Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

[Users] Freeswan + Checkpoint NG NO_PROPOSAL_CHOSEN

From: Jason Aley <Jason.Aley(at)spicers.net>
Date: Thu May 08 2003 - 13:05:24 EDT


Dear all

I am trying to create an IPSEC tunnel between by Linux firewall running Freeswan 1.99 and a Nokia checkpoint NG firewall.

Despite following the set-up guide verbatum I cannot create the tunnel and am getting the error message "No_Proposal_chosen".

I have successfully created a tunnel between 2 Linux firewalls running Freeswan so am reasonably confident of my configuration on the Linux end.
I have complete control of the Freeswan end of the tunnel but am reliant on other resources at the Nokia end.

I am able to ping the remote firewall unencrypted so am confident of routes etc.

An example log is included below - Any help on this matter would be greatly appreciated

regards

Jason

Do you need help?X

May 8 14:58:57 vpn pluto[9220]: | *received 40 bytes from xxx.xxx.67.135:500 on eth0
May 8 14:58:57 vpn pluto[9220]: | b0 ed 28 0f a5 00 e2 be 00 00 00 00 00 00 00 00
May 8 14:58:57 vpn pluto[9220]: | 0b 10 05 00 a1 d2 df d9 00 00 00 28 00 00 00 0c

May  8 14:58:57 vpn pluto[9220]: |   00 00 00 00  01 00 00 0e
May  8 14:58:57 vpn pluto[9220]: | **parse ISAKMP Message:
May  8 14:58:57 vpn pluto[9220]: |    initiator cookie:
May  8 14:58:57 vpn pluto[9220]: |   b0 ed 28 0f  a5 00 e2 be
May  8 14:58:57 vpn pluto[9220]: |    responder cookie:
May  8 14:58:57 vpn pluto[9220]: |   00 00 00 00  00 00 00 00
May  8 14:58:57 vpn pluto[9220]: |    next payload type: ISAKMP_NEXT_N
May  8 14:58:57 vpn pluto[9220]: |    ISAKMP version: ISAKMP Version 1.0
May  8 14:58:57 vpn pluto[9220]: |    exchange type: ISAKMP_XCHG_INFO
May  8 14:58:57 vpn pluto[9220]: |    flags: none
May  8 14:58:57 vpn pluto[9220]: |    message ID:  a1 d2 df d9
May  8 14:58:57 vpn pluto[9220]: |    length: 40
May  8 14:58:57 vpn pluto[9220]: | ICOOKIE:  b0 ed 28 0f  a5 00 e2 be
May  8 14:58:57 vpn pluto[9220]: | RCOOKIE:  00 00 00 00  00 00 00 00
May  8 14:58:57 vpn pluto[9220]: | peer:  d5 a1 43 87
May  8 14:58:57 vpn pluto[9220]: | state hash entry 3
May  8 14:58:57 vpn pluto[9220]: | state object #1 found, in
STATE_MAIN_I1
May 8 14:58:57 vpn pluto[9220]: | ***parse ISAKMP Notification Payload: May 8 14:58:57 vpn pluto[9220]: | next payload type: ISAKMP_NEXT_NONE
May  8 14:58:57 vpn pluto[9220]: |    length: 12
May  8 14:58:57 vpn pluto[9220]: |    DOI: ISAKMP_DOI_ISAKMP
May  8 14:58:57 vpn pluto[9220]: |    protocol ID: 1
May  8 14:58:57 vpn pluto[9220]: |    SPI size: 0
May  8 14:58:57 vpn pluto[9220]: |    Notify Message Type:
NO_PROPOSAL_CHOSEN
May 8 14:58:57 vpn pluto[9220]: "net-ABS-net-SPICERS" #1: ignoring informational payload, type NO_PROPOSAL_CHOSEN May 8 14:58:57 vpn pluto[9220]: | info: May 8 14:58:57 vpn pluto[9220]: "net-ABS-net-SPICERS" #1: received and ignored informational message
May 8 14:58:57 vpn pluto[9220]: | next event EVENT_RETRANSMIT in 4 seconds for #1
May  8 14:59:01 vpn pluto[9220]: |  
May  8 14:59:01 vpn pluto[9220]: | *time to handle event
May  8 14:59:01 vpn pluto[9220]: | event after this is EVENT_SHUNT_SCAN
in 109 seconds
May 8 14:59:01 vpn pluto[9220]: | handling event EVENT_RETRANSMIT for 213.161.67.135 "net-ABS-net-SPICERS" #1
May 8 14:59:01 vpn pluto[9220]: | sending 176 bytes for EVENT_RETRANSMIT through eth0 to xxx.xxx.67.135:500:

This e-mail message is intended solely for the person to whom it is addressed and may contain confidential or privileged information. If you have received it in error, please notify postmaster@spicers.net and destroy this e-mail and any attachments. In addition, you must not disclose, copy, distribute or take any action in reliance on this e-mail or any attachments.  Any views or opinions presented in this e-mail are solely those of the author and do not necessarily represent those of the company. E-mail may be susceptible to data corruption, interception, unauthorised amendment, viruses and unforeseen delays, and we do not accept liability for any such data corruption, interception, unauthorised amendment, viruses and delays or the consequences thereof. Accordingly, this e-mail and any attachments are opened at your own risk. Spicers Ltd.

Registered in England, Registration No. 425809

Users mailing list
Users@lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users Received on Thu May 8 13:45:33 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:01:30 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library