Еще такой момент я на DFL Ставлю DNS имя удаленной стороны и включаю DPD на удаленной стороне в строке REMOTE GW ставлю 0.0.0.0
то в логе со стороны 2640 вижу что устройство готово принять ISAKMP, потом сам выступает как инициатор соединения
Код:
an 1 00:01:04 daemon info racoon: INFO: @(#)ipsec-tools 0.5.1 (http://ipsec-tools.sourceforge.net)
Jan 1 00:01:04 daemon info racoon: INFO: @(#)This product linked OpenSSL 0.9.7f 22 Mar 2005 (http://www.openssl.org/)
Jan 1 00:01:04 daemon info racoon: INFO: 127.0.0.1[500] used as isakmp port (fd=13)
Jan 1 00:01:04 daemon info racoon: INFO: 127.0.0.1[500] used for NAT-T
Jan 1 00:01:04 daemon info racoon: INFO: 192.168.1.1[500] used as isakmp port (fd=14)
Jan 1 00:01:04 daemon info racoon: INFO: 192.168.1.1[500] used for NAT-T
Jan 1 00:01:04 daemon info racoon: INFO: 78.36.*.* [500] used as isakmp port (fd=15)
Jan 1 00:01:04 daemon info racoon: INFO: 78.36.*.* [500] used for NAT-T
an 1 00:14:14 daemon info racoon: INFO: initiate new phase 1 negotiation: 78.36.221.144[500]<=>0.0.0.0[500]
Jan 1 00:14:14 daemon info racoon: INFO: begin Identity Protection mode.
Jan 1 00:14:45 daemon info racoon: ERROR: phase2 negotiation failed due to time up waiting for phase1. ESP 0.0.0.0->78.36.*.*
Jan 1 00:14:45 daemon info racoon: INFO: delete phase 2 handler.
Jan 1 00:15:14 daemon info racoon: ERROR: phase1 negotiation failed due to time up. 0c5900b106acc2ca:0000000000000000
Jan 1 00:17:05 daemon info racoon: INFO: IPsec-SA request for 0.0.0.0 queued due to no phase1 found.
Jan 1 00:17:05 daemon info racoon: INFO: initiate new phase 1 negotiation: 78.36.*.* [500]<=>0.0.0.0[500]
Jan 1 00:17:05 daemon info racoon: INFO: begin Identity Protection mode.
Jan 1 00:17:36 daemon info racoon: ERROR: phase2 negotiation failed due to time up waiting for phase1. ESP 0.0.0.0->78.36.*.*
Jan 1 00:17:36 daemon info racoon: INFO: delete phase 2 handler.
Jan 1 00:18:05 daemon info racoon: ERROR: phase1 negotiation failed due to time up. 9e91ca90c2410dc8:0000000000000000
Т.е по идеи туннель должен подняться но увы.