Alberto Fabiano | 2 Oct 2003 13:58
Picon

RES: FreeSWAN CA 2.02 x PIX - Trouble in phase 2

Hi Jean-Francois,

	I already made some experiences, but now I verified that the trouble there
is in the following point:

	- ignoring informational payload, type NO_PROPOSAL_CHOSEN

	- max number of retransmissions (2) reached STATE_QUICK_I1.  No acceptable
response to our first Quick Mode message: perhaps peer likes no proposal

      I found several references on this message (some 18 in Google) but up
to now I didn't get to identify indeed what is, maybe for my poor experience
with FreeSWAN.

	Thankful to all for the helps, but I still seek a light! :-)

Att.
[]´s++

./alberto -fabiano

> -----Mensagem original-----
> De: Jean-Francois Dive [mailto:jef <at> linuxbe.org]
> Enviada em: terça-feira, 30 de setembro de 2003 08:02
> Para: Alberto Fabiano
> Cc: Vpn
> Assunto: Re: [VPN] FreeSWAN CA 2.02 x PIX - Trouble in phase 2
>
>
> you dont see the answer from the PIX, sounds like the problem is in the
(Continue reading)

Jean-Francois Dive | 2 Oct 2003 15:44

Re: RES: FreeSWAN CA 2.02 x PIX - Trouble in phase 2

well yes, so you need to set both side to appropriate settings. Check
algorithms, protocols and selectors, they must match exactly (well lets
say exactly) to get the negociation to suceed. The debugs on the PIX
should show you the proposals. 

Again, if you want you should send your PIX ipsec config and freeswan
ipsec.conf file and one should be able to see what's not correctly
configured.

J.

On Thu, 2003-10-02 at 13:58, Alberto Fabiano wrote:
> Hi Jean-Francois,
> 
> 	I already made some experiences, but now I verified that the trouble there
> is in the following point:
> 
> 	- ignoring informational payload, type NO_PROPOSAL_CHOSEN
> 
> 	- max number of retransmissions (2) reached STATE_QUICK_I1.  No acceptable
> response to our first Quick Mode message: perhaps peer likes no proposal
> 
>       I found several references on this message (some 18 in Google) but up
> to now I didn't get to identify indeed what is, maybe for my poor experience
> with FreeSWAN.
> 
> 	Thankful to all for the helps, but I still seek a light! :-)
> 
> 
> Att.
(Continue reading)


Gmane