[Openswan Users] can't connect to ipsec server with winXP Client

Omar Stalin Abreu Manzueta omar.abreu at gmail.com
Wed Apr 13 15:15:40 CEST 2005


I got a linux box with openswan as a gateway, i can connect from other
linux ipsec client but when i try to connect from the winXP i get this
error

C:\ipsec>ipsec
IPSec Version 2.2.0 (c) 2001-2003 Marcus Mueller
Getting running Config ...
Microsoft's Windows XP identified
Setting up IPSec ...

       Deactivating old policy...
       Removing old policy...

Connection roadwarrior:
       MyTunnel     : 172.16.4.15
       MyNet        : 172.16.4.15/255.255.255.255
       PartnerTunnel: 172.27.26.216
       PartnerNet   : 172.27.26.216/255.255.255.255
       CA (ID)      : C=do,ST=Santo Domingo,L=Santo Domingo,O=abreu.info...
       PFS          : y
       Auto         : start
       Auth.Mode    : MD5
       Rekeying     : 3600S/50000K
Error 0xcbbb0012 occurred:

The authentication method specified is invalid or unsupported.

POTF_VERSION
USAGE:
ipseccmd \\machinename -f FilterList -n NegotiationMethodList -t TunnelAddr
        -a AuthMethodList -1s SecurityMethodList -1k MMRekeyTime
        -1e SoftSAExpirationTime -soft -confirm [-dialup OR -lan]
        {-w Location -p PolicyName:PollInterval -r RuleName [-x OR -y] -o}
    Creates or modifies IPSec policy.

ipseccmd \\machinename show gpo filters policies auth stats sas all
    Displays current IPSec configuration.

ipseccmd \\machinename set [logike OR dontlogike]
    Turns on/off IKE logging.

ipseccmd \\machinename [import OR export] Location FileName
    Imports or exports a static policy file.

ipseccmd -file FileName
    Executes a file containing regular static or dynamic ipseccmd commands.

For extended usage, run: ipseccmd -?
Fehler bei Command: ipseccmd -w REG -p FreeSwan -r Host-roadwarrior -t 172.27.26
.216 -f 172.16.4.15/255.255.255.255=172.27.26.216/255.255.255.255 -n ESP[MD5,3DE
S]3600S/50000KPFS -a CERT:"C=do,ST=Santo Domingo,L=Santo Domingo,O=abreu.infotel
.com.do,CN=abreu.infotel.com.do,emailAddress=omar.abreu at infotel.com.do" -lan -1p
> NUL:
Error 0xcbbb0012 occurred:

The authentication method specified is invalid or unsupported.

POTF_VERSION
USAGE:
ipseccmd \\machinename -f FilterList -n NegotiationMethodList -t TunnelAddr
        -a AuthMethodList -1s SecurityMethodList -1k MMRekeyTime
        -1e SoftSAExpirationTime -soft -confirm [-dialup OR -lan]
        {-w Location -p PolicyName:PollInterval -r RuleName [-x OR -y] -o}
    Creates or modifies IPSec policy.

ipseccmd \\machinename show gpo filters policies auth stats sas all
    Displays current IPSec configuration.

ipseccmd \\machinename set [logike OR dontlogike]
    Turns on/off IKE logging.

ipseccmd \\machinename [import OR export] Location FileName
    Imports or exports a static policy file.

ipseccmd -file FileName
    Executes a file containing regular static or dynamic ipseccmd commands.

For extended usage, run: ipseccmd -?
Fehler bei Command: ipseccmd -w REG -p FreeSwan -r roadwarrior-Host -t 172.16.4.
15 -f 172.27.26.216/255.255.255.255=172.16.4.15/255.255.255.255 -n ESP[MD5,3DES]
3600S/50000KPFS -a CERT:"C=do,ST=Santo Domingo,L=Santo Domingo,O=abreu.infotel.c
om.do,CN=abreu.infotel.com.do,emailAddress=omar.abreu at infotel.com.do" -lan -1p >
NUL:
       Activating policy...
Error converting policy: 0x5

Connection roadwarrior-net:
       MyTunnel     : 172.16.4.15
       MyNet        : 172.16.4.15/255.255.255.255
       PartnerTunnel: 172.27.26.216
       PartnerNet   : 192.168.2.0/255.255.252.0
       CA (ID)      : C=do,ST=Santo Domingo,L=Santo Domingo,O=abreu.info...
       PFS          : y
       Auto         : start
       Auth.Mode    : MD5
       Rekeying     : 3600S/50000K
Error 0xcbbb0012 occurred:

The authentication method specified is invalid or unsupported.

POTF_VERSION
USAGE:
ipseccmd \\machinename -f FilterList -n NegotiationMethodList -t TunnelAddr
        -a AuthMethodList -1s SecurityMethodList -1k MMRekeyTime
        -1e SoftSAExpirationTime -soft -confirm [-dialup OR -lan]
        {-w Location -p PolicyName:PollInterval -r RuleName [-x OR -y] -o}
    Creates or modifies IPSec policy.

ipseccmd \\machinename show gpo filters policies auth stats sas all
    Displays current IPSec configuration.

ipseccmd \\machinename set [logike OR dontlogike]
    Turns on/off IKE logging.

ipseccmd \\machinename [import OR export] Location FileName
    Imports or exports a static policy file.

ipseccmd -file FileName
    Executes a file containing regular static or dynamic ipseccmd commands.

For extended usage, run: ipseccmd -?
Fehler bei Command: ipseccmd -w REG -p FreeSwan -r Host-roadwarrior-net -t 172.2
7.26.216 -f 172.16.4.15/255.255.255.255=192.168.2.0/255.255.252.0 -n ESP[MD5,3DE
S]3600S/50000KPFS -a CERT:"C=do,ST=Santo Domingo,L=Santo Domingo,O=abreu.infotel
.com.do,CN=abreu.infotel.com.do,emailAddress=omar.abreu at infotel.com.do" -lan -1p
> NUL:
Error 0xcbbb0012 occurred:

The authentication method specified is invalid or unsupported.

POTF_VERSION
USAGE:
ipseccmd \\machinename -f FilterList -n NegotiationMethodList -t TunnelAddr
        -a AuthMethodList -1s SecurityMethodList -1k MMRekeyTime
        -1e SoftSAExpirationTime -soft -confirm [-dialup OR -lan]
        {-w Location -p PolicyName:PollInterval -r RuleName [-x OR -y] -o}
    Creates or modifies IPSec policy.

ipseccmd \\machinename show gpo filters policies auth stats sas all
    Displays current IPSec configuration.

ipseccmd \\machinename set [logike OR dontlogike]
    Turns on/off IKE logging.

ipseccmd \\machinename [import OR export] Location FileName
    Imports or exports a static policy file.

ipseccmd -file FileName
    Executes a file containing regular static or dynamic ipseccmd commands.

For extended usage, run: ipseccmd -?
Fehler bei Command: ipseccmd -w REG -p FreeSwan -r roadwarrior-net-Host -t 172.1
6.4.15 -f 192.168.2.0/255.255.252.0=172.16.4.15/255.255.255.255 -n ESP[MD5,3DES]
3600S/50000KPFS -a CERT:"C=do,ST=Santo Domingo,L=Santo Domingo,O=abreu.infotel.c
om.do,CN=abreu.infotel.com.do,emailAddress=omar.abreu at infotel.com.do" -lan -1p >
NUL:
       Activating policy...
Error converting policy: 0x5

C:\ipsec>

If you can help me i'll be glad,

Thanks anyway

Omar Abreu


More information about the Users mailing list