Hallo,
bisher hat es gut funktioniert, nur wäre da die zwei Jahresfrist nicht.
Ein Laptop (XP prof) von mehreren macht Probleme:
Log Intranator:
Mar 15 13:51:06 intranator pluto[14102]: packet from 212.144.81.98:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]
Mar 15 13:51:06 intranator pluto[14102]: packet from 212.144.81.98:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n]
Mar 15 13:51:06 intranator pluto[14102]: "C3"[6] 212.144.81.98 #9: responding to Main Mode from unknown peer 212.144.81.98
Mar 15 13:51:08 intranator pluto[14102]: "C3"[6] 212.144.81.98 #9: ignoring Vendor ID payload [47bbe7c993f1fc13...]
Mar 15 13:51:08 intranator pluto[14102]: "C3"[6] 212.144.81.98 #9: ignoring Vendor ID payload [da8e937880010000]
Mar 15 13:51:08 intranator pluto[14102]: "C3"[6] 212.144.81.98 #9: ignoring Vendor ID payload [XAUTH]
Mar 15 13:51:10 intranator pluto[14102]: "C3"[6] 212.144.81.98 #9: ignoring informational payload, type IPSEC_INITIAL_CONTACT
Mar 15 13:51:10 intranator pluto[14102]: "C3"[6] 212.144.81.98 #9: Main mode peer ID is ID_DER_ASN1_DN: 'C=DE, CN=gerl001'
Mar 15 13:51:10 intranator pluto[14102]: "C3"[6] 212.144.81.98 #9: Issuer CA certificate not found
Mar 15 13:51:10 intranator pluto[14102]: "C3"[6] 212.144.81.98 #9: X.509 certificate rejected
Mar 15 13:51:10 intranator pluto[14102]: "C3"[6] 212.144.81.98 #9: no suitable connection for peer 'C=DE, CN=gerl001'
Mar 15 13:51:10 intranator pluto[14102]: "C3"[6] 212.144.81.98 #9: sending notification INVALID_ID_INFORMATION to 212.144.81.98:500
Mar 15 13:51:19 intranator pluto[14102]: "C3"[6] 212.144.81.98 #9: encrypted Informational Exchange message is invalid because it is for incomplete ISAKMP SA
Log Netgear Client:
3-15: 13:50:54.566 Interface added: 212.144.81.98/255.255.255.0 on MODEM "PCTEL 2304WT V.92 MDC Modem".
3-15: 13:51:05.362 My Connections\Axxx Router - Attempting to resolve Hostname (Axxx.dyndns.org)
3-15: 13:51:05.662 My Connections\Axxx Router - Initiating IKE Phase 1 (Hostname=Axxx.dyndns.org) (IP ADDR=213.23.163.x22)
3-15: 13:51:06.013 My Connections\Axxx Router - SENDING>>>> ISAKMP OAK MM (SA, VID 2x)
3-15: 13:51:06.283 My Connections\Axxx Router - RECEIVED<<< ISAKMP OAK MM (SA)
3-15: 13:51:07.305 My Connections\Axxx Router - SENDING>>>> ISAKMP OAK MM (KE, NON, VID 3x)
3-15: 13:51:07.725 My Connections\Axxx Router - RECEIVED<<< ISAKMP OAK MM (KE, NON, CERT_REQ 8x)
3-15: 13:51:08.777 My Connections\Axxx Router - Using configured machine certificate "gerl001's CN=gerl001, C=DE ID".
3-15: 13:51:08.997 My Connections\Axxx Router - SENDING>>>> ISAKMP OAK MM *(ID, CERT, CERT_REQ 11x, SIG, NOTIFY:STATUS_INITIAL_CONTACT)
3-15: 13:51:10.269 My Connections\Axxx Router - RECEIVED<<< ISAKMP OAK INFO (NOTIFY:INVALID_ID_INFO)
3-15: 13:51:18.340 My Connections\Axxx Router - RECEIVED<<< ISAKMP OAK MM (KE, NON, CERT_REQ 8x)
3-15: 13:51:18.340 No matching Phase 1 ID received for Policy Entry My Connections\Axxx Router.
3-15: 13:51:18.340 My Connections\Axxx Router - SENDING>>>> ISAKMP OAK INFO *(HASH, NOTIFY:INVALID_ID_INFO)
3-15: 13:51:18.340 My Connections\Axxx Router - Discarding IKE SA negotiation
3-15: 13:51:18.340 MY COOKIE 5d 2f bd 46 68 45 41 1b
3-15: 13:51:18.340 HIS COOKIE d8 f8 d2 8d 6a e9 dc 1b
3-15: 13:51:37.608 NO MATCHING SECURE CONNECTION - RECEIVED<<< ISAKMP OAK MM (KE, NON, CERT_REQ 8x)
3-15: 13:51:37.608 NO MATCHING SECURE CONNECTION - Received message from unrecognized peer: 213.23.163.x22.
3-15: 13:51:37.608 NO MATCHING SECURE CONNECTION - SENDING>>>> ISAKMP OAK INFO (NOTIFY:NO_PROPOSAL_CHOSEN)
Problem: Issuer CA certificate not found
Schlüsselsatz und Verbindung (auf dem Intranator) sind in Ordnung, habe ich auf einem anderen Laptop ausprobiert. Auch ein anderes funktionierendes Schlüsselpaar geht auf dem Problemlaptop nicht![]()
Netgear Client auch schon deinstalliert und neu installiert -> gleiches Problem.
Gibt es außer Neuinstallation noch Ideen![]()


Zitieren
