AW: [suse-security] VPN with IPsec (FreeSwan) and Windows 2000 Cl ient
Hi,
I tried to setup a VPN tunnel. My VPN Gateway is based on SuSE 8.0 and FreeSwan 1.98b shipped with the distribution.
I followed my installation instruction found via google for the gateway. Authorisation should be realized with x509 certificates. My VPN Gateway starts with rcipsec start and a rcipsec status told me,
ipsec is active.
I´ve created a p12 certificate for my windows 2000 client and installed
Hi, I solved the problem. In my conn Roadwarrior I have changed the value for network=both to network=lan. Now ipsec on my w2k client starts without errors. How can I test the vpn tunnel ? I have made a tcpdump -n -i ipsec0 on my gateway and a ping from my client to the gateway. The ping works fine, but there were no packets detected with tcpdump. Best regards Stefan -----Ursprüngliche Nachricht----- Von: Andreas Baetz [mailto:lac01@web.de] Gesendet: Donnerstag, 13. März 2003 13:16 An: suse-security@suse.com Betreff: Re: [suse-security] VPN with IPsec (FreeSwan) and Windows 2000 Client On Thursday 13 March 2003 12:55, Junge, Stefan wrote: that the
additional software from Marcus Müller.
Now, when I´m starting ipsec on my w2k client the following message occurs :
IPSec Version 2.1.4 .... Getting running Config ... Microsoft´s Windows 2000 identified Host name is : P0741099 No RAS connections found. LAN IP address : 192.168.150.2 Setting up IPsec ...
Deactivatin old policy... Removing old policy...
Connection VPNTEST: Could not identify my own Interface below you show the conn "Raodwarrior", what is the configuration of conn VPNTEST ?
My ipsec.conf placed in C:\programme\ipsec contains conn Roadwarrior left=%any right=192.168.150.1 rightsubnet=192.168.150.1/255.255.255.0 rightca="...." network=both auto=start pfs=yes
Andreas Baetz -- Check the headers for your unsubscription address For additional commands, e-mail: suse-security-help@suse.com Security-related bug reports go to security@suse.de, not here
On Thursday 13 March 2003 13:33, Junge, Stefan wrote:
Hi,
I solved the problem. In my conn Roadwarrior I have changed the value for network=both to network=lan.
Now ipsec on my w2k client starts without errors.
How can I test the vpn tunnel ? I have made a tcpdump -n -i ipsec0 on my gateway and a ping from my client to the gateway. The ping works fine, but there were no packets detected with tcpdump. You should see the decoded packets on ipsec0 (if that is your tunnel if) and the encrypted packets with proto 50 on eth0 (if that is your lan if).
On the linux side you can use "ipsec look" to check if there is a tunnel, and you could turn on logging, e.g. with plutodebug="emitting parsing control" in /etc/ipsec.conf (restart ipsec after that) On the w2k side you can use "ipsecmon" to check if there is a tunnel. Andreas Baetz
participants (2)
-
Andreas Baetz
-
Junge, Stefan