Ich habe seit geraumer Zeit mehr und mehr Probleme mit meiner einstmals gut laufenden VPN-Verbindung. Ein Verbindungsaufbau kommt nur noch selten zu Stande, dann aber auch so, dass ein Arbeiten kaum möglich ist. Manchmal erreichen nicht mal die Hälfte der Ping Pakete ihr Ziel. Jetzt aber gelingt es mir neuerdings so gut wie gar nicht mehr eine Verbindung auf zu bauen.
Im Log steht dazu folgendes:
Feb 10 12:48:27 intranator pluto[2356]: packet from 141.30.202.51:500: ignoring Vendor ID payload [da8e937880010000]
Feb 10 12:48:27 intranator pluto[2356]: packet from 141.30.202.51:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03]
Feb 10 12:48:27 intranator pluto[2356]: packet from 141.30.202.51:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n]
Feb 10 12:48:27 intranator pluto[2356]: packet from 141.30.202.51:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]
Feb 10 12:48:27 intranator pluto[2356]: packet from 141.30.202.51:500: received Vendor ID payload [RFC 3947]
Feb 10 12:48:27 intranator pluto[2356]: packet from 141.30.202.51:500: received Vendor ID payload [Dead Peer Detection]
Feb 10 12:48:27 intranator pluto[2356]: packet from 141.30.202.51:500: ignoring Vendor ID payload [NCP Client]
Feb 10 12:48:27 intranator pluto[2356]: packet from 141.30.202.51:500: ignoring Vendor ID payload [c61baca1f1a60cc11500000000000000]
Feb 10 12:48:27 intranator pluto[2356]: packet from 141.30.202.51:500: ignoring Vendor ID payload [FRAGMENTATION c0000000]
Feb 10 12:48:27 intranator pluto[2356]: "C6"[2] 141.30.202.51 #464: responding to Main Mode from unknown peer 141.30.202.51
Feb 10 12:48:27 intranator pluto[2356]: "C6"[2] 141.30.202.51 #464: Oakley Transform [OAKLEY_AES_CBC (256), OAKLEY_SHA, OAKLEY_GROUP_MODP1024] refused due to strict flag
Feb 10 12:48:27 intranator pluto[2356]: "C6"[2] 141.30.202.51 #464: Oakley Transform [OAKLEY_AES_CBC (256), OAKLEY_MD5, OAKLEY_GROUP_MODP1024] refused due to strict flag
Feb 10 12:48:27 intranator pluto[2356]: "C6"[2] 141.30.202.51 #464: Oakley Transform [OAKLEY_AES_CBC (256), OAKLEY_SHA, OAKLEY_GROUP_MODP1536] refused due to strict flag
Feb 10 12:48:27 intranator pluto[2356]: "C6"[2] 141.30.202.51 #464: Oakley Transform [OAKLEY_AES_CBC (256), OAKLEY_MD5, OAKLEY_GROUP_MODP1536] refused due to strict flag
Feb 10 12:48:27 intranator pluto[2356]: "C6"[2] 141.30.202.51 #464: Oakley Transform [OAKLEY_AES_CBC (192), OAKLEY_SHA, OAKLEY_GROUP_MODP1536] refused due to strict flag
Feb 10 12:48:27 intranator pluto[2356]: "C6"[2] 141.30.202.51 #464: Oakley Transform [OAKLEY_AES_CBC (192), OAKLEY_MD5, OAKLEY_GROUP_MODP1536] refused due to strict flag
Feb 10 12:48:27 intranator pluto[2356]: "C6"[2] 141.30.202.51 #464: NAT-Traversal: Result using RFC 3947: peer is NATed
Feb 10 12:48:27 intranator pluto[2356]: "C6"[2] 141.30.202.51 #464: ignoring informational payload, type IPSEC_INITIAL_CONTACT
Feb 10 12:48:27 intranator pluto[2356]: "C6"[2] 141.30.202.51 #464: Peer ID is ID_DER_ASN1_DN: 'C=DE, O=HYDRO-AIR, CN=EricT61p'
Feb 10 12:48:27 intranator pluto[2356]: "C6"[2] 141.30.202.51 #464: issuer cacert not found
Feb 10 12:48:27 intranator pluto[2356]: "C6"[2] 141.30.202.51 #464: X.509 certificate rejected
Feb 10 12:48:27 intranator pluto[2356]: "C6"[2] 141.30.202.51 #464: we have a cert and are sending it
Feb 10 12:48:27 intranator pluto[2356]: "C6"[2] 141.30.202.51:4500 #464: sent MR3, ISAKMP SA established
Feb 10 12:48:37 intranator pluto[2356]: "C6"[2] 141.30.202.51:4500 #464: retransmitting in response to duplicate packet; already STATE_MAIN_R3
Feb 10 12:48:41 intranator pluto[2356]: "C6"[2] 141.30.202.51:4500 #464: retransmitting in response to duplicate packet; already STATE_MAIN_R3
Feb 10 12:48:46 intranator pluto[2356]: "C6"[2] 141.30.202.51:4500 #464: discarding duplicate packet -- exhausted retransmission; already STATE_MAIN_R3
Feb 10 12:48:49 intranator dhcpd: DHCPDISCOVER from e1:6c:d6:ae:52:90 via eth0
Feb 10 12:48:49 intranator dhcpd: DHCPOFFER on 192.168.0.200 to e1:6c:d6:ae:52:90 via eth0
Feb 10 12:48:49 intranator dhcpd: DHCPDISCOVER from e1:6c:d6:ae:52:90 via 192.168.0.170
Feb 10 12:48:49 intranator dhcpd: DHCPOFFER on 192.168.0.200 to e1:6c:d6:ae:52:90 via 192.168.0.170
Feb 10 12:48:49 intranator dhcpd: DHCPINFORM from 192.168.0.184
Feb 10 12:48:49 intranator dhcpd: DHCPDISCOVER from e1:6c:d6:ae:52:90 via eth0
Feb 10 12:48:49 intranator dhcpd: DHCPOFFER on 192.168.0.200 to e1:6c:d6:ae:52:90 via eth0
Feb 10 12:48:49 intranator dhcpd: DHCPDISCOVER from e1:6c:d6:ae:52:90 via 192.168.0.170
Feb 10 12:48:49 intranator dhcpd: DHCPOFFER on 192.168.0.200 to e1:6c:d6:ae:52:90 via 192.168.0.170
Feb 10 12:48:49 intranator dhcpd: DHCPINFORM from 192.168.0.181
Feb 10 12:48:49 intranator dhcpd: DHCPINFORM from 192.168.0.181
Feb 10 12:48:49 intranator dhcpd: DHCPDISCOVER from e1:6c:d6:ae:52:90 via eth0
Feb 10 12:48:49 intranator dhcpd: DHCPOFFER on 192.168.0.200 to e1:6c:d6:ae:52:90 via eth0
Feb 10 12:48:49 intranator dhcpd: DHCPDISCOVER from e1:6c:d6:ae:52:90 via 192.168.0.170
Feb 10 12:48:49 intranator dhcpd: DHCPOFFER on 192.168.0.200 to e1:6c:d6:ae:52:90 via 192.168.0.170
Feb 10 12:48:49 intranator dhcpd: DHCPINFORM from 192.168.0.180
Feb 10 12:48:49 intranator dhcpd: DHCPINFORM from 192.168.0.180
Feb 10 12:48:50 intranator kernel: DENY IN=eth1 OUT= MAC=01:00:5e:00:00:01:00:1a:4f:76:4f:e6:08:00 SRC=192.168.0.249 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0x80 TTL=1 ID=3116 DF PROTO=2
Feb 10 12:48:52 intranator pluto[2356]: "C6"[2] 141.30.202.51:4500 #464: next payload type of ISAKMP Hash Payload has an unknown value: 116
Feb 10 12:48:52 intranator pluto[2356]: "C6"[2] 141.30.202.51:4500 #464: malformed payload in packet
Feb 10 12:48:57 intranator lmtpunix[6259]: Delivered: <cmu-lmtpd-6259-1234266537-0@intranator.ha.intern> to mailbox: user.cyrus
Ich war immer der Meinung, dass es an der Verbindung liegt, da an Anderen Stellen oft Problemlos die VPN-Verbindung aufgebaut wird.
Doch wenn ich das nun zusätzlich noch über eine UMTS-Verbindung teste komme ich wieder an genau diesen Punkt. Von Vodafone ist mir zumindest nicht bekannt, dass VPN-Passthrough nicht unterstützt wird.
Für ihre Hilfe oder Denkanstöße wäre ich sehr dankbar.
MfG Eric


Zitieren
