Adrian
October 26th, 2004, 07:14
I have a isakmpd.conf and didn't work... why?
Here is isakmpd.conf
1. Configuration for VPN Gateway at location One (COSTA)
[General]
Retransmits= 5
Exchange-max-time= 120
Default-phase-1-lifetime= 600,60:86400
Default-phase-2-lifetime= 200,60:86400
[Phase 1]
87.77.58.53= COSTA
87.77.56.6= ACASA
87.77.50.6= STEFAN
[Phase 2]
Connections= COSTAgate-ACASAgate, COSTAgate-STEFANgate,
COSTAgate-ACASAlan, COSTAgate-STEFANlan,
COSTAlan-ACASAgate, COSTAlan-STEFANgate,
COSTAlan-ACASAlan, COSTAlan-STEFANlan
## ISAKMP Phase 1 peer sections for COSTA (using authentication-keys 1 & 2)
[ACASA]
Phase= 1
Transport= udp
Local-Address= 87.77.58.53
Address= 87.77.56.6
Configuration= Default-main-mode
Authentication= 4162428485550fc0105768f533c0eca5
[STEFAN]
Phase= 1
Transport= udp
Local-Address= 87.77.58.53
Address= 87.77.50.6
Configuration= Default-main-mode
Authentication= d24747784d85f3e328b3ccaad05741d6
## IPSEC Phase 2 sections
[COSTAgate-ACASAgate]
Phase= 2
ISAKMP-peer= ACASA
Configuration= Default-quick-mode
Local-ID= COSTAgate
Remote-ID= ACASAgate
[COSTAgate-STEFANgate]
Phase= 2
ISAKMP-peer= STEFAN
Configuration= Default-quick-mode
Local-ID= COSTAgate
Remote-ID= STEFANgate
[COSTAgate-ACASAlan]
Phase= 2
ISAKMP-peer= ACASA
Configuration= Default-quick-mode
Local-ID= COSTAgate
Remote-ID= ACASAlan
[COSTAgate-STEFANlan]
Phase= 2
ISAKMP-peer= STEFAN
Configuration= Default-quick-mode
Local-ID= COSTAgate
Remote-ID= STEFANlan
[COSTAlan-ACASAgate]
Phase= 2
ISAKMP-peer= ACASA
Configuration= Default-quick-mode
Local-ID= COSTAlan
Remote-ID= ACASAgate
[COSTAlan-STEFANgate]
Phase= 2
ISAKMP-peer= STEFAN
Configuration= Default-quick-mode
Local-ID= COSTAlan
Remote-ID= STEFANgate
[COSTAlan-ACASAlan]
Phase= 2
ISAKMP-peer= ACASA
Configuration= Default-quick-mode
Local-ID= COSTAlan
Remote-ID= ACASAlan
[COSTAlan-STEFANlan]
Phase= 2
ISAKMP-peer= STEFAN
Configuration= Default-quick-mode
Local-ID= COSTAlan
Remote-ID= STEFANlan
## Client ID sections
[COSTAlan]
ID-type= IPV4_ADDR_SUBNET
Network= 192.168.1.0
Netmask= 255.255.255.0
[ACASAlan]
ID-type= IPV4_ADDR_SUBNET
Network= 192.168.2.0
Netmask= 255.255.255.0
[STEFANlan]
ID-type= IPV4_ADDR_SUBNET
Network= 192.168.3.0
Netmask= 255.255.255.0
## Mode Descriptions
[Default-main-mode]
DOI= IPSEC
Exchange_Type= ID_PROT
Transforms= BLF-MD5
[Default-quick-mode]
DOI= IPSEC
Exchange_Type= QUICK_MODE
Suites= QM-ESP-BLF-MD5-SUITE
## Main Mode Transforms
[BLF-MD5]
Encryption_Algorithm= BLOWFISH_CBC
Key_Length= 128,96:192
Hash_Algorithm= MD5
Authentication_Method= pre_shared
Group_Description= EC2N_155
Life= LIFE_60_SECS,LIFE_1000_KB
[LIFE_60_SECS]
Life_Type= seconds
Life_Duration= 60,45:72
[LIFE_1000_KB]
Life_Type= kilobytes
Life_Duration= 1000,768:1536
2. Configuration for VPN Gateway at location Two (ACASA)
[General]
Retransmits= 5
Exchange-max-time= 120
Default-phase-1-lifetime= 600,60:86400
Default-phase-2-lifetime= 200,60:86400
[Phase 1]
87.77.56.6= ACASA
87.77.58.53= COSTA
87.77.50.6= STEFAN
[Phase 2]
Connections= ACASAgate-COSTAgate, ACASAgate-STEFANgate,
ACASAgate-COSTAlan, ACASAgate-STEFANlan,
ACASAlan-COSTAgate, ACASAlan-STEFANgate,
ACASAlan-COSTAlan, ACASAlan-STEFANlan
## ISAKMP Phase 1 peer sections for ACASA (using authentication-keys 1 & 3)
[COSTA]
Phase= 1
Transport= udp
Local-Address= 87.77.56.6
Address= 87.77.58.53
Configuration= Default-main-mode
Authentication= 4162428485550fc0105768f533c0eca5
[STEFAN]
Phase= 1
Transport= udp
Local-Address= 87.77.56.6
Address= 87.77.50.6
Configuration= Default-main-mode
Authentication= 03548fb63add9f6552b5400b33db3b00
## IPSEC Phase 2 sections
[ACASAgate-COSTAgate]
Phase= 2
ISAKMP-peer= COSTA
Configuration= Default-quick-mode
Local-ID= ACASAgate
Remote-ID= COSTAgate
[ACASAgate-STEFANgate]
Phase= 2
ISAKMP-peer= STEFAN
Configuration= Default-quick-mode
Local-ID= ACASAgate
Remote-ID= STEFANgate
[ACASAgate-COSTAlan]
Phase= 2
ISAKMP-peer= COSTA
Configuration= Default-quick-mode
Local-ID= ACASAgate
Remote-ID= COSTAlan
[ACASAgate-STEFANlan]
Phase= 2
ISAKMP-peer= STEFAN
Configuration= Default-quick-mode
Local-ID= ACASAgate
Remote-ID= STEFANlan
[ACASAlan-COSTAgate]
Phase= 2
ISAKMP-peer= COSTA
Configuration= Default-quick-mode
Local-ID= ACASAlan
Remote-ID= COSTAgate
[ACASAlan-STEFANgate]
Phase= 2
ISAKMP-peer= STEFAN
Configuration= Default-quick-mode
Local-ID= ACASAlan
Remote-ID= STEFANgate
[ACASAlan-COSTAlan]
Phase= 2
ISAKMP-peer= COSTA
Configuration= Default-quick-mode
Local-ID= ACASAlan
Remote-ID= COSTAlan
[ACASAlan-STEFANlan]
Phase= 2
ISAKMP-peer= STEFAN
Configuration= Default-quick-mode
Local-ID= ACASAlan
Remote-ID= STEFANlan
## Client ID sections
[ACASAlan]
ID-type= IPV4_ADDR_SUBNET
Network= 192.168.2.0
Netmask= 255.255.255.0
[COSTAlan]
ID-type= IPV4_ADDR_SUBNET
Network= 192.168.1.0
Netmask= 255.255.255.0
[STEFANlan]
ID-type= IPV4_ADDR_SUBNET
Network= 192.168.3.0
Netmask= 255.255.255.0
## Mode Descriptions
[Default-main-mode]
DOI= IPSEC
Exchange_Type= ID_PROT
Transforms= BLF-MD5
[Default-quick-mode]
DOI= IPSEC
Exchange_Type= QUICK_MODE
Suites= QM-ESP-BLF-MD5-SUITE
## Main Mode Transforms
[BLF-MD5]
Encryption_Algorithm= BLOWFISH_CBC
Key_Length= 128,96:192
Hash_Algorithm= MD5
Authentication_Method= pre_shared
Group_Description= EC2N_155
Life= LIFE_60_SECS,LIFE_1000_KB
[LIFE_60_SECS]
Life_Type= seconds
Life_Duration= 60,45:72
[LIFE_1000_KB]
Life_Type= kilobytes
Life_Duration= 1000,768:1536
3. Configuration for VPN Gateway at location Three (STEFAN)
[General]
Retransmits= 5
Exchange-max-time= 120
Default-phase-1-lifetime= 600,60:86400
Default-phase-2-lifetime= 200,60:86400
[Phase 1]
87.77.50.6= STEFAN
87.77.58.53= COSTA
87.77.56.6= ACASA
[Phase 2]
Connections= STEFANgate-COSTAgate, STEFANgate-ACASAgate,
STEFANgate-COSTAlan, STEFANgate-ACASAlan,
STEFANlan-COSTAgate, STEFANlan-ACASAgate,
STEFANlan-COSTAlan, STEFANlan-ACASAlan
## ISAKMP Phase 1 peer sections for STEFAN (using authentication-keys 2 & 3)
[COSTA]
Phase= 1
Transport= udp
Local-Address= 87.77.50.6
Address= 87.77.58.53
Configuration= Default-main-mode
Authentication= d24747784d85f3e328b3ccaad05741d6
[ACASA]
Phase= 1
Transport= udp
Local-Address= 87.77.50.6
Address= 87.77.56.6
Configuration= Default-main-mode
Authentication= 03548fb63add9f6552b5400b33db3b00
## IPSEC Phase 2 sections
[STEFANgate-COSTAgate]
Phase= 2
ISAKMP-peer= COSTA
Configuration= Default-quick-mode
Local-ID= STEFANgate
Remote-ID= COSTAgate
[STEFANgate-ACASAgate]
Phase= 2
ISAKMP-peer= ACASA
Configuration= Default-quick-mode
Local-ID= STEFANgate
Remote-ID= ACASAgate
[STEFANgate-COSTAlan]
Phase= 2
ISAKMP-peer= COSTA
Configuration= Default-quick-mode
Local-ID= STEFANgate
Remote-ID= COSTAlan
[STEFANgate-ACASAlan]
Phase= 2
ISAKMP-peer= ACASA
Configuration= Default-quick-mode
Local-ID= STEFANgate
Remote-ID= ACASAlan
[STEFANlan-COSTAgate]
Phase= 2
ISAKMP-peer= COSTA
Configuration= Default-quick-mode
Local-ID= STEFANlan
Remote-ID= COSTAgate
[STEFANlan-ACASAgate]
Phase= 2
ISAKMP-peer= ACASA
Configuration= Default-quick-mode
Local-ID= STEFANlan
Remote-ID= ACASAgate
[STEFANlan-COSTAlan]
Phase= 2
ISAKMP-peer= COSTA
Configuration= Default-quick-mode
Local-ID= STEFANlan
Remote-ID= COSTAlan
[STEFANlan-ACASAlan]
Phase= 2
ISAKMP-peer= ACASA
Configuration= Default-quick-mode
Local-ID= STEFANlan
Remote-ID= ACASAlan
## Client ID sections
[STEFANlan]
ID-type= IPV4_ADDR_SUBNET
Network= 192.168.3.0
Netmask= 255.255.255.0
[ACASAlan]
ID-type= IPV4_ADDR_SUBNET
Network= 192.168.2.0
Netmask= 255.255.255.0
[COSTAlan]
ID-type= IPV4_ADDR_SUBNET
Network= 192.168.1.0
Netmask= 255.255.255.0
## Mode Descriptions
[Default-main-mode]
DOI= IPSEC
Exchange_Type= ID_PROT
Transforms= BLF-MD5
[Default-quick-mode]
DOI= IPSEC
Exchange_Type= QUICK_MODE
Suites= QM-ESP-BLF-MD5-SUITE
## Main Mode Transforms
[BLF-MD5]
Encryption_Algorithm= BLOWFISH_CBC
Key_Length= 128,96:192
Hash_Algorithm= MD5
Authentication_Method= pre_shared
Group_Description= EC2N_155
Life= LIFE_60_SECS,LIFE_1000_KB
[LIFE_60_SECS]
Life_Type= seconds
Life_Duration= 60,45:72
[LIFE_1000_KB]
Life_Type= kilobytes
Life_Duration= 1000,768:1536
Here is isakmpd.conf
1. Configuration for VPN Gateway at location One (COSTA)
[General]
Retransmits= 5
Exchange-max-time= 120
Default-phase-1-lifetime= 600,60:86400
Default-phase-2-lifetime= 200,60:86400
[Phase 1]
87.77.58.53= COSTA
87.77.56.6= ACASA
87.77.50.6= STEFAN
[Phase 2]
Connections= COSTAgate-ACASAgate, COSTAgate-STEFANgate,
COSTAgate-ACASAlan, COSTAgate-STEFANlan,
COSTAlan-ACASAgate, COSTAlan-STEFANgate,
COSTAlan-ACASAlan, COSTAlan-STEFANlan
## ISAKMP Phase 1 peer sections for COSTA (using authentication-keys 1 & 2)
[ACASA]
Phase= 1
Transport= udp
Local-Address= 87.77.58.53
Address= 87.77.56.6
Configuration= Default-main-mode
Authentication= 4162428485550fc0105768f533c0eca5
[STEFAN]
Phase= 1
Transport= udp
Local-Address= 87.77.58.53
Address= 87.77.50.6
Configuration= Default-main-mode
Authentication= d24747784d85f3e328b3ccaad05741d6
## IPSEC Phase 2 sections
[COSTAgate-ACASAgate]
Phase= 2
ISAKMP-peer= ACASA
Configuration= Default-quick-mode
Local-ID= COSTAgate
Remote-ID= ACASAgate
[COSTAgate-STEFANgate]
Phase= 2
ISAKMP-peer= STEFAN
Configuration= Default-quick-mode
Local-ID= COSTAgate
Remote-ID= STEFANgate
[COSTAgate-ACASAlan]
Phase= 2
ISAKMP-peer= ACASA
Configuration= Default-quick-mode
Local-ID= COSTAgate
Remote-ID= ACASAlan
[COSTAgate-STEFANlan]
Phase= 2
ISAKMP-peer= STEFAN
Configuration= Default-quick-mode
Local-ID= COSTAgate
Remote-ID= STEFANlan
[COSTAlan-ACASAgate]
Phase= 2
ISAKMP-peer= ACASA
Configuration= Default-quick-mode
Local-ID= COSTAlan
Remote-ID= ACASAgate
[COSTAlan-STEFANgate]
Phase= 2
ISAKMP-peer= STEFAN
Configuration= Default-quick-mode
Local-ID= COSTAlan
Remote-ID= STEFANgate
[COSTAlan-ACASAlan]
Phase= 2
ISAKMP-peer= ACASA
Configuration= Default-quick-mode
Local-ID= COSTAlan
Remote-ID= ACASAlan
[COSTAlan-STEFANlan]
Phase= 2
ISAKMP-peer= STEFAN
Configuration= Default-quick-mode
Local-ID= COSTAlan
Remote-ID= STEFANlan
## Client ID sections
[COSTAlan]
ID-type= IPV4_ADDR_SUBNET
Network= 192.168.1.0
Netmask= 255.255.255.0
[ACASAlan]
ID-type= IPV4_ADDR_SUBNET
Network= 192.168.2.0
Netmask= 255.255.255.0
[STEFANlan]
ID-type= IPV4_ADDR_SUBNET
Network= 192.168.3.0
Netmask= 255.255.255.0
## Mode Descriptions
[Default-main-mode]
DOI= IPSEC
Exchange_Type= ID_PROT
Transforms= BLF-MD5
[Default-quick-mode]
DOI= IPSEC
Exchange_Type= QUICK_MODE
Suites= QM-ESP-BLF-MD5-SUITE
## Main Mode Transforms
[BLF-MD5]
Encryption_Algorithm= BLOWFISH_CBC
Key_Length= 128,96:192
Hash_Algorithm= MD5
Authentication_Method= pre_shared
Group_Description= EC2N_155
Life= LIFE_60_SECS,LIFE_1000_KB
[LIFE_60_SECS]
Life_Type= seconds
Life_Duration= 60,45:72
[LIFE_1000_KB]
Life_Type= kilobytes
Life_Duration= 1000,768:1536
2. Configuration for VPN Gateway at location Two (ACASA)
[General]
Retransmits= 5
Exchange-max-time= 120
Default-phase-1-lifetime= 600,60:86400
Default-phase-2-lifetime= 200,60:86400
[Phase 1]
87.77.56.6= ACASA
87.77.58.53= COSTA
87.77.50.6= STEFAN
[Phase 2]
Connections= ACASAgate-COSTAgate, ACASAgate-STEFANgate,
ACASAgate-COSTAlan, ACASAgate-STEFANlan,
ACASAlan-COSTAgate, ACASAlan-STEFANgate,
ACASAlan-COSTAlan, ACASAlan-STEFANlan
## ISAKMP Phase 1 peer sections for ACASA (using authentication-keys 1 & 3)
[COSTA]
Phase= 1
Transport= udp
Local-Address= 87.77.56.6
Address= 87.77.58.53
Configuration= Default-main-mode
Authentication= 4162428485550fc0105768f533c0eca5
[STEFAN]
Phase= 1
Transport= udp
Local-Address= 87.77.56.6
Address= 87.77.50.6
Configuration= Default-main-mode
Authentication= 03548fb63add9f6552b5400b33db3b00
## IPSEC Phase 2 sections
[ACASAgate-COSTAgate]
Phase= 2
ISAKMP-peer= COSTA
Configuration= Default-quick-mode
Local-ID= ACASAgate
Remote-ID= COSTAgate
[ACASAgate-STEFANgate]
Phase= 2
ISAKMP-peer= STEFAN
Configuration= Default-quick-mode
Local-ID= ACASAgate
Remote-ID= STEFANgate
[ACASAgate-COSTAlan]
Phase= 2
ISAKMP-peer= COSTA
Configuration= Default-quick-mode
Local-ID= ACASAgate
Remote-ID= COSTAlan
[ACASAgate-STEFANlan]
Phase= 2
ISAKMP-peer= STEFAN
Configuration= Default-quick-mode
Local-ID= ACASAgate
Remote-ID= STEFANlan
[ACASAlan-COSTAgate]
Phase= 2
ISAKMP-peer= COSTA
Configuration= Default-quick-mode
Local-ID= ACASAlan
Remote-ID= COSTAgate
[ACASAlan-STEFANgate]
Phase= 2
ISAKMP-peer= STEFAN
Configuration= Default-quick-mode
Local-ID= ACASAlan
Remote-ID= STEFANgate
[ACASAlan-COSTAlan]
Phase= 2
ISAKMP-peer= COSTA
Configuration= Default-quick-mode
Local-ID= ACASAlan
Remote-ID= COSTAlan
[ACASAlan-STEFANlan]
Phase= 2
ISAKMP-peer= STEFAN
Configuration= Default-quick-mode
Local-ID= ACASAlan
Remote-ID= STEFANlan
## Client ID sections
[ACASAlan]
ID-type= IPV4_ADDR_SUBNET
Network= 192.168.2.0
Netmask= 255.255.255.0
[COSTAlan]
ID-type= IPV4_ADDR_SUBNET
Network= 192.168.1.0
Netmask= 255.255.255.0
[STEFANlan]
ID-type= IPV4_ADDR_SUBNET
Network= 192.168.3.0
Netmask= 255.255.255.0
## Mode Descriptions
[Default-main-mode]
DOI= IPSEC
Exchange_Type= ID_PROT
Transforms= BLF-MD5
[Default-quick-mode]
DOI= IPSEC
Exchange_Type= QUICK_MODE
Suites= QM-ESP-BLF-MD5-SUITE
## Main Mode Transforms
[BLF-MD5]
Encryption_Algorithm= BLOWFISH_CBC
Key_Length= 128,96:192
Hash_Algorithm= MD5
Authentication_Method= pre_shared
Group_Description= EC2N_155
Life= LIFE_60_SECS,LIFE_1000_KB
[LIFE_60_SECS]
Life_Type= seconds
Life_Duration= 60,45:72
[LIFE_1000_KB]
Life_Type= kilobytes
Life_Duration= 1000,768:1536
3. Configuration for VPN Gateway at location Three (STEFAN)
[General]
Retransmits= 5
Exchange-max-time= 120
Default-phase-1-lifetime= 600,60:86400
Default-phase-2-lifetime= 200,60:86400
[Phase 1]
87.77.50.6= STEFAN
87.77.58.53= COSTA
87.77.56.6= ACASA
[Phase 2]
Connections= STEFANgate-COSTAgate, STEFANgate-ACASAgate,
STEFANgate-COSTAlan, STEFANgate-ACASAlan,
STEFANlan-COSTAgate, STEFANlan-ACASAgate,
STEFANlan-COSTAlan, STEFANlan-ACASAlan
## ISAKMP Phase 1 peer sections for STEFAN (using authentication-keys 2 & 3)
[COSTA]
Phase= 1
Transport= udp
Local-Address= 87.77.50.6
Address= 87.77.58.53
Configuration= Default-main-mode
Authentication= d24747784d85f3e328b3ccaad05741d6
[ACASA]
Phase= 1
Transport= udp
Local-Address= 87.77.50.6
Address= 87.77.56.6
Configuration= Default-main-mode
Authentication= 03548fb63add9f6552b5400b33db3b00
## IPSEC Phase 2 sections
[STEFANgate-COSTAgate]
Phase= 2
ISAKMP-peer= COSTA
Configuration= Default-quick-mode
Local-ID= STEFANgate
Remote-ID= COSTAgate
[STEFANgate-ACASAgate]
Phase= 2
ISAKMP-peer= ACASA
Configuration= Default-quick-mode
Local-ID= STEFANgate
Remote-ID= ACASAgate
[STEFANgate-COSTAlan]
Phase= 2
ISAKMP-peer= COSTA
Configuration= Default-quick-mode
Local-ID= STEFANgate
Remote-ID= COSTAlan
[STEFANgate-ACASAlan]
Phase= 2
ISAKMP-peer= ACASA
Configuration= Default-quick-mode
Local-ID= STEFANgate
Remote-ID= ACASAlan
[STEFANlan-COSTAgate]
Phase= 2
ISAKMP-peer= COSTA
Configuration= Default-quick-mode
Local-ID= STEFANlan
Remote-ID= COSTAgate
[STEFANlan-ACASAgate]
Phase= 2
ISAKMP-peer= ACASA
Configuration= Default-quick-mode
Local-ID= STEFANlan
Remote-ID= ACASAgate
[STEFANlan-COSTAlan]
Phase= 2
ISAKMP-peer= COSTA
Configuration= Default-quick-mode
Local-ID= STEFANlan
Remote-ID= COSTAlan
[STEFANlan-ACASAlan]
Phase= 2
ISAKMP-peer= ACASA
Configuration= Default-quick-mode
Local-ID= STEFANlan
Remote-ID= ACASAlan
## Client ID sections
[STEFANlan]
ID-type= IPV4_ADDR_SUBNET
Network= 192.168.3.0
Netmask= 255.255.255.0
[ACASAlan]
ID-type= IPV4_ADDR_SUBNET
Network= 192.168.2.0
Netmask= 255.255.255.0
[COSTAlan]
ID-type= IPV4_ADDR_SUBNET
Network= 192.168.1.0
Netmask= 255.255.255.0
## Mode Descriptions
[Default-main-mode]
DOI= IPSEC
Exchange_Type= ID_PROT
Transforms= BLF-MD5
[Default-quick-mode]
DOI= IPSEC
Exchange_Type= QUICK_MODE
Suites= QM-ESP-BLF-MD5-SUITE
## Main Mode Transforms
[BLF-MD5]
Encryption_Algorithm= BLOWFISH_CBC
Key_Length= 128,96:192
Hash_Algorithm= MD5
Authentication_Method= pre_shared
Group_Description= EC2N_155
Life= LIFE_60_SECS,LIFE_1000_KB
[LIFE_60_SECS]
Life_Type= seconds
Life_Duration= 60,45:72
[LIFE_1000_KB]
Life_Type= kilobytes
Life_Duration= 1000,768:1536