|
|||||||||||
|
Re: [Users] FreeSwan <---> Watchguard Firebox
From: Cristian Marin <cristian.marin(at)urbisinternational.ro>
Date: Wed Oct 01 2003 - 10:20:22 EDT
Hello Sascha,
Here is what I'v tried: Manual keying
On the Firebox
on FreeSwan
conn test left=myip, leftsubnet=mysubnet, leftnexthop=mygate rigt=fireboxip, rightsubnet=the other subnet, rightnexthop=hisgate auto=add spi=0x101 esp=3des-md5-96 espenckey=0xthe key generated on the firebox espauthkey=0xthe key generated on the firebox pfs=no
If I try to start with "ipsec manual --up test" the connection from the
linux box, I'm geting the error:
Auto keying
On Firebox
Local ID type: IP address Authentication:md5-hmac Encryption: 3des-cbc Diffie-Hellman Group: 2 epf=disable aggressive mode=disable Phase2 SAP type: esp authentication: md5-hmac encryption: 3des-cbc
On FreeSWan
conn test left=myip, leftsubnet=mysubnet, leftnexthop=mygate rigt=fireboxip, rightsubnet=the other subnet, rightnexthop=hisgate auto=add authby=secret esp=3des-md5-96 ah=hmac-md5 pfs=no
ipsec.secrets
with this conf. never passed the STATE_MAIN_I1 I you want I can send you the logs with debug=all or the barf file Sory if my other message was so short, but I wanted to know first if someone faced the same problem.
Thank you again
-------Original Message-------
From: Sascha Runschke
> I'm trying to make a VPN between a Linux RH 7.3 with FreeSwan
A vague assumption in my opinion ;) > I tried all the configurations a have found on the net,
What exactly did you try? What exactly is the error message? I'm truly sorry, but I borrowed away my crystal ball yesterday ;-) > Does anyone have this pair working?
Yes.
Firebox Systems don't use PFS, so don't forget to disable
it for the connection.
regards
--
phinfon: +49 (0)211 16686-514 phinmail: sascha.runschke@phinware.de phinfax: +49 (0)211 16686-666 phinweb: http://www.phinware.de .
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:01:39 EDT |
||||||||||
|
|||||||||||