Hallo,
nach dem gestrigen Update auf die Version 5.3.10 können sich unsere Shrew Clients nicht mehr verbinden.
Hier ein Auszug aus dem log:
Aug 2 11:17:37 mail pluto[2618]: packet from 84.151.219.147:973: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]
Aug 2 11:17:37 mail pluto[2618]: packet from 84.151.219.147:973: ignoring Vendor ID payload [16f6ca16e4a4066d83821a0f0aeaa862]
Aug 2 11:17:37 mail pluto[2618]: packet from 84.151.219.147:973: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n]
Aug 2 11:17:37 mail pluto[2618]: packet from 84.151.219.147:973: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03]
Aug 2 11:17:37 mail pluto[2618]: packet from 84.151.219.147:973: received Vendor ID payload [RFC 3947]
Aug 2 11:17:37 mail pluto[2618]: packet from 84.151.219.147:973: ignoring Vendor ID payload [FRAGMENTATION 80000000]
Aug 2 11:17:37 mail pluto[2618]: packet from 84.151.219.147:973: received Vendor ID payload [Dead Peer Detection]
Aug 2 11:17:37 mail pluto[2618]: packet from 84.151.219.147:973: ignoring Vendor ID payload [f14b94b7bff1fef02773b8c49feded26]
Aug 2 11:17:37 mail pluto[2618]: packet from 84.151.219.147:973: ignoring Vendor ID payload [166f932d55eb64d8e4df4fd37e2313f0d0fd8451]
Aug 2 11:17:37 mail pluto[2618]: packet from 84.151.219.147:973: ignoring Vendor ID payload [8404adf9cda05760b2ca292e4bff537b]
Aug 2 11:17:37 mail pluto[2618]: packet from 84.151.219.147:973: ignoring Vendor ID payload [Cisco-Unity]
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: responding to Main Mode from unknown peer 84.151.219.147:973
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: Oakley Transform [AES_CBC (256), HMAC_MD5, MODP_3072] refused due to strict flag
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: Oakley Transform [AES_CBC (256), HMAC_MD5, MODP_2048] refused due to strict flag
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: Oakley Transform [AES_CBC (256), HMAC_MD5, MODP_1536] refused due to strict flag
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: Oakley Transform [AES_CBC (256), HMAC_MD5, MODP_1024] refused due to strict flag
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: MODP_768 is not supported. Attribute OAKLEY_GROUP_DESCRIPTION
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: Oakley Transform [AES_CBC (256), HMAC_SHA1, MODP_3072] refused due to strict flag
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: Oakley Transform [AES_CBC (256), HMAC_SHA1, MODP_2048] refused due to strict flag
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: Oakley Transform [AES_CBC (256), HMAC_SHA1, MODP_1536] refused due to strict flag
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: Oakley Transform [AES_CBC (256), HMAC_SHA1, MODP_1024] refused due to strict flag
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: MODP_768 is not supported. Attribute OAKLEY_GROUP_DESCRIPTION
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: Oakley Transform [AES_CBC (192), HMAC_MD5, MODP_3072] refused due to strict flag
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: Oakley Transform [AES_CBC (192), HMAC_MD5, MODP_2048] refused due to strict flag
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: Oakley Transform [AES_CBC (192), HMAC_MD5, MODP_1536] refused due to strict flag
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: Oakley Transform [AES_CBC (192), HMAC_MD5, MODP_1024] refused due to strict flag
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: MODP_768 is not supported. Attribute OAKLEY_GROUP_DESCRIPTION
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: Oakley Transform [AES_CBC (192), HMAC_SHA1, MODP_3072] refused due to strict flag
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: Oakley Transform [AES_CBC (192), HMAC_SHA1, MODP_2048] refused due to strict flag
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: Oakley Transform [AES_CBC (192), HMAC_SHA1, MODP_1536] refused due to strict flag
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: Oakley Transform [AES_CBC (192), HMAC_SHA1, MODP_1024] refused due to strict flag
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: MODP_768 is not supported. Attribute OAKLEY_GROUP_DESCRIPTION
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: Oakley Transform [AES_CBC (128), HMAC_MD5, MODP_3072] refused due to strict flag
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: Oakley Transform [AES_CBC (128), HMAC_MD5, MODP_2048] refused due to strict flag
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: Oakley Transform [AES_CBC (128), HMAC_MD5, MODP_1536] refused due to strict flag
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: Oakley Transform [AES_CBC (128), HMAC_MD5, MODP_1024] refused due to strict flag
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: MODP_768 is not supported. Attribute OAKLEY_GROUP_DESCRIPTION
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: Oakley Transform [AES_CBC (128), HMAC_SHA1, MODP_3072] refused due to strict flag
Aug 2 11:17:37 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: Oakley Transform [AES_CBC (128), HMAC_SHA1, MODP_2048] refused due to strict flag
Aug 2 11:18:42 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #73: max number of retransmissions (2) reached STATE_MAIN_R1
Aug 2 11:18:47 mail pluto[2618]: "C4"[4] 84.151.219.147:973 #74: max number of retransmissions (2) reached STATE_MAIN_R1
Aug 2 11:18:47 mail pluto[2618]: "C4"[4] 84.151.219.147:973: deleting connection "C4" instance with peer 84.151.219.147 {isakmp=#0/ipsec=#0}
Client-Einstellungen erfolgten gemäß Handbuch und bis zum Update funktionierte alles einwandfrei.


Zitieren
