I checked with these configuration too ( but using MD5 instead of SHA1) - I am getting still same thing.<br><br>How do we create Policies for ipsec by the way? Is there something that requires to be configured other than this IKE, ESP for IPSEC Tunnel once ISAKMP is UP?<br>
<br><br><div class="gmail_quote">On Fri, Feb 29, 2008 at 4:49 PM, Sebastien COUPPEY <<a href="mailto:sebastien.couppey@zero9.it">sebastien.couppey@zero9.it</a>> wrote:<br><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">
You don t put the IKE parameter ?<br>
me with the cisco vpn3030 I have forced :<br>
<br>
ikelifetime=24h<br>
keylife=28800<br>
ike=3des-sha1-modp1024<br>
esp=3des-sha1<br>
pfs=no<br>
dpddelay=30<br>
dpdtimeout=120<br>
dpdaction=restart<br>
auto=start<br>
<div class="Ih2E3d"><br>
<br>
<br>
<br>
On Thu, Feb 28, 2008 at 11:25:17AM +0500, Khan, Hammad Aslam wrote:<br>
> Correction<br>
><br>
> On Thu, Feb 28, 2008 at 11:24 AM, Khan, Hammad Aslam <<a href="mailto:raohammad@gmail.com">raohammad@gmail.com</a>><br>
> wrote:<br>
><br>
> > Hi All,<br>
> > I am supposed to connect to a VPN Concentrator 3000 series CISCO on remote end and Linux Fedora Core 6 on my End with OpenSWAN installed;<br>
> ><br>
> > *While trying to connect to remote end; I stuck on *<br>
> > 117 "connectionName" #2:STATE_QUICK_I1: initiate<br>
> ><br>
> > 010 "connectionName" #2: STATE_QUICK_I1: retransmission; will wait 20s for response<br>
> ><br>
> > 010 "connectionName" #2: STATE_QUICK_I1: retransmission; will wait 40s for response<br>
> ><br>
> > *Remote End Company says (VPN Concentrator CISCO 3000 series)*<br>
> > Please check your side policy. There is a miss match.<br>
> ><br>
</div>> > 14719 02/26/2008 13:07:45.600 SEV=4 IKE/61 RPT=40382 <<a href="http://58.27.207.70/" target="_blank">http://58.27.207.70/</a>>my.host.ip.add <<a href="http://58.27.207.70/" target="_blank">http://58.27.207.70/</a>><br>
> ><br>
> > Group [my.host.ip.add <<a href="http://58.27.207.70/" target="_blank">http://58.27.207.70/</a>>]<br>
> ><br>
> > Tunnel rejected: Policy not found for Src:my.private.server.add <<a href="http://10.5.125.105/" target="_blank">http://10.5.125.105/</a>>, Dst: remote.private.ip.add <<a href="http://172.18.104.244/" target="_blank">http://172.18.104.244/</a>>!<br>
> ><br>
> ><br>
> > *My Connection Config*<br>
<div class="Ih2E3d">> > conn connectionName<br>
> > type=tunnel<br>
> > authby=secret # secret key<br>
> ><br>
> > auth=esp<br>
> > pfs=no<br>
> > esp=3des-md5-96<br>
</div>> > left=my.host.ip.add <<a href="http://58.27.207.70/" target="_blank">http://58.27.207.70/</a>> #<br>
> ><br>
> > leftsubnet=my.private.server.add <<a href="http://10.5.125.105/" target="_blank">http://10.5.125.105/</a>><br>
<div class="Ih2E3d">> ><br>
> > #leftnexthop=<a href="http://192.168.100.11" target="_blank">192.168.100.11</a> #second eth of my OpenVPS machine connected to my provate network<br>
> > right=<a href="http://202.69.9.240" target="_blank">202.69.9.240</a> # my peer's external, internet-routable ip address=<br>
> ><br>
</div>> > rightsubnet= remote.private.ip.add <<a href="http://172.18.104.244/" target="_blank">http://172.18.104.244/</a>>/32<br>
<div class="Ih2E3d">> ><br>
> ><br>
> > config setup<br>
> > interfaces="ipsec0=eth0"<br>
> > plutodebug="all"<br>
> ><br>
> > *Connection that we were supposed to make (Remote End Credentials that we need to match)*<br>
> ><br>
> > Hardware Cisco VPN Concentrator 3000 DH Group Diffie-Helman Group 2 Production<br>
> > Peer <a href="http://6.6.6.6" target="_blank">6.6.6.6</a> Encryption Domain <a href="http://172.18.104.244" target="_blank">172.18.104.244</a> Encryption 3DES<br>
> > Authentication MD5 Life Time 86400 sec PreShared Key "sharedKey"<br>
> > Protocol ESP<br>
> ><br>
> ><br>
> > *<br>
> > *How am I supposed to change policy to match above mentioned connection credentials.*<br>
> ><br>
> > Regards,<br>
</div>> > *<br>
> ><br>
> ><br>
<br>
> _______________________________________________<br>
> <a href="mailto:Users@openswan.org">Users@openswan.org</a><br>
> <a href="http://lists.openswan.org/mailman/listinfo/users" target="_blank">http://lists.openswan.org/mailman/listinfo/users</a><br>
> Building and Integrating Virtual Private Networks with Openswan:<br>
> <a href="http://www.amazon.com/gp/product/1904811256/104-3099591-2946327?n=283155" target="_blank">http://www.amazon.com/gp/product/1904811256/104-3099591-2946327?n=283155</a><br>
<br>
</blockquote></div><br>