Ну объясните мне!
Я сбросил конфиг на DNS и заново настроил по книжке. C гейтвеем непонятно, но до него мы не доходим.
Сделал логи по ikesnoop, читаю. Первая фаза - ок. Xauth - ок. Адрес в локалке клиенту выдан и получен.
Согласовывают 2-ю фазу - и никак.
На DFL включено IP Sec алгоритмы - стандартные (DES-MD5-SHA1).
Дальше лог такой:
Код:
2014-02-01 15:55:01: IkeSnoop: Received IKE packet from 192.168.10.51:500
Exchange type : Quick mode
ISAKMP Version : 1.0
Flags : E (encryption)
Cookies : 0xe2c686a8bfa76c2 -> 0x93e31753beac65
Message ID : 0x27376505
Packet length : 1504 bytes
# payloads : 5
Payloads:
HASH (Hash)
Payload data length : 16 bytes
SA (Security Association)
Payload data length : 1400 bytes
DOI : 1 (IPsec DOI)
Proposal 1/1
Protocol 1/1
Protocol ID : ESP
SPI Size : 4
SPI Value : 0x3532d8b7
Transform 1/45
Transform ID : Rijndael (aes)
Encapsulation mode : Tunnel
Key length : 256
Authentication algorithm : HMAC-MD5
SA life type : Seconds
SA life duration : 3600
Transform 2/45
Transform ID : Rijndael (aes)
Encapsulation mode : Tunnel
Key length : 256
Authentication algorithm : HMAC-SHA-1
SA life type : Seconds
SA life duration : 3600
Transform 3/45
Transform ID : Rijndael (aes)
Encapsulation mode : Tunnel
Key length : 256
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 4/45
Transform ID : Rijndael (aes)
Encapsulation mode : Tunnel
Key length : 256
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 5/45
Transform ID : Rijndael (aes)
Encapsulation mode : Tunnel
Key length : 256
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 6/45
Transform ID : Rijndael (aes)
Encapsulation mode : Tunnel
Key length : 192
Authentication algorithm : HMAC-MD5
SA life type : Seconds
SA life duration : 3600
Transform 7/45
Transform ID : Rijndael (aes)
Encapsulation mode : Tunnel
Key length : 192
Authentication algorithm : HMAC-SHA-1
SA life type : Seconds
SA life duration : 3600
Transform 8/45
Transform ID : Rijndael (aes)
Encapsulation mode : Tunnel
Key length : 192
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 9/45
Transform ID : Rijndael (aes)
Encapsulation mode : Tunnel
Key length : 192
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 10/45
Transform ID : Rijndael (aes)
Encapsulation mode : Tunnel
Key length : 192
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 11/45
Transform ID : Rijndael (aes)
Encapsulation mode : Tunnel
Key length : 128
Authentication algorithm : HMAC-MD5
SA life type : Seconds
SA life duration : 3600
Transform 12/45
Transform ID : Rijndael (aes)
Encapsulation mode : Tunnel
Key length : 128
Authentication algorithm : HMAC-SHA-1
SA life type : Seconds
SA life duration : 3600
Transform 13/45
Transform ID : Rijndael (aes)
Encapsulation mode : Tunnel
Key length : 128
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 14/45
Transform ID : Rijndael (aes)
Encapsulation mode : Tunnel
Key length : 128
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 15/45
Transform ID : Rijndael (aes)
Encapsulation mode : Tunnel
Key length : 128
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 16/45
Transform ID : Blowfish
Encapsulation mode : Tunnel
Key length : 256
Authentication algorithm : HMAC-MD5
SA life type : Seconds
SA life duration : 3600
Transform 17/45
Transform ID : Blowfish
Encapsulation mode : Tunnel
Key length : 256
Authentication algorithm : HMAC-SHA-1
SA life type : Seconds
SA life duration : 3600
Transform 18/45
Transform ID : Blowfish
Encapsulation mode : Tunnel
Key length : 256
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 19/45
Transform ID : Blowfish
Encapsulation mode : Tunnel
Key length : 256
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 20/45
Transform ID : Blowfish
Encapsulation mode : Tunnel
Key length : 256
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 21/45
Transform ID : Blowfish
Encapsulation mode : Tunnel
Key length : 192
Authentication algorithm : HMAC-MD5
SA life type : Seconds
SA life duration : 3600
Transform 22/45
Transform ID : Blowfish
Encapsulation mode : Tunnel
Key length : 192
Authentication algorithm : HMAC-SHA-1
SA life type : Seconds
SA life duration : 3600
Transform 23/45
Transform ID : Blowfish
Encapsulation mode : Tunnel
Key length : 192
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 24/45
Transform ID : Blowfish
Encapsulation mode : Tunnel
Key length : 192
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 25/45
Transform ID : Blowfish
Encapsulation mode : Tunnel
Key length : 192
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 26/45
Transform ID : Blowfish
Encapsulation mode : Tunnel
Key length : 128
Authentication algorithm : HMAC-MD5
SA life type : Seconds
SA life duration : 3600
Transform 27/45
Transform ID : Blowfish
Encapsulation mode : Tunnel
Key length : 128
Authentication algorithm : HMAC-SHA-1
SA life type : Seconds
SA life duration : 3600
Transform 28/45
Transform ID : Blowfish
Encapsulation mode : Tunnel
Key length : 128
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 29/45
Transform ID : Blowfish
Encapsulation mode : Tunnel
Key length : 128
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 30/45
Transform ID : Blowfish
Encapsulation mode : Tunnel
Key length : 128
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 31/45
Transform ID : 3DES
Encapsulation mode : Tunnel
Authentication algorithm : HMAC-MD5
SA life type : Seconds
SA life duration : 3600
Transform 32/45
Transform ID : 3DES
Encapsulation mode : Tunnel
Authentication algorithm : HMAC-SHA-1
SA life type : Seconds
SA life duration : 3600
Transform 33/45
Transform ID : 3DES
Encapsulation mode : Tunnel
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 34/45
Transform ID : 3DES
Encapsulation mode : Tunnel
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 35/45
Transform ID : 3DES
Encapsulation mode : Tunnel
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 36/45
Transform ID : Cast
Encapsulation mode : Tunnel
Authentication algorithm : HMAC-MD5
SA life type : Seconds
SA life duration : 3600
Transform 37/45
Transform ID : Cast
Encapsulation mode : Tunnel
Authentication algorithm : HMAC-SHA-1
SA life type : Seconds
SA life duration : 3600
Transform 38/45
Transform ID : Cast
Encapsulation mode : Tunnel
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 39/45
Transform ID : Cast
Encapsulation mode : Tunnel
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 40/45
Transform ID : Cast
Encapsulation mode : Tunnel
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 41/45
Transform ID : DES
Encapsulation mode : Tunnel
Authentication algorithm : HMAC-MD5
SA life type : Seconds
SA life duration : 3600
Transform 42/45
Transform ID : DES
Encapsulation mode : Tunnel
Authentication algorithm : HMAC-SHA-1
SA life type : Seconds
SA life duration : 3600
Transform 43/45
Transform ID : DES
Encapsulation mode : Tunnel
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 44/45
Transform ID : DES
Encapsulation mode : Tunnel
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
Transform 45/45
Transform ID : DES
Encapsulation mode : Tunnel
Authentication algorithm : Unknown IPsec authentication alg
SA life type : Seconds
SA life duration : 3600
NONCE (Nonce)
Payload data length : 20 bytes
ID (Identification)
Payload data length : 8 bytes
ID : ipv4(any:0,[0..3]=192.168.102.31)
ID (Identification)
Payload data length : 12 bytes
ID : ipv4_subnet(any:0,[0..7]=0.0.0.0/0)
2014-02-01 15:55:01: IkeSnoop: Sending IKE packet to 192.168.10.51:500
Exchange type : Informational
ISAKMP Version : 1.0
Flags : E (encryption)
Cookies : 0xe2c686a8bfa76c2 -> 0x93e31753beac65
Message ID : 0x6cd908f1
Packet length : 114 bytes
# payloads : 2
Payloads:
HASH (Hash)
Payload data length : 16 bytes
N (Notification)
Payload data length : 62 bytes
Protocol ID : ESP
Notification : No proposal chosen
Notification data:
Notify message version: 1
Error text: "Could not find acceptable proposal"
Offending message ID: 0x27376505
Время (3600) соответствует.
Чем ей не понравились 41 и 42 предложения?