NAT-Traversal: Result using draft-ietf-ipsec-nat-t-ike-02/03: no NAT<br>
> detected<br>> Feb 18 19:01:17 testradiu2 pluto[31465]: "roadwarrior"[2] <a href="http://172.31.1.194/" target="_blank">172.31.1.194</a> #2:<br>> transition from state STATE_MAIN_R1 to state STATE_MAIN_R2<br>
> Feb 18 19:01:17 testradiu2 pluto[31465]: "roadwarrior"[2] <a href="http://172.31.1.194/" target="_blank">172.31.1.194</a> #2:<br>> STATE_MAIN_R2: sent MR2, expecting MI3<br>> Feb 18 19:01:20 testradiu2 pluto[31465]: "roadwarrior"[2] <a href="http://172.31.1.194/" target="_blank">172.31.1.194</a> #2:<br>
> next payload type of ISAKMP Hash Payload has an unknown value: 76<br>> Feb 18 19:01:20 testradiu2 pluto[31465]: "roadwarrior"[2] <a href="http://172.31.1.194/" target="_blank">172.31.1.194</a> #2:<br>> malformed payload in packet<br>
> Feb 18 19:01:20 testradiu2 pluto[31465]: "roadwarrior"[2] <a href="http://172.31.1.194/" target="_blank">172.31.1.194</a> #2:<br>> sending notification PAYLOAD_MALFORMED to <a href="http://172.31.1.194:500/" target="_blank">172.31.1.194:500</a><br>
> Feb 18 19:01:20 testradiu2 pluto[31465]: "roadwarrior"[2] <a href="http://172.31.1.194/" target="_blank">172.31.1.194</a> #2:<br>> next payload type of ISAKMP Hash Payload has an unknown value: 125<br>> Feb 18 19:01:20 testradiu2 pluto[31465]: "roadwarrior"[2] <a href="http://172.31.1.194/" target="_blank">172.31.1.194</a> #2:<br>
> malformed payload in packet<br>> Feb 18 19:01:27 testradiu2 pluto[31465]: ERROR: asynchronous network error<br>> report on eth0 (sport=500) for message to <a href="http://172.31.1.194/" target="_blank">172.31.1.194</a> port 500, complainant<br>
> <a href="http://172.31.1.194/" target="_blank">172.31.1.194</a>: Connection refused [errno 111, origin ICMP type 3 code 3 (not<br>> authenticated)]<br>> Feb 18 19:01:47 testradiu2 pluto[31465]: ERROR: asynchronous network error<br>
> report on eth0 (sport=500) for message to <a href="http://172.31.1.194/" target="_blank">172.31.1.194</a> port 500, complainant<br>> <a href="http://172.31.1.194/" target="_blank">172.31.1.194</a>: Connection refused [errno 111, origin ICMP type 3 code 3 (not<br>
> authenticated)]<br>> Feb 18 19:02:27 testradiu2 pluto[31465]: "roadwarrior"[2] <a href="http://172.31.1.194/" target="_blank">172.31.1.194</a> #2:<br>> max number of retransmissions (2) reached STATE_MAIN_R2<br>
> Feb 18 19:02:27 testradiu2 pluto[31465]: "roadwarrior"[2] <a href="http://172.31.1.194/" target="_blank">172.31.1.194</a>:<br>> deleting connection "roadwarrior" instance with peer<br>> 172.31.1.194{isakmp=#0/ipsec=#0}<br>
><br>> Do you have any suggenstion?<br>><br>> Thanks!<br>><br>><br><br>--<br></div></div>Building and integrating Virtual Private Networks with Openswan:<br><a href="http://www.amazon.com/gp/product/1904811256/104-3099591-2946327?n=283155" target="_blank">http://www.amazon.com/gp/product/1904811256/104-3099591-2946327?n=283155</a><br>
</blockquote></div><br><br clear="all"><br>-- <br>Denis Beltramo