📄 description.txt
字号:
This is a test of pre-shared mode from an unknown IP address.It uses main mode, and nat-t support is explicitely disabled.road connects to east in this test.This failure was reported by Astaro:Date: Fri, 17 Jun 2005 12:31:23 +0200From: Stephan Scholz <sscholz@astaro.com>Subject: PSK and NAT-T optionI have found a bug in Openswan 2.3.1 concerning PSK and the NAT-Traversaloption.If NAT-Traversal is disabled in ipsec.conf, then a roadwarrior PSK connectionfails to establish - regardless of whether NAT-T is actually needed or not.I have attached the pluto log file.2005:06:16-13:51:15 (none) pluto[26118]: | 2005:06:16-13:51:15 (none) pluto[26118]: | *received 756 bytes from 192.168.2.96:500 on eth0 (port=500)2005:06:16-13:51:15 (none) pluto[26118]: | 11 ec a0 34 0f 1b 5e 38 00 00 00 00 00 00 00 002005:06:16-13:51:15 (none) pluto[26118]: | 01 10 02 00 00 00 00 00 00 00 02 f4 0d 00 02 342005:06:16-13:51:15 (none) pluto[26118]: | 00 00 00 01 00 00 00 01 00 00 02 28 01 01 00 0e2005:06:16-13:51:15 (none) pluto[26118]: | 03 00 00 28 01 01 00 00 80 01 00 07 80 02 00 022005:06:16-13:51:15 (none) pluto[26118]: | 80 03 00 01 80 04 00 02 80 0b 00 01 00 0c 00 042005:06:16-13:51:15 (none) pluto[26118]: | 00 00 70 80 80 0e 00 80 03 00 00 28 02 01 00 002005:06:16-13:51:15 (none) pluto[26118]: | 80 01 00 07 80 02 00 01 80 03 00 01 80 04 00 022005:06:16-13:51:15 (none) pluto[26118]: | 80 0b 00 01 00 0c 00 04 00 00 70 80 80 0e 00 802005:06:16-13:51:15 (none) pluto[26118]: | 03 00 00 24 03 01 00 00 80 01 00 05 80 02 00 022005:06:16-13:51:15 (none) pluto[26118]: | 80 03 00 01 80 04 00 02 80 0b 00 01 00 0c 00 042005:06:16-13:51:15 (none) pluto[26118]: | 00 00 70 80 03 00 00 24 04 01 00 00 80 01 00 052005:06:16-13:51:15 (none) pluto[26118]: | 80 02 00 01 80 03 00 01 80 04 00 02 80 0b 00 012005:06:16-13:51:15 (none) pluto[26118]: | 00 0c 00 04 00 00 70 80 03 00 00 28 05 01 00 002005:06:16-13:51:15 (none) pluto[26118]: | 80 01 00 07 80 02 00 02 80 03 00 01 80 04 00 022005:06:16-13:51:15 (none) pluto[26118]: | 80 0b 00 01 00 0c 00 04 00 00 70 80 80 0e 01 002005:06:16-13:51:15 (none) pluto[26118]: | 03 00 00 28 06 01 00 00 80 01 00 07 80 02 00 012005:06:16-13:51:15 (none) pluto[26118]: | 80 03 00 01 80 04 00 02 80 0b 00 01 00 0c 00 042005:06:16-13:51:15 (none) pluto[26118]: | 00 00 70 80 80 0e 01 00 03 00 00 28 07 01 00 002005:06:16-13:51:15 (none) pluto[26118]: | 80 01 00 07 80 02 00 02 80 03 00 01 80 04 00 052005:06:16-13:51:15 (none) pluto[26118]: | 80 0b 00 01 00 0c 00 04 00 00 70 80 80 0e 00 802005:06:16-13:51:15 (none) pluto[26118]: | 03 00 00 28 08 01 00 00 80 01 00 07 80 02 00 012005:06:16-13:51:15 (none) pluto[26118]: | 80 03 00 01 80 04 00 05 80 0b 00 01 00 0c 00 042005:06:16-13:51:15 (none) pluto[26118]: | 00 00 70 80 80 0e 00 80 03 00 00 24 09 01 00 002005:06:16-13:51:15 (none) pluto[26118]: | 80 01 00 05 80 02 00 02 80 03 00 01 80 04 00 052005:06:16-13:51:15 (none) pluto[26118]: | 80 0b 00 01 00 0c 00 04 00 00 70 80 03 00 00 242005:06:16-13:51:15 (none) pluto[26118]: | 0a 01 00 00 80 01 00 05 80 02 00 01 80 03 00 012005:06:16-13:51:15 (none) pluto[26118]: | 80 04 00 05 80 0b 00 01 00 0c 00 04 00 00 70 802005:06:16-13:51:15 (none) pluto[26118]: | 03 00 00 28 0b 01 00 00 80 01 00 07 80 02 00 022005:06:16-13:51:15 (none) pluto[26118]: | 80 03 00 01 80 04 00 05 80 0b 00 01 00 0c 00 042005:06:16-13:51:15 (none) pluto[26118]: | 00 00 70 80 80 0e 01 00 03 00 00 28 0c 01 00 002005:06:16-13:51:15 (none) pluto[26118]: | 80 01 00 07 80 02 00 01 80 03 00 01 80 04 00 052005:06:16-13:51:15 (none) pluto[26118]: | 80 0b 00 01 00 0c 00 04 00 00 70 80 80 0e 01 002005:06:16-13:51:15 (none) pluto[26118]: | 03 00 00 28 0d 01 00 00 80 01 00 07 80 02 00 022005:06:16-13:51:15 (none) pluto[26118]: | 80 03 00 01 80 04 00 05 80 0b 00 01 00 0c 00 042005:06:16-13:51:15 (none) pluto[26118]: | 00 00 70 80 80 0e 00 c0 00 00 00 28 0e 01 00 002005:06:16-13:51:15 (none) pluto[26118]: | 80 01 00 07 80 02 00 01 80 03 00 01 80 04 00 052005:06:16-13:51:15 (none) pluto[26118]: | 80 0b 00 01 00 0c 00 04 00 00 70 80 80 0e 00 c02005:06:16-13:51:15 (none) pluto[26118]: | 0d 00 00 0c da 8e 93 78 80 01 00 00 0d 00 00 0c2005:06:16-13:51:15 (none) pluto[26118]: | 09 00 26 89 df d6 b7 12 0d 00 00 14 7d 94 19 a62005:06:16-13:51:15 (none) pluto[26118]: | 53 10 ca 6f 2c 17 9d 92 15 52 9d 56 0d 00 00 142005:06:16-13:51:15 (none) pluto[26118]: | 90 cb 80 91 3e bb 69 6e 08 63 81 b5 ec 42 7b 1f2005:06:16-13:51:15 (none) pluto[26118]: | 0d 00 00 14 44 85 15 2d 18 b6 bb cd 0b e8 a8 462005:06:16-13:51:15 (none) pluto[26118]: | 95 79 dd cc 0d 00 00 14 4a 13 1c 81 07 03 58 452005:06:16-13:51:15 (none) pluto[26118]: | 5c 57 28 f2 0e 95 45 2f 0d 00 00 14 af ca d7 132005:06:16-13:51:15 (none) pluto[26118]: | 68 a1 f1 c9 6b 86 96 fc 77 57 01 00 0d 00 00 142005:06:16-13:51:15 (none) pluto[26118]: | 10 1f b0 b3 5c 5a 4f 4c 08 b9 19 f1 cb 97 77 af2005:06:16-13:51:15 (none) pluto[26118]: | 00 00 00 14 12 f5 f2 8c 45 71 68 a9 70 2d 9f e22005:06:16-13:51:15 (none) pluto[26118]: | 74 cc 01 002005:06:16-13:51:15 (none) pluto[26118]: | **parse ISAKMP Message:2005:06:16-13:51:15 (none) pluto[26118]: | initiator cookie:2005:06:16-13:51:15 (none) pluto[26118]: | 11 ec a0 34 0f 1b 5e 382005:06:16-13:51:15 (none) pluto[26118]: | responder cookie:2005:06:16-13:51:15 (none) pluto[26118]: | 00 00 00 00 00 00 00 002005:06:16-13:51:15 (none) pluto[26118]: | next payload type: ISAKMP_NEXT_SA2005:06:16-13:51:15 (none) pluto[26118]: | ISAKMP version: ISAKMP Version 1.02005:06:16-13:51:15 (none) pluto[26118]: | exchange type: ISAKMP_XCHG_IDPROT2005:06:16-13:51:15 (none) pluto[26118]: | flags: none2005:06:16-13:51:15 (none) pluto[26118]: | message ID: 00 00 00 002005:06:16-13:51:15 (none) pluto[26118]: | length: 7562005:06:16-13:51:15 (none) pluto[26118]: | ***parse ISAKMP Security Association Payload:2005:06:16-13:51:15 (none) pluto[26118]: | next payload type: ISAKMP_NEXT_VID2005:06:16-13:51:15 (none) pluto[26118]: | length: 5642005:06:16-13:51:15 (none) pluto[26118]: | DOI: ISAKMP_DOI_IPSEC2005:06:16-13:51:15 (none) pluto[26118]: | ***parse ISAKMP Vendor ID Payload:2005:06:16-13:51:15 (none) pluto[26118]: | next payload type: ISAKMP_NEXT_VID2005:06:16-13:51:15 (none) pluto[26118]: | length: 122005:06:16-13:51:15 (none) pluto[26118]: | ***parse ISAKMP Vendor ID Payload:2005:06:16-13:51:15 (none) pluto[26118]: | next payload type: ISAKMP_NEXT_VID2005:06:16-13:51:15 (none) pluto[26118]: | length: 122005:06:16-13:51:15 (none) pluto[26118]: | ***parse ISAKMP Vendor ID Payload:2005:06:16-13:51:15 (none) pluto[26118]: | next payload type: ISAKMP_NEXT_VID2005:06:16-13:51:15 (none) pluto[26118]: | length: 202005:06:16-13:51:15 (none) pluto[26118]: | ***parse ISAKMP Vendor ID Payload:2005:06:16-13:51:15 (none) pluto[26118]: | next payload type: ISAKMP_NEXT_VID2005:06:16-13:51:15 (none) pluto[26118]: | length: 202005:06:16-13:51:15 (none) pluto[26118]: | ***parse ISAKMP Vendor ID Payload:2005:06:16-13:51:15 (none) pluto[26118]: | next payload type: ISAKMP_NEXT_VID2005:06:16-13:51:15 (none) pluto[26118]: | length: 202005:06:16-13:51:15 (none) pluto[26118]: | ***parse ISAKMP Vendor ID Payload:2005:06:16-13:51:15 (none) pluto[26118]: | next payload type: ISAKMP_NEXT_VID2005:06:16-13:51:15 (none) pluto[26118]: | length: 202005:06:16-13:51:15 (none) pluto[26118]: | ***parse ISAKMP Vendor ID Payload:2005:06:16-13:51:15 (none) pluto[26118]: | next payload type: ISAKMP_NEXT_VID2005:06:16-13:51:15 (none) pluto[26118]: | length: 202005:06:16-13:51:15 (none) pluto[26118]: | ***parse ISAKMP Vendor ID Payload:2005:06:16-13:51:15 (none) pluto[26118]: | next payload type: ISAKMP_NEXT_VID2005:06:16-13:51:15 (none) pluto[26118]: | length: 202005:06:16-13:51:15 (none) pluto[26118]: | ***parse ISAKMP Vendor ID Payload:2005:06:16-13:51:15 (none) pluto[26118]: | next payload type: ISAKMP_NEXT_NONE2005:06:16-13:51:15 (none) pluto[26118]: | length: 202005:06:16-13:51:15 (none) pluto[26118]: packet from 192.168.2.96:500: ignoring unknown Vendor ID payload [da8e937880010000]2005:06:16-13:51:15 (none) pluto[26118]: packet from 192.168.2.96:500: received Vendor ID payload [XAUTH]2005:06:16-13:51:15 (none) pluto[26118]: packet from 192.168.2.96:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03] meth=108, but port floating is off2005:06:16-13:51:15 (none) pluto[26118]: packet from 192.168.2.96:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n] meth=106, but port floating is off2005:06:16-13:51:15 (none) pluto[26118]: packet from 192.168.2.96:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]2005:06:16-13:51:15 (none) pluto[26118]: packet from 192.168.2.96:500: received Vendor ID payload [RFC 3947] meth=109, but port floating is off2005:06:16-13:51:15 (none) pluto[26118]: packet from 192.168.2.96:500: received Vendor ID payload [Dead Peer Detection]2005:06:16-13:51:15 (none) pluto[26118]: packet from 192.168.2.96:500: ignoring unknown Vendor ID payload [101fb0b35c5a4f4c08b919f1cb9777af]2005:06:16-13:51:15 (none) pluto[26118]: packet from 192.168.2.96:500: received Vendor ID payload [Cisco-Unity]2005:06:16-13:51:15 (none) pluto[26118]: | find_host_connection called from main_inI1_outR12005:06:16-13:51:15 (none) pluto[26118]: | find_host_pair: comparing to 192.168.6.21:500 0.0.0.0:500 2005:06:16-13:51:15 (none) pluto[26118]: | find_host_pair_conn (find_host_connection2): 192.168.6.21:500 192.168.2.96:500 -> hp:none 2005:06:16-13:51:15 (none) pluto[26118]: | find_host_connection called from main_inI1_outR12005:06:16-13:51:15 (none) pluto[26118]: | find_host_pair: comparing to 192.168.6.21:500 0.0.0.0:500 2005:06:16-13:51:15 (none) pluto[26118]: | find_host_pair_conn (find_host_connection2): 192.168.6.21:500 %any:500 -> hp:S_roadie_0 2005:06:16-13:51:15 (none) pluto[26118]: | alg_info_addref() alg_info->ref_cnt=32005:06:16-13:51:15 (none) pluto[26118]: | alg_info_addref() alg_info->ref_cnt=32005:06:16-13:51:15 (none) pluto[26118]: | alg_info_addref() alg_info->ref_cnt=42005:06:16-13:51:15 (none) pluto[26118]: | alg_info_addref() alg_info->ref_cnt=42005:06:16-13:51:15 (none) pluto[26118]: | find_host_pair: comparing to 192.168.6.21:500 0.0.0.0:500 2005:06:16-13:51:15 (none) pluto[26118]: | connect_to_host_pair: 192.168.6.21:500 192.168.2.96:500 -> hp:none 2005:06:16-13:51:15 (none) pluto[26118]: | instantiated "S_roadie_0" for 192.168.2.962005:06:16-13:51:15 (none) pluto[26118]: | creating state object #1 at 0x81142882005:06:16-13:51:15 (none) pluto[26118]: | processing connection S_roadie_0[1] 192.168.2.962005:06:16-13:51:15 (none) pluto[26118]: | ICOOKIE: 11 ec a0 34 0f 1b 5e 382005:06:16-13:51:15 (none) pluto[26118]: | RCOOKIE: d2 2a 6b e0 16 38 c1 2f2005:06:16-13:51:15 (none) pluto[26118]: | peer: c0 a8 02 602005:06:16-13:51:15 (none) pluto[26118]: | state hash entry 42005:06:16-13:51:15 (none) pluto[26118]: | inserting event EVENT_SO_DISCARD, timeout in 0 seconds for #12005:06:16-13:51:15 (none) pluto[26118]: "S_roadie_0"[1] 192.168.2.96 #1: responding to Main Mode from unknown peer 192.168.2.962005:06:16-13:51:15 (none) pluto[26118]: | **emit ISAKMP Message:2005:06:16-13:51:15 (none) pluto[26118]: | initiator cookie:2005:06:16-13:51:15 (none) pluto[26118]: | 11 ec a0 34 0f 1b 5e 382005:06:16-13:51:15 (none) pluto[26118]: | responder cookie:2005:06:16-13:51:15 (none) pluto[26118]: | d2 2a 6b e0 16 38 c1 2f2005:06:16-13:51:15 (none) pluto[26118]: | next payload type: ISAKMP_NEXT_SA2005:06:16-13:51:15 (none) pluto[26118]: | ISAKMP version: ISAKMP Version 1.02005:06:16-13:51:15 (none) pluto[26118]: | exchange type: ISAKMP_XCHG_IDPROT2005:06:16-13:51:15 (none) pluto[26118]: | flags: none2005:06:16-13:51:15 (none) pluto[26118]: | message ID: 00 00 00 002005:06:16-13:51:15 (none) pluto[26118]: | ***emit ISAKMP Security Association Payload:2005:06:16-13:51:15 (none) pluto[26118]: | next payload type: ISAKMP_NEXT_VID2005:06:16-13:51:15 (none) pluto[26118]: | DOI: ISAKMP_DOI_IPSEC
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -