Jump to content

skomik

Forum Members
  • Posts

    1
  • Joined

  • Last visited

Posts posted by skomik

  1. Приветствую!

    Подскажите, пожалуйста, по настройке IPsec VPN сервера на Keenetic Giga III (2.06.A.7.0-5) и клиента на OS X 10.11. Перебрал все комбинации настроек на клиенте и сервере, ничего не выходит. Дальше всего смог продвинуться в соединении, когда на клиенте настраиваю L2TP over IPsec, а на сервере IKEv1, XAuth: None, Negotiation: Main. Тогда хотя бы проходит первая фаза IKE. Лог прикладываю ниже.

    Кто нибудь на маке настраивал соединение, роутер вообще поддерживает L2TP/IPsec или надо использовать другие доступные режимы в настройках OS — Cisco IPsec или IKEv2 (ни в одном из них тоже не получилось)? PPTP завелся сразу, но использовать его не хочу.

    [more]Feb 10 01:12:56ipsec05[iKE] received NAT-T (RFC 3947) vendor ID

    Feb 10 01:12:56ipsec05[iKE] received draft-ietf-ipsec-nat-t-ike vendor ID

    Feb 10 01:12:56ipsec05[iKE] received draft-ietf-ipsec-nat-t-ike-08 vendor ID

    Feb 10 01:12:56ipsec05[iKE] received draft-ietf-ipsec-nat-t-ike-07 vendor ID

    Feb 10 01:12:56ipsec05[iKE] received draft-ietf-ipsec-nat-t-ike-06 vendor ID

    Feb 10 01:12:56ipsec05[iKE] received draft-ietf-ipsec-nat-t-ike-05 vendor ID

    Feb 10 01:12:56ipsec05[iKE] received draft-ietf-ipsec-nat-t-ike-04 vendor ID

    Feb 10 01:12:56ipsec05[iKE] received draft-ietf-ipsec-nat-t-ike-03 vendor ID

    Feb 10 01:12:56ipsec05[iKE] received draft-ietf-ipsec-nat-t-ike-02 vendor ID

    Feb 10 01:12:56ipsec05[iKE] received draft-ietf-ipsec-nat-t-ike-02\n vendor ID

    Feb 10 01:12:56ipsec05[iKE] received FRAGMENTATION vendor ID

    Feb 10 01:12:56ipsec05[iKE] received DPD vendor ID

    Feb 10 01:12:56ipsec05[iKE] 213.87.145.181 is initiating a Main Mode IKE_SA

    Feb 10 01:12:56ipsec11[iKE] remote host is behind NAT

    Feb 10 01:12:56ipsec11[iKE] linked key for crypto map '(unnamed)' is not found, still searching

    Feb 10 01:12:57ipsec08[CFG] looking for pre-shared key peer configs matching MY_IP_ADDRESS...213.87.145.181[172.20.10.4]

    Feb 10 01:12:57ipsec08[CFG] selected peer config "skomikVPN"

    Feb 10 01:12:57ipsec08[iKE] IKE_SA skomikVPN[2] established between MY_IP_ADDRESS[MY_IP_ADDRESS]...213.87.145.181[172.20.10.4]

    Feb 10 01:12:57ipsec08[iKE] scheduling reauthentication in 3571s

    Feb 10 01:12:57ipsec08[iKE] maximum IKE_SA lifetime 3591s

    Feb 10 01:12:57ipsec04[iKE] no matching CHILD_SA config found

    Feb 10 01:13:01ipsec12[iKE] received retransmit of request with ID 4107092407, but no response to retransmit

    Feb 10 01:13:04ipsec15[iKE] received retransmit of request with ID 4107092407, but no response to retransmit

    Feb 10 01:13:07ipsec09[iKE] received retransmit of request with ID 4107092407, but no response to retransmit

    Feb 10 01:13:10ipsec11[iKE] received retransmit of request with ID 4107092407, but no response to retransmit

    Feb 10 01:13:13ipsec08[iKE] received retransmit of request with ID 4107092407, but no response to retransmit

    Feb 10 01:13:16ipsec12[iKE] received retransmit of request with ID 4107092407, but no response to retransmit

    Feb 10 01:13:19ipsec15[iKE] received retransmit of request with ID 4107092407, but no response to retransmit

    Feb 10 01:13:22ipsec09[iKE] received retransmit of request with ID 4107092407, but no response to retransmit

    Feb 10 01:13:25ipsec10[iKE] received retransmit of request with ID 4107092407, but no response to retransmit

    Feb 10 01:13:27ipsec12[iKE] received DELETE for IKE_SA skomikVPN[2]

    Feb 10 01:13:27ipsec12[iKE] deleting IKE_SA skomikVPN[2] between MY_IP_ADDRESS[MY_IP_ADDRESS]...213.87.145.181[172.20.10.4][/more]

×
×
  • Create New...