paul at xelerance.com
Wed Dec 7 17:08:53 CET 2005
On Wed, 7 Dec 2005, Michael Tinsay wrote:
> I'm stuck here in trying to make openswan connect to a netscreen 5xt appliance. Phase 1 is being accomplished, but fails on Phase 2 with the netscreen log indicating "IKE<w.x.y.z> Phase 2: Rejected proposals from peer. Negotiations failed."
> My ipsec.conf:
> conn weroam01
You should specify an esp= line as well.
> # left side = local
> # right side = netscreen
> From the netscreen webui, here are the acceptable proposals:
> Name PFS Encap. Encrypt/Auth Life Time Life Size Configure
That needs another pfs=no and add esp=3des-md5
More information about the Users