Hallo zusammen
ich habe ein Phänomen bei dem ich Eure Hilfe brauche:
Mit einem Notebook welches eingerichtet war und wo die Verbindung auch klappte, komme ich nur noch sporadisch über den Netgear VPN Client auf den Intranator und somit in unser Netz.
Nach der kompletten Neuinstallation des Notebooks und neuer Vodafone Treiber und neuem Netgear Client komme ich gar nicht mehr rein.
NAT ist im Intranator eingeschaltet.
Da wir mehrere Notebooks erfolgreich verbinden, weiß ich mir keinen Rat mehr, warum diese jetzt nach längerer Zeit im Aussendienst, Probleme macht. Den Vodafone Globe Trotter habe ich auch schon mal getauscht und einen neuen Schlüssel angelegt.
Hier die Log vom Notebook
7-01: 11:24:02.593 My Connections\Fotofix - Initiating IKE Phase 1 (IP ADDR=87.139.39.73)
7-01: 11:24:03.140 My Connections\Fotofix - SENDING>>>> ISAKMP OAK MM (SA, VID 2x)
7-01: 11:24:03.281 My Connections\Fotofix - RECEIVED<<< ISAKMP OAK MM (SA, VID 4x)
7-01: 11:24:03.406 My Connections\Fotofix - Peer supports Dead Peer Detection Version 1.0
7-01: 11:24:03.406 My Connections\Fotofix - Peer is NAT-T draft-02 capable
7-01: 11:24:03.406 My Connections\Fotofix - Dead Peer Detection enabled
7-01: 11:24:03.421 My Connections\Fotofix - SENDING>>>> ISAKMP OAK MM (KE, NON, NAT-D 2x, VID 4x)
7-01: 11:24:03.625 My Connections\Fotofix - RECEIVED<<< ISAKMP OAK MM (KE, NON, CERT_REQ, NAT-D 2x)
7-01: 11:24:03.875 My Connections\Fotofix - Using configured machine certificate "VertriebAD2's Fotofix ID".
7-01: 11:24:04.015 My Connections\Fotofix - SENDING>>>> ISAKMP OAK MM *(ID, CERT, CERT_REQ, SIG, NOTIFY:STATUS_REPLAY_STATUS, NOTIFY:STATUS_INITIAL_CONTACT)
7-01: 11:24:05.078 Interface added: 90.186.95.243/255.0.0.0 on MODEM "GlobeTrotter 3G+ Modem Interface".
7-01: 11:24:05.109 Clearing arp for adapter 131076
7-01: 11:24:19.156 My Connections\Fotofix - message not received! Retransmitting!
7-01: 11:24:19.156 My Connections\Fotofix - SENDING>>>> ISAKMP OAK MM *(Retransmission)
7-01: 11:24:34.156 My Connections\Fotofix - message not received! Retransmitting!
7-01: 11:24:34.156 My Connections\Fotofix - SENDING>>>> ISAKMP OAK MM *(Retransmission)
7-01: 11:24:49.187 My Connections\Fotofix - message not received! Retransmitting!
7-01: 11:24:49.187 My Connections\Fotofix - SENDING>>>> ISAKMP OAK MM *(Retransmission)
7-01: 11:25:04.187 My Connections\Fotofix - Exceeded 3 IKE SA negotiation attempts
7-01: 11:25:04.187 My Connections\Fotofix - Deleting IKE SA (IP ADDR=87.139.39.73)
7-01: 11:25:04.187 My Connections\Fotofix - MY COOKIE d7 80 e7 7b dc 9a bd ab
7-01: 11:25:04.187 My Connections\Fotofix - HIS COOKIE 13 43 d5 30 51 26 be c5
7-01: 11:25:04.187 My Connections\Fotofix - SENDING>>>> ISAKMP OAK INFO *(HASH, DEL)
7-01: 11:25:19.046
7-01: 11:25:19.046 My Connections\Fotofix - Initiating IKE Phase 1 (IP ADDR=87.139.39.73)
Hier die Log vom Intranator:
Jul 1 11:23:18 mail pluto[2827]: "C10"[66] 78.49.12.221:61441 #2453: max number of retransmissions (2) reached STATE_QUICK_I1. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
Jul 1 11:23:18 mail pluto[2827]: "C10"[66] 78.49.12.221:61441 #2453: starting keying attempt 3 of at most 3
Jul 1 11:23:26 mail pluto[2827]: "C10"[73] 78.49.12.221:61441 #2454: max number of retransmissions (2) reached STATE_MAIN_I1. No response (or no acceptable response) to our first IKE message
Jul 1 11:23:26 mail pluto[2827]: "C10"[73] 78.49.12.221:61441 #2454: starting keying attempt 2 of at most 3
Jul 1 11:23:26 mail pluto[2827]: "C10"[73] 78.49.12.221:61441 #2455: initiating Main Mode to replace #2454
Jul 1 11:23:26 mail pluto[2827]: ERROR: asynchronous network error report on ppp0 for message to 78.49.12.221 port 61441, complainant 78.49.12.221: No route to host [errno 113, origin ICMP type 3 code 13 (not authenticated)]
Jul 1 11:23:36 mail pluto[2827]: ERROR: asynchronous network error report on ppp0 for message to 78.49.12.221 port 61441, complainant 78.49.12.221: No route to host [errno 113, origin ICMP type 3 code 13 (not authenticated)]
Jul 1 11:23:43 mail named[2196]: success resolving '190.8.68.58.in-addr.arpa/PTR' (in '.'?) after reducing the advertised EDNS UDP packet size to 512 octets
Jul 1 11:23:57 mail pluto[2827]: ERROR: asynchronous network error report on ppp0 for message to 78.49.12.221 port 61441, complainant 78.49.12.221: No route to host [errno 113, origin ICMP type 3 code 13 (not authenticated)]
Jul 1 11:24:07 mail pluto[2827]: packet from 90.186.95.243:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]
Jul 1 11:24:07 mail pluto[2827]: packet from 90.186.95.243:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n]
Jul 1 11:24:07 mail pluto[2827]: "C21"[36] 90.186.95.243 #2456: responding to Main Mode from unknown peer 90.186.95.243
Jul 1 11:24:08 mail pluto[2827]: "C21"[36] 90.186.95.243 #2456: ignoring Vendor ID payload [47bbe7c993f1fc13b4e6d0db565c68e5010201010201010310 31302e382e3320...]
Jul 1 11:24:08 mail pluto[2827]: "C21"[36] 90.186.95.243 #2456: ignoring Vendor ID payload [da8e937880010000]
Jul 1 11:24:08 mail pluto[2827]: "C21"[36] 90.186.95.243 #2456: received Vendor ID payload [Dead Peer Detection]
Jul 1 11:24:08 mail pluto[2827]: "C21"[36] 90.186.95.243 #2456: received Vendor ID payload [XAUTH]
Jul 1 11:24:08 mail pluto[2827]: "C21"[36] 90.186.95.243 #2456: NAT-Traversal: Result using draft-ietf-ipsec-nat-t-ike-02/03: no NAT detected
Jul 1 11:24:09 mail pluto[2827]: "C21"[36] 90.186.95.243 #2456: ignoring informational payload, type IPSEC_REPLAY_STATUS
Jul 1 11:24:09 mail pluto[2827]: "C21"[36] 90.186.95.243 #2456: ignoring informational payload, type IPSEC_INITIAL_CONTACT
Jul 1 11:24:09 mail pluto[2827]: "C21"[36] 90.186.95.243 #2456: Peer ID is ID_DER_ASN1_DN: 'C=DE, ST=NRW, L=Krefeld, O=Fotofix, OU=Vertrieb, CN=VertriebAD2, E=Norbert.Majd@fotofix.info'
Jul 1 11:24:09 mail pluto[2827]: "C21"[36] 90.186.95.243 #2456: issuer cacert not found
Jul 1 11:24:09 mail pluto[2827]: "C21"[36] 90.186.95.243 #2456: X.509 certificate rejected
Jul 1 11:24:09 mail pluto[2827]: "C21"[36] 90.186.95.243 #2456: we have a cert and are sending it upon request
Jul 1 11:24:09 mail pluto[2827]: "C21"[36] 90.186.95.243 #2456: sent MR3, ISAKMP SA established
Jul 1 11:24:24 mail pluto[2827]: "C21"[36] 90.186.95.243 #2456: retransmitting in response to duplicate packet; already STATE_MAIN_R3
Jul 1 11:24:36 mail pluto[2827]: "C10"[73] 78.49.12.221:61441 #2455: max number of retransmissions (2) reached STATE_MAIN_I1. No response (or no acceptable response) to our first IKE message
Jul 1 11:24:36 mail pluto[2827]: "C10"[73] 78.49.12.221:61441 #2455: starting keying attempt 3 of at most 3
Jul 1 11:24:36 mail pluto[2827]: "C10"[73] 78.49.12.221:61441 #2457: initiating Main Mode to replace #2455
Jul 1 11:24:36 mail pluto[2827]: ERROR: asynchronous network error report on ppp0 for message to 78.49.12.221 port 61441, complainant 78.49.12.221: No route to host [errno 113, origin ICMP type 3 code 13 (not authenticated)]
Jul 1 11:24:40 mail pluto[2827]: "C21"[36] 90.186.95.243 #2456: retransmitting in response to duplicate packet; already STATE_MAIN_R3
Jul 1 11:24:46 mail pluto[2827]: ERROR: asynchronous network error report on ppp0 for message to 78.49.12.221 port 61441, complainant 78.49.12.221: No route to host [errno 113, origin ICMP type 3 code 13 (not authenticated)]
Jul 1 11:24:54 mail pluto[2827]: "C21"[36] 90.186.95.243 #2456: discarding duplicate packet -- exhausted retransmission; already STATE_MAIN_R3
Jul 1 11:25:06 mail pluto[2827]: ERROR: asynchronous network error report on ppp0 for message to 78.49.12.221 port 61441, complainant 78.49.12.221: No route to host [errno 113, origin ICMP type 3 code 13 (not authenticated)]
Jul 1 11:25:08 mail pluto[2827]: "C21"[36] 90.186.95.243 #2456: next payload type of ISAKMP Hash Payload has an unknown value: 33
Jul 1 11:25:08 mail pluto[2827]: "C21"[36] 90.186.95.243 #2456: malformed payload in packet
Jul 1 11:25:14 mail lmtpunix[11658]: IOERROR: opening /var/spool/imap/user/cyrus/cyrus.index: Permission denied
Jul 1 11:25:15 mail mon[2876]: failure for intranator lmtp 1246440315 /var/imap/socket/lmtp
Jul 1 11:25:24 mail pluto[2827]: packet from 90.186.95.243:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]
Jul 1 11:25:24 mail pluto[2827]: packet from 90.186.95.243:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n]
Jul 1 11:25:24 mail pluto[2827]: "C21"[36] 90.186.95.243 #2458: responding to Main Mode from unknown peer 90.186.95.243
Jul 1 11:25:24 mail pluto[2827]: "C21"[36] 90.186.95.243 #2458: ignoring Vendor ID payload [47bbe7c993f1fc13b4e6d0db565c68e5010201010201010310 31302e382e3320...]
Jul 1 11:25:24 mail pluto[2827]: "C21"[36] 90.186.95.243 #2458: ignoring Vendor ID payload [da8e937880010000]
Jul 1 11:25:24 mail pluto[2827]: "C21"[36] 90.186.95.243 #2458: received Vendor ID payload [Dead Peer Detection]
Jul 1 11:25:24 mail pluto[2827]: "C21"[36] 90.186.95.243 #2458: received Vendor ID payload [XAUTH]
Jul 1 11:25:24 mail pluto[2827]: "C21"[36] 90.186.95.243 #2458: NAT-Traversal: Result using draft-ietf-ipsec-nat-t-ike-02/03: no NAT detected
Jul 1 11:25:25 mail pluto[2827]: "C21"[36] 90.186.95.243 #2458: ignoring informational payload, type IPSEC_REPLAY_STATUS
Jul 1 11:25:25 mail pluto[2827]: "C21"[36] 90.186.95.243 #2458: ignoring informational payload, type IPSEC_INITIAL_CONTACT
Jul 1 11:25:25 mail pluto[2827]: "C21"[36] 90.186.95.243 #2458: Peer ID is ID_DER_ASN1_DN: 'C=DE, ST=NRW, L=Krefeld, O=Fotofix, OU=Vertrieb, CN=VertriebAD2, E=Norbert.Majd@fotofix.info'
Jul 1 11:25:25 mail pluto[2827]: "C21"[36] 90.186.95.243 #2458: issuer cacert not found
Jul 1 11:25:25 mail pluto[2827]: "C21"[36] 90.186.95.243 #2458: X.509 certificate rejected
Vielen Dank im Voraus für jede Hilfe
Grüße
Thomas


Zitieren
