[Leaplist] {Disarmed} Ipcop ipsec tunnel problems

Randall Perry randallp at domain-logic.com
Mon May 11 23:14:10 EDT 2009


Hey, all.
I am having problems getting a VPN client to connect to an IPCop box using
the roadwarrior ipsec setup.
The box currently has a dedicated IPSEC point-to-point that has been running
for 5 years now without issues.
Those are both IPCop boxes.  I also did not have problems setting up an
IPCop box to connect to a Cisco VPN concentrator.
This, however, is a pain in the nether region.
The client connection device is an Avaya IP telephone.
I loaded the VPNremote firmware on it (that has prescribed settings for
Juniper, Cisco, Avaya..and generic ipsec psk).
I setup generic PSK and then this comes up:

"avaya"[888] 10.0.0.120:2070 #11868: no acceptable Oakley Transform
"avaya"[888] 10.0.0.120:2070 #11868: sending notification NO_PROPOSAL_CHOSEN
to 10.0.0.120:2070
"avaya"[888] 10.0.0.120:2070: deleting connection "avaya" instance with peer
10.0.0.120
"avaya"[889] 10.0.0.120:2070 #11869: Aggressive mode peer ID is ID_FQDN:
'@@avaya'
"avaya"[890] 10.0.0.120:2070 #11869: deleting connection "avaya" instance
with peer 10.0.0.120
"avaya"[890] 10.0.0.120:2070 #11869: responding to Aggressive Mode, state
#11869, connection "avaya" from 10.0.0.120
"avaya"[890] 10.0.0.120:2070 #11869: Can't authenticate: no preshared key
found for `@avaya' and `%any'.  Attribute OAKLEY_AUTHENTICATION_METHOD

The %any is there because of it being roadwarrior ipsec.
Here is my ipsec.secrets file (not real pre shared key):

@avaya %any : PSK 'passwordpassword'

Will it puke without an actual hostname where @avaya is at?


-- 
Randall Perry
www.domain-logic.com
574.612.5893

Ohann von Goethe: “None are more hopelessly enslaved than those who falsely
believe they are free.”

-- 
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.leap-cf.org/pipermail/leaplist/attachments/20090511/e3d0da01/attachment.html


More information about the Leaplist mailing list