VPN

1. VPN

Aécio Meneses Alves
cicinho.brown

(usa Fedora)

Enviado em 12/08/2009 - 10:25h

Estou tendo uma dor de cabeça tremenda para autenticar um Windows Vista Starter em um servidor de VPN que usa L2TP para fechar a VPN.
Meu server roda CentOS 5.1.
No WinXP funciona normalmente. Testei a conexão na versão Home Basic do Windows Vista e também não consegui me conectar.

Estou com o log do servidor abaixo:

Aug 12 09:12:32 mileum pluto[2061]: packet from 201.x.x.x:500: ignoring Vendor ID payload [MS NT5 ISAKMPOAKLEY 00000006]
Aug 12 09:12:32 mileum pluto[2061]: packet from 201.x.x.x:500: received Vendor ID payload [RFC 3947] method set to=110
Aug 12 09:12:32 mileum pluto[2061]: packet from 201.x.x.x:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n] meth=106, but already using method 110
Aug 12 09:12:32 mileum pluto[2061]: packet from 201.x.x.x:500: ignoring Vendor ID payload [FRAGMENTATION]
Aug 12 09:12:32 mileum pluto[2061]: packet from 201.x.x.x:500: ignoring unknown Vendor ID payload [fb1de3cdf341b7ea16b7e5be0855f120]
Aug 12 09:12:32 mileum pluto[2061]: packet from 201.x.x.x:500: ignoring Vendor ID payload [Vid-Initial-Contact]
Aug 12 09:12:32 mileum pluto[2061]: packet from 201.x.x.x:500: ignoring unknown Vendor ID payload [e3a5966a76379fe707228231e5ce8652]
Aug 12 09:12:32 mileum pluto[2061]: "RW-PSK"[58] 201.x.x.x #332: responding to Main Mode from unknown peer 201.x.x.x
Aug 12 09:12:32 mileum pluto[2061]: "RW-PSK"[58] 201.x.x.x #332: only OAKLEY_GROUP_MODP1024 and OAKLEY_GROUP_MODP1536 supported. Attribute OAKLEY_GROUP_DESCRIPTION
Aug 12 09:12:32 mileum pluto[2061]: "RW-PSK"[58] 201.x.x.x #332: only OAKLEY_GROUP_MODP1024 and OAKLEY_GROUP_MODP1536 supported. Attribute OAKLEY_GROUP_DESCRIPTION
Aug 12 09:12:32 mileum pluto[2061]: "RW-PSK"[58] 201.x.x.x #332: transition from state STATE_MAIN_R0 to state STATE_MAIN_R1
Aug 12 09:12:32 mileum pluto[2061]: "RW-PSK"[58] 201.x.x.x #332: STATE_MAIN_R1: sent MR1, expecting MI2
Aug 12 09:12:32 mileum pluto[2061]: "RW-PSK"[58] 201.x.x.x #332: NAT-Traversal: Result using 3: peer is NATed
Aug 12 09:12:32 mileum pluto[2061]: "RW-PSK"[58] 201.x.x.x #332: transition from state STATE_MAIN_R1 to state STATE_MAIN_R2
Aug 12 09:12:32 mileum pluto[2061]: "RW-PSK"[58] 201.x.x.x #332: STATE_MAIN_R2: sent MR2, expecting MI3
Aug 12 09:12:33 mileum pluto[2061]: "RW-PSK"[58] 201.x.x.x #332: Main mode peer ID is ID_IPV4_ADDR: '10.10.x.194'
Aug 12 09:12:33 mileum pluto[2061]: "RW-PSK"[58] 201.x.x.x #332: switched from "RW-PSK" to "RW-PSK"
Aug 12 09:12:33 mileum pluto[2061]: "RW-PSK"[59] 201.x.x.x #332: deleting connection "RW-PSK" instance with peer 201.x.x.x {isakmp=#0/ipsec=#0}
Aug 12 09:12:33 mileum pluto[2061]: "RW-PSK"[59] 201.x.x.x #332: I did not send a certificate because I do not have one.
Aug 12 09:12:33 mileum pluto[2061]: "RW-PSK"[59] 201.x.x.x #332: transition from state STATE_MAIN_R2 to state STATE_MAIN_R3
Aug 12 09:12:33 mileum pluto[2061]: | NAT-T: new mapping 201.x.x.x:500/4500)
Aug 12 09:12:33 mileum pluto[2061]: "RW-PSK"[59] 201.x.x.x #332: STATE_MAIN_R3: sent MR3, ISAKMP SA established {auth=OAKLEY_PRESHARED_KEY cipher=oakley_3des_cbc_192 prf=oak
ley_sha group=modp2048}
Aug 12 09:12:33 mileum pluto[2061]: "RW-PSK"[59] 201.x.x.x #332: cannot respond to IPsec SA request because no connection is known for 200.y.y.y:17/1701...201.x.x.x[10.10.x.194]:17/1701===10.10.x.194/x
Aug 12 09:12:33 mileum pluto[2061]: "RW-PSK"[59] 201.x.x.x #332: sending encrypted notification INVALID_ID_INFORMATION to 201.x.x.x:4500
Aug 12 09:12:35 mileum pluto[2061]: "RW-PSK"[59] 201.x.x.x #332: Quick Mode I1 message is unacceptable because it uses a previously used Message ID 0x01000000 (perhaps this
is a duplicated packet)
Aug 12 09:12:35 mileum pluto[2061]: "RW-PSK"[59] 201.x.x.x #332: sending encrypted notification INVALID_MESSAGE_ID to 201.x.x.x:4500
Aug 12 09:12:38 mileum pluto[2061]: "RW-PSK"[59] 201.x.x.x #332: Quick Mode I1 message is unacceptable because it uses a previously used Message ID 0x01000000 (perhaps this
is a duplicated packet)
Aug 12 09:12:38 mileum pluto[2061]: "RW-PSK"[59] 201.x.x.x #332: sending encrypted notification INVALID_MESSAGE_ID to 201.x.x.x:4500
Aug 12 09:12:43 mileum pluto[2061]: "RW-PSK"[59] 201.x.x.x #332: Quick Mode I1 message is unacceptable because it uses a previously used Message ID 0x01000000 (perhaps this
is a duplicated packet)
Aug 12 09:12:43 mileum pluto[2061]: "RW-PSK"[59] 201.x.x.x #332: sending encrypted notification INVALID_MESSAGE_ID to 201.x.x.x:4500
Aug 12 09:12:51 mileum pluto[2061]: "RW-PSK"[59] 201.x.x.x #332: Quick Mode I1 message is unacceptable because it uses a previously used Message ID 0x01000000 (perhaps this
is a duplicated packet)
Aug 12 09:12:51 mileum pluto[2061]: "RW-PSK"[59] 201.x.x.x #332: sending encrypted notification INVALID_MESSAGE_ID to 201.x.x.x:4500
Aug 12 09:13:08 mileum pluto[2061]: "RW-PSK"[59] 201.x.x.x #332: Quick Mode I1 message is unacceptable because it uses a previously used Message ID 0x01000000 (perhaps this
is a duplicated packet)
Aug 12 09:13:08 mileum pluto[2061]: "RW-PSK"[59] 201.x.x.x #332: sending encrypted notification INVALID_MESSAGE_ID to 201.x.x.x:4500
Aug 12 09:13:25 mileum pluto[2061]: "RW-PSK"[59] 201.x.x.x #332: Quick Mode I1 message is unacceptable because it uses a previously used Message ID 0x01000000 (perhaps this
is a duplicated packet)
Aug 12 09:13:25 mileum pluto[2061]: "RW-PSK"[59] 201.x.x.x #332: sending encrypted notification INVALID_MESSAGE_ID to 201.x.x.x:4500
Aug 12 09:13:37 mileum pluto[2061]: "RW-PSK"[59] 201.x.x.x #332: received Delete SA payload: deleting ISAKMP State #332
Aug 12 09:13:37 mileum pluto[2061]: "RW-PSK"[59] 201.x.x.x: deleting connection "RW-PSK" instance with peer 201.x.x.x {isakmp=#0/ipsec=#0}
Aug 12 09:13:37 mileum pluto[2061]: packet from 201.x.x.x:4500: received and ignored informational message
Aug 12 09:14:38 mileum pluto[2061]: packet from 201.x.x.x:500: ignoring Vendor ID payload [MS NT5 ISAKMPOAKLEY 00000006]
Aug 12 09:14:38 mileum pluto[2061]: packet from 201.x.x.x:500: received Vendor ID payload [RFC 3947] method set to=110
Aug 12 09:14:38 mileum pluto[2061]: packet from 201.x.x.x:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n] meth=106, but already using method 110
Aug 12 09:14:38 mileum pluto[2061]: packet from 201.x.x.x:500: ignoring Vendor ID payload [FRAGMENTATION]
Aug 12 09:14:38 mileum pluto[2061]: packet from 201.x.x.x:500: ignoring unknown Vendor ID payload [fb1de3cdf341b7ea16b7e5be0855f120]
Aug 12 09:14:38 mileum pluto[2061]: packet from 201.x.x.x:500: ignoring Vendor ID payload [Vid-Initial-Contact]
Aug 12 09:14:38 mileum pluto[2061]: packet from 201.x.x.x:500: ignoring unknown Vendor ID payload [e3a5966a76379fe707228231e5ce8652]
Aug 12 09:14:38 mileum pluto[2061]: "RW-PSK"[60] 201.x.x.x #333: responding to Main Mode from unknown peer 201.x.x.x
Aug 12 09:14:38 mileum pluto[2061]: "RW-PSK"[60] 201.x.x.x #333: only OAKLEY_GROUP_MODP1024 and OAKLEY_GROUP_MODP1536 supported. Attribute OAKLEY_GROUP_DESCRIPTION
Aug 12 09:14:38 mileum pluto[2061]: "RW-PSK"[60] 201.x.x.x #333: only OAKLEY_GROUP_MODP1024 and OAKLEY_GROUP_MODP1536 supported. Attribute OAKLEY_GROUP_DESCRIPTION
Aug 12 09:14:38 mileum pluto[2061]: "RW-PSK"[60] 201.x.x.x #333: transition from state STATE_MAIN_R0 to state STATE_MAIN_R1
Aug 12 09:14:38 mileum pluto[2061]: "RW-PSK"[60] 201.x.x.x #333: STATE_MAIN_R1: sent MR1, expecting MI2
Aug 12 09:14:38 mileum pluto[2061]: "RW-PSK"[60] 201.x.x.x #333: NAT-Traversal: Result using 3: peer is NATed
Aug 12 09:14:38 mileum pluto[2061]: "RW-PSK"[60] 201.x.x.x #333: transition from state STATE_MAIN_R1 to state STATE_MAIN_R2
Aug 12 09:14:38 mileum pluto[2061]: "RW-PSK"[60] 201.x.x.x #333: STATE_MAIN_R2: sent MR2, expecting MI3
Aug 12 09:14:39 mileum pluto[2061]: "RW-PSK"[60] 201.x.x.x #333: Main mode peer ID is ID_IPV4_ADDR: '10.10.x.194'
Aug 12 09:14:39 mileum pluto[2061]: "RW-PSK"[60] 201.x.x.x #333: switched from "RW-PSK" to "RW-PSK"
Aug 12 09:14:39 mileum pluto[2061]: "RW-PSK"[61] 201.x.x.x #333: deleting connection "RW-PSK" instance with peer 201.x.x.x {isakmp=#0/ipsec=#0}
Aug 12 09:14:39 mileum pluto[2061]: "RW-PSK"[61] 201.x.x.x #333: I did not send a certificate because I do not have one.
Aug 12 09:14:39 mileum pluto[2061]: "RW-PSK"[61] 201.x.x.x #333: transition from state STATE_MAIN_R2 to state STATE_MAIN_R3
Aug 12 09:14:39 mileum pluto[2061]: | NAT-T: new mapping 201.x.x.x:500/4500)
Aug 12 09:14:39 mileum pluto[2061]: "RW-PSK"[61] 201.x.x.x #333: STATE_MAIN_R3: sent MR3, ISAKMP SA established {auth=OAKLEY_PRESHARED_KEY cipher=oakley_3des_cbc_192 prf=oak
ley_sha group=modp2048}
Aug 12 09:14:39 mileum pluto[2061]: "RW-PSK"[61] 201.x.x.x #333: cannot respond to IPsec SA request because no connection is known for 200.y.y.y:17/1701...201.x.x.x[10.10.x.194]:17/1701===10.10.x.194/x
Aug 12 09:14:39 mileum pluto[2061]: "RW-PSK"[61] 201.x.x.x #333: sending encrypted notification INVALID_ID_INFORMATION to 201.x.x.x:4500
Aug 12 09:14:41 mileum pluto[2061]: "RW-PSK"[61] 201.x.x.x #333: Quick Mode I1 message is unacceptable because it uses a previously used Message ID 0x01000000 (perhaps this is a duplicated packet)
Aug 12 09:14:41 mileum pluto[2061]: "RW-PSK"[61] 201.x.x.x #333: sending encrypted notification INVALID_MESSAGE_ID to 201.x.x.x:4500
Aug 12 09:14:44 mileum pluto[2061]: "RW-PSK"[61] 201.x.x.x #333: Quick Mode I1 message is unacceptable because it uses a previously used Message ID 0x01000000 (perhaps this is a duplicated packet)
Aug 12 09:14:44 mileum pluto[2061]: "RW-PSK"[61] 201.x.x.x #333: sending encrypted notification INVALID_MESSAGE_ID to 201.x.x.x:4500
Aug 12 09:14:49 mileum pluto[2061]: "RW-PSK"[61] 201.x.x.x #333: Quick Mode I1 message is unacceptable because it uses a previously used Message ID 0x01000000 (perhaps this is a duplicated packet)
Aug 12 09:14:49 mileum pluto[2061]: "RW-PSK"[61] 201.x.x.x #333: sending encrypted notification INVALID_MESSAGE_ID to 201.x.x.x:4500
Aug 12 09:14:57 mileum pluto[2061]: "RW-PSK"[61] 201.x.x.x #333: Quick Mode I1 message is unacceptable because it uses a previously used Message ID 0x01000000 (perhaps this
is a duplicated packet)
Aug 12 09:14:57 mileum pluto[2061]: "RW-PSK"[61] 201.x.x.x #333: sending encrypted notification INVALID_MESSAGE_ID to 201.x.x.x:4500
Aug 12 09:15:13 mileum pluto[2061]: "RW-PSK"[61] 201.x.x.x #333: Quick Mode I1 message is unacceptable because it uses a previously used Message ID 0x01000000 (perhaps this is a duplicated packet)
Aug 12 09:15:13 mileum pluto[2061]: "RW-PSK"[61] 201.x.x.x #333: sending encrypted notification INVALID_MESSAGE_ID to 201.x.x.x:4500
Aug 12 09:15:30 mileum pluto[2061]: "RW-PSK"[61] 201.x.x.x #333: Quick Mode I1 message is unacceptable because it uses a previously used Message ID 0x01000000 (perhaps this is a duplicated packet)
Aug 12 09:15:30 mileum pluto[2061]: "RW-PSK"[61] 201.x.x.x #333: sending encrypted notification INVALID_MESSAGE_ID to 201.x.x.x:4500
Aug 12 09:15:43 mileum pluto[2061]: "RW-PSK"[61] 201.x.x.x #333: received Delete SA payload: deleting ISAKMP State #333
Aug 12 09:15:43 mileum pluto[2061]: "RW-PSK"[61] 201.x.x.x: deleting connection "RW-PSK" instance with peer 201.x.x.x {isakmp=#0/ipsec=#0}
Aug 12 09:15:43 mileum pluto[2061]: packet from 201.x.x.x:4500: received and ignored informational message


Alguém poderia me ajudar a identificar o problema?

Obrigado,

Aécio


  


2. Re: VPN

Aécio Meneses Alves
cicinho.brown

(usa Fedora)

Enviado em 12/08/2009 - 10:28h

O erro que o Windows Vista apresenta é o 789 que diz:

Falha na tentativa de conexão L2TP porque a camada de segurança encontrou um erro de processamento durante as negociações iniciais com o computador remoto.



3. Re: VPN

Aécio Meneses Alves
cicinho.brown

(usa Fedora)

Enviado em 13/08/2009 - 12:35h

UP






Patrocínio

Site hospedado pelo provedor RedeHost.
Linux banner

Destaques

Artigos

Dicas

Tópicos

Top 10 do mês

Scripts