VPN setup problem

I have installed Snow Leopard Server on a new XServe. I have updated to 10.6.2.
Other services are working Related to VPN I have configured the VPN Service using L2TP.
I have no additional network routing defined.
Every time I try to setup a connection (from my macbook pro --> running snow leopard 10.6.2) I get the following log messages:
2009-11-15 14:44:41 CET Incoming call... Address given to client = 192.168.1.160
Sun Nov 15 14:44:41 2009 : Directory Services Authentication plugin initialized
Sun Nov 15 14:44:41 2009 : Directory Services Authorization plugin initialized
Sun Nov 15 14:44:41 2009 : L2TP incoming call in progress from '192.168.1.15'...
Sun Nov 15 14:44:41 2009 : L2TP received SCCRQ
Sun Nov 15 14:44:41 2009 : L2TP sent SCCRP
Sun Nov 15 14:44:41 2009 : L2TP received SCCCN
Sun Nov 15 14:44:41 2009 : L2TP received ICRQ
Sun Nov 15 14:44:41 2009 : L2TP sent ICRP
Sun Nov 15 14:44:41 2009 : L2TP received ICCN
Sun Nov 15 14:44:41 2009 : L2TP connection established.
Sun Nov 15 14:44:41 2009 : using link 0
Sun Nov 15 14:44:41 2009 : Using interface ppp0
Sun Nov 15 14:44:41 2009 : Connect: ppp0 <--> socket[34:18]
Sun Nov 15 14:44:41 2009 : sent [LCP ConfReq id=0x1 <asyncmap 0x0> <auth eap> <magic 0x7dd4d1cd> <pcomp> <accomp>]
Sun Nov 15 14:44:41 2009 : rcvd [LCP ConfReq id=0x1 <asyncmap 0x0> <magic 0x1e217556> <pcomp> <accomp>]
Sun Nov 15 14:44:41 2009 : lcp_reqci: returning CONFACK.
Sun Nov 15 14:44:41 2009 : sent [LCP ConfAck id=0x1 <asyncmap 0x0> <magic 0x1e217556> <pcomp> <accomp>]
Sun Nov 15 14:44:41 2009 : rcvd [LCP ConfAck id=0x1 <asyncmap 0x0> <auth eap> <magic 0x7dd4d1cd> <pcomp> <accomp>]
Sun Nov 15 14:44:41 2009 : sent [LCP EchoReq id=0x0 magic=0x7dd4d1cd]
Sun Nov 15 14:44:41 2009 : sent [EAP Request id=0x1 Identity ]
Sun Nov 15 14:44:41 2009 : rcvd [LCP EchoReq id=0x0 magic=0x1e217556]
Sun Nov 15 14:44:41 2009 : sent [LCP EchoRep id=0x0 magic=0x7dd4d1cd]
Sun Nov 15 14:44:41 2009 : rcvd [LCP EchoRep id=0x0 magic=0x1e217556]
Sun Nov 15 14:44:41 2009 : rcvd [EAP Response id=0x1 Identity <"]
Sun Nov 15 14:44:47 2009 : LCP terminated by peer (Failed to authenticate ourselves to peer)
Sun Nov 15 14:44:47 2009 : sent [LCP TermAck id=0x2]
Sun Nov 15 14:44:47 2009 : L2TP received CDN
Sun Nov 15 14:44:47 2009 : Connection terminated.
Sun Nov 15 14:44:47 2009 : L2TP disconnecting...
Sun Nov 15 14:44:47 2009 : L2TP sent CDN
Sun Nov 15 14:44:47 2009 : L2TP sent StopCCN
Sun Nov 15 14:44:47 2009 : L2TP disconnected
2009-11-15 14:44:47 CET --> Client with address = 192.168.1.160 has hungup
What does that mean:
"Failed to authenticate ourselves to peer" ???
Are there some configurations which can solve this problem ???
Best regards
Andreas

This are the related client side log entries:
Sun Nov 15 14:44:40 2009 : L2TP connecting to server '192.168.1.10' (192.168.1.10)...
Sun Nov 15 14:44:40 2009 : IPSec connection started
Sun Nov 15 14:44:40 2009 : IPSec phase 1 client started
Sun Nov 15 14:44:40 2009 : IPSec phase 1 server replied
Sun Nov 15 14:44:41 2009 : IPSec phase 2 started
Sun Nov 15 14:44:41 2009 : IPSec phase 2 established
Sun Nov 15 14:44:41 2009 : IPSec connection established
Sun Nov 15 14:44:41 2009 : L2TP sent SCCRQ
Sun Nov 15 14:44:41 2009 : L2TP received SCCRP
Sun Nov 15 14:44:41 2009 : L2TP sent SCCCN
Sun Nov 15 14:44:41 2009 : L2TP sent IRCQ
Sun Nov 15 14:44:41 2009 : L2TP received ICRP
Sun Nov 15 14:44:41 2009 : L2TP sent ICCN
Sun Nov 15 14:44:41 2009 : L2TP connection established.
Sun Nov 15 14:44:41 2009 : using link 0
Sun Nov 15 14:44:41 2009 : Using interface ppp0
Sun Nov 15 14:44:41 2009 : Connect: ppp0 <--> socket[34:18]
Sun Nov 15 14:44:41 2009 : sent [LCP ConfReq id=0x1 <asyncmap 0x0> <magic 0x1e217556> <pcomp> <accomp>]
Sun Nov 15 14:44:41 2009 : rcvd [LCP ConfReq id=0x1 <asyncmap 0x0> <auth eap> <magic 0x7dd4d1cd> <pcomp> <accomp>]
Sun Nov 15 14:44:41 2009 : lcp_reqci: returning CONFACK.
Sun Nov 15 14:44:41 2009 : sent [LCP ConfAck id=0x1 <asyncmap 0x0> <auth eap> <magic 0x7dd4d1cd> <pcomp> <accomp>]
Sun Nov 15 14:44:41 2009 : rcvd [LCP ConfAck id=0x1 <asyncmap 0x0> <magic 0x1e217556> <pcomp> <accomp>]
Sun Nov 15 14:44:41 2009 : sent [LCP EchoReq id=0x0 magic=0x1e217556]
Sun Nov 15 14:44:41 2009 : rcvd [LCP EchoReq id=0x0 magic=0x7dd4d1cd]
Sun Nov 15 14:44:41 2009 : sent [LCP EchoRep id=0x0 magic=0x1e217556]
Sun Nov 15 14:44:41 2009 : rcvd [EAP Request id=0x1 Identity ]
Sun Nov 15 14:44:41 2009 : sent [EAP Response id=0x1 Identity <"]
Sun Nov 15 14:44:47 2009 : Connection terminated.
Sun Nov 15 14:44:47 2009 : rcvd [EAP Request id=0x2 EAP KRB <00003f000001000101>]
Sun Nov 15 14:44:47 2009 : L2TP disconnecting...
Sun Nov 15 14:44:47 2009 : L2TP sent CDN
Sun Nov 15 14:44:47 2009 : L2TP sent StopCCN
Sun Nov 15 14:44:47 2009 : L2TP disconnected

Similar Messages

  • I do not see where to enter IP addresses in the Open VPN setup. Also, how can I set it up so that I can choose different servers in the same way as I can currently choose them with my VPN app but for PPTP?

    I think I have it working on my iPhone 5. But, I do not see how I can control the exit point that I would like for the VPN. Are all the exit points shown in the VPN setting now going to work with Open VPN, or do they remain PPTP? If I am reading correctly, they look like they remain PPTP. If I cannot control the exit point for open VPN, which exit point is the default in the profile you provided me?I note that Open VPN Connect does not work with any of the new 64 bit devices like the iPhone 5S, the iPad Air, and the new iPad MIni. Is there any chance that you guys will come up with an update for your app so that open VPN can be made to work on all iOS devices? That would be nice, particularly if the Open VPN Connect app does not give me a choice of exit points.Thanks,
    I do not see where to enter IP addresses in the Open VPN setup. Also, how can I set it up so that I can choose different servers in the same way as I can currently choose them with my VPN app but for PPTP?
    Just a quick note to tell you that Open VPN has updated their app so that it is compatible with 64 bit ARM devices like the iPhone 5S, the iPad Air, and the iPad Mini Retina.That does not resolve the problem of how to easily choose among the various possibilities for the exit server. We need to find an easy way to choose.

    Thank you for trying the new Firefox. I'm sorry that you’re unhappy with the new design.
    I understand your frustration and surprise at the removal of these features but I can't undo these changes. I'm just a support volunteer and I do not work for Mozilla. But you can send any feedback about these changes to http://input.mozilla.org/feedback. Firefox developers collect data submitted through there then present it at the weekly Firefox meeting
    I recommend you try to adjust to 29 and see if you can't make it work for you before you downgrade to a less secure and soon outdated version of Firefox.
    Here are a few suggestions for restoring the old design. I hope you’ll find one that works for you:
    *Use the [https://addons.mozilla.org/en-US/firefox/addon/classicthemerestorer/ Classic Theme Restorer] to bring back the old design. Learn more here: [[How to make the new Firefox look like the old Firefox]]
    *Use the [https://addons.mozilla.org/en-US/firefox/addon/the-addon-bar/ Add-on Bar Restored] to bring back the add-on bar. Learn more here: [[What happened to the Add-on Bar?]]

  • Out of ideas diagnosing VPN connection problems

    I'm having trouble narrowing down what's causing the VPN connection problems to my new Mini Server. Sometimes I can connect just fine with my MacBookPro and use all the resources like file sharing, etc. So, this leads me to believe it has been setup correctly. But then, for no reason at all (maybe it's later in the same day, or a completely different day) it will just stop working and I cannot connect at all.
    *MacBook and iMac at home cannot connect, but iPhone can*
    This is what's really throwing me off. This afternoon, I cannot connect to the server from home with my MacBook or my iMac. BUT, my iPhone can -using the same WiFi network my computers are on, not the cellular network. How could that be? The VPN settings on all 3 devices match exactly.
    *Colleagues with other ISP's can connect, while I cannot*
    I've called Comcast business (which provides the static IP for our office server) and they tell me all my settings are correct for allowing VPN traffic through. Likewise, Comcast Residential tells me there is nothing that would block VPN traffic from my home. They tell me to talk with Apple. argh!
    *Web and Server Admin services are still accessible when VPN is not working*
    We have exposed the Server's Web and Admin services without needing a VPN connection to access them. Since these services are accessible to me even when the VPN is not working, this leads me to believe the server is operating normally and capable of receiving incoming traffic.
    I'm out of ideas and I'm starting to lose my mind!!! Any ideas on why my 2 computers sometimes can connect, yet sometimes cannot...all the while, my iPhone can connect just fine over the same network???

    I don't have an explanation for the erratic nature of your connections. It's only as I've said before, in my experiences with such problems it has always traced back to misconfigured network or DNS settings. mDNS is multicast DNS and it's a protocol Apple uses so its devices can find each other easily. That may be the reason why your iPhone can connect when other things can't.
    To take a step back, here is how I think things should be set up:
    \- Your dedicated IP address should be assigned to your router automatically through PPPoE
    \- The name servers as set in your router should be your ISP's name servers
    \- Make sure the server has only one connection to the router that is managing the dedicated IP, either wired or wireless, but not both
    \- A static network address should be assigned to your server's MAC address in the router's DHCP settings
    \- The server's network address should be put in the DMZ on the router or set as the default server in the NAT settings, depending on the router
    \- The network settings in System Preferences on the server should be set to DHCP with manual address and the server's network address entered correctly
    \- The router address should be listed correctly in the network settings in System Preferences on the server
    \- The name servers in the network settings in System Preferences on the server should be 127.0.0.1 and the router's IP address, nothing else.
    \- The zone files on the server should have a primary and reverse zone for each domain name and its network address. Do not use the dedicated IP address in the zone files on the server.
    If everything is set as I described, it should work. If it doesn't, it's time to call a witch doctor or an exorcist.

  • I need to upgrade my 10.5.1 os on my G4/1.25 (I'm having some audio-midi setup problems), but it's a machine that is not connected to the internet.  Do I have any options?  Thanks!

    Friends,
    I'm having some audio-midi setup problems on my G4/1.25/10.5.1 machine.  I'm thinking that a routine OS upgrade might help.  However, this machine is not connected to the internet.  Are there any alternate methods for upgrading system software?  Thanks in advance!

    OK, what you should do is download the updates on another machine and burn them to a disc.  Start at this link http://support.apple.com/downloads/#leopard for downloads and find, among other things, the 10.5.8 combo updater that works on PPC machines, plus security, QuickTime and other updates.  Going from 10.5.1 to 10.5.8, there will probably be a bunch of things that you should install.  Being off the internet with the machine, you can't have Software Update sort it out, so something might get missed, unfortunately.
    My suggestion is this: if it looks like you might need a download, get it onto that disc.

  • Remote Access VPN Setup

    Hello Support,
    I have a question regarding a remote access VPN setup with the following. I have a Cisco 6500 with multiple VLANs, and an FWSM setup in mutliple context mode. Each of our clients sits behind their own context, and has their own associated VLANs. Each context has a shared interface, so that one network (our management network) can see all of the networks. We are using a Cisco ASA to terminate P2P VPNs as the FWSms cannot do so, but I would like to setup a remote access VPN from the ASA, but I will need to connect in and have access to all networks. Currently the ASA has an outside interface for internet, two client inside interfaces, and one interface on the shared network.
    If I setup a remote access VPN from the ASA with a separate scope will I be able to see all the networks that I setup routes and nonats for or is there more to it?
    I provided a brief diagram showing all the vlans, I will need to be able to access all of the 6500s vlans when connected using the VPN.
    Thanks in advance for all ideas, suggestions, and assistance.

    Hello John,
    You will need to configure the respective IP Address pool for the Anyconnect users,
    Then create the no_nat rules from all of the internal subnets to the Anyconnect Pool.
    That should do it bud . I mean just make sure the internal network (core) knows that in order to reach the anyconnect pool must send the traffic to the ASA.
    Rate all of the helpful posts!!!
    Regards,
    Jcarvaja
    Follow me on http://laguiadelnetworking.com

  • Setup problem, windows xp, firefox upgrade to 4 and asked to reboot but did not progress. keeps asking to restart even if I try to remove

    setup problem, windows xp, firefox upgrade to 4 and asked to reboot but did not progress. keeps asking to restart even if I try to remove

    Hi marsano,
    Usually the only reason it will ask you to reboot is if there is a file that must be modified that the updater doesn't currently have access to. You should try running the Firefox program once as Administrator:
    * Right-click the icon and choose ''Run as Administrator''
    If that doesn't help then do a clean reinstall.
    # Download a fresh copy of Firefox from the [http://www.mozilla.org/firefox/fx/ Mozilla download page] and save the file to the desktop.
    # [[Uninstalling Firefox|Uninstall]] your current version of Firefox and remove the Firefox program folder before running the new installer.
    # Run installer
    Remember that you don't want to remove personal data when uninstalling. That way you'll still have your personal information.
    Hopefully this helps!

  • Simple VISA Setup Problem

    Hi all,
    I'm having issues working with VISA in LabVIEW. Previously, I've used Peek/Poke VIs (before they were VISA VIs) that allowed me to read and write directly to registers at a given Windows address. I have a new, custom PCI Express board that uses the same architecture that I've worked with previously only this time I'm trying to access the registers using VISA.
    As this is my first time using VISA, I'm having some setup problems. Yesterday I got to a state where logically things should work but I still end up getting an error when I try to run a simple VISA Open command (see attached screenshot).
    The initial problem I had was I was not able to acquire a VISA resource that opens a session to my PCIe board...it would simply not show up on the resource list. After reading around I discovered I needed to create a custom VISA driver for my board. Once I did that using the VISA Driver Wizard, the device showed up in my list (as seen in the screenshot). I wrote the simplest of all VIs where I simply open that VISA resource, however, the error seen in the screenshot is produced.
    I'm pretty sure this is a simple setup issue, but does anyone know what I'm doing wrong?
    Attachments:
    Screenshot1.JPG ‏145 KB

    Hi bonhomme,
    I see you're having some issues using VISA. It sounds like you're new to VISA, so I wanted to pass along some information that we have availble on this software. This link gives good general information about VISA, and the related links are extremely helpful in finding specific issues.
    Thank you for attaching your error. This is extremely helpful in debugging since we can actually see the numbers. There is another forumn that talks about these at this link and at this link. 
    Hope this helps you out!!
    Lea D.
    Applications Engineering
    National Instruments

  • CDC setup problem

    {noformat}Dear all,{noformat}{noformat}Trying to troubleshoot a CDC setup problem in ODI:{noformat}{noformat}I got an error when trying to "Start Journal" from the CDC source model (in Designer).{noformat}{noformat}Here is what I've done:{noformat}{noformat}1. grant the following role to the CDC source schema (user):{noformat}{noformat}DBA, execute on DBMS_CDC_PUBLISH, connect, resource, select_on_change_sets, create session, select_catalog_role, execute_catalog_role, create sequence{noformat}{noformat}2. in the CDC source model "Journalizing" tab, specify JKM 9i logminer (CDC source is on 9i) and specify "Automatic Configuration"{noformat}{noformat}3. add a subscriber "SUNOPSIS" to the source model -&gt; Changed Data Capture (Operator successfully run){noformat}{noformat}4. "add to CDC" from source model -&gt; Changed Data Capture{noformat}{noformat}5. "Start Journal" from source model -&gt; Changed Data Capture (Operator run failed with the following errors in the "create Journal" step){noformat}{noformat}
    30475 : 99999 : java.sql.BatchUpdateException: ORA-30475: feature not enabled:
    ORA-06512: at "SYS.DBMS_CDC_PUBLISH", line 298
    ORA-06512: at line 1
    30475 : 99999 : java.sql.SQLException: ORA-30475: feature not enabled:
    ORA-06512: at "SYS.DBMS_CDC_PUBLISH", line 298
    ORA-06512: at line 1
    java.sql.BatchUpdateException: ORA-30475: feature not enabled:
    ORA-06512: at "SYS.DBMS_CDC_PUBLISH", line 298
    ORA-06512: at line 1
    at oracle.jdbc.driver.DatabaseError.throwBatchUpdateException(DatabaseError.java:367)
    at oracle.jdbc.driver.OraclePreparedStatement.executeBatch(OraclePreparedStatement.java:9119)
    at com.sunopsis.sql.SnpsQuery.executeBatch(SnpsQuery.java)
    at com.sunopsis.dwg.dbobj.SnpSessTaskSql.execCollOrders(SnpSessTaskSql.java)
    at com.sunopsis.dwg.dbobj.SnpSessTaskSql.treatTaskTrt(SnpSessTaskSql.java)
    at com.sunopsis.dwg.dbobj.SnpSessTaskSqlC.treatTaskTrt(SnpSessTaskSqlC.java)
    at com.sunopsis.dwg.dbobj.SnpSessTaskSql.treatTask(SnpSessTaskSql.java)
    at com.sunopsis.dwg.dbobj.SnpSessStep.treatSessStep(SnpSessStep.java)
    at com.sunopsis.dwg.dbobj.SnpSession.treatSession(SnpSession.java)
    {noformat}{noformat}Any idea?{noformat}{noformat} {noformat}{noformat}William Lam
    {noformat}

    Hi Cezar,
    Thanks for following up. Below is from the description tab of the "Create Journal" steps:
    LOADING:
    select     FULL_TABLE_NAME     FULL_TABLE_NAME
    from     CDCSRC.SNP_TMP_TABLE_LIST     TMP
    where     TMP.FULL_TABLE_NAME = 'CDCSRC.DEPT'
    and     not exists      (
              select     'X'
              from     CDCSRC.SNP_CDC_OBJECTS     OBJ,
                   CDCSRC.SNP_CDC_SET_TABLE     TBL
              where     TBL.FULL_TABLE_NAME          = OBJ.FULL_TABLE_NAME
              and     TBL.FULL_TABLE_NAME          = TMP.FULL_TABLE_NAME
              and     TBL.CDC_SET_NAME          = 'CDCSRC.CDCSRC'
              and     OBJ.FULL_OBJECT_NAME     = 'CDCSRC.J$DEPT'
              and     OBJ.CDC_OBJECT_TYPE          = 'JRN_FULL_NAME'
    DEFAULT:
    BEGIN
         DBMS_LOGMNR_CDC_PUBLISH.CREATE_CHANGE_TABLE(
         owner          => 'CDCSRC',
         change_table_name     => 'J$DEPT',
         change_set_name     => 'SYNC_SET',
         source_schema     => 'CDCSRC',
         source_table     => 'DEPT',
         column_type_list     => 'DEPTNO NUMBER(2) ',
         capture_values     => 'new',
         rs_id          => 'n',
         row_id          => 'n',
         user_id          => 'n',
         timestamp          => 'y',
         object_id          => 'n',
         source_colmap     => 'n',
         target_colmap     => 'n',
         options_string     => ''
    END;
    The error message from the Execution Tab:
    30475 : 99999 : java.sql.BatchUpdateException: ORA-30475: feature not enabled:
    ORA-06512: at "SYS.DBMS_CDC_PUBLISH", line 298
    ORA-06512: at line 1
    30475 : 99999 : java.sql.SQLException: ORA-30475: feature not enabled:
    ORA-06512: at "SYS.DBMS_CDC_PUBLISH", line 298
    ORA-06512: at line 1
    java.sql.BatchUpdateException: ORA-30475: feature not enabled:
    ORA-06512: at "SYS.DBMS_CDC_PUBLISH", line 298
    ORA-06512: at line 1
    Once again, the setup details:
    - CDC source is on Oracle 9i
    - KM used is Oracle 9i LogMiner
    - enabled archivelog in Oracle 9i
    - installed logminer by running the 2 sqls as described in the earlier tread.
    I need to meet a tight deadline for POC completion and I desparate need some help here.
    Thanks and regards,
    William

  • To run VPN setup my iphone is requesting for 4 digit pass code ... can you pls assisit?

    To run VPN setup my iphone is requesting for 4 digit pass code ... can you pls assisit?

    Hello RozR,
    We've an article that can help circumvent the new passcode and restore access to your iPhone.
    iOS: Forgotten passcode or device disabled after entering wrong passcode
    http://support.apple.com/kb/HT1212
    Cheers,
    Allen

  • RV120W VPN Setup - basic help needed

    Hi all,
    I've recently bought a RV 120W Wireless-N VPN Firewall hoping it would ease me in creating VPN and remote connectivity. But I seems to be struggling with this.
    Here is my situation.
    When I bought my Cisco router I didn't know it had an ethernet port for WAN. I thought it would have a RJ11 compliant port. So now I am having to put the router behind my modem.
    I gave my modem's LAN 192.168.2.1 and to RV120W I gave 192.168.2.2.
    All PC's are not connected to internet via RV120W. For RV120W, the local IP network is 192.168.1.0. I've set 192.168.1.1 as the management IP of the Cisco RV120W. All the PC's can get internet from the above layout arrangement.
    With frustration, I've portforwared all my ports on the modem (except 1 port) to RV120W i.e to IP 192.168.2.2.
    If I enable PPTP on RV120W I can ping its port (1723 i remember) from outside. If I connect to port 80 from outside my network, I can get the managemnt interface of the RV120W.
    With the help of the RV120W's userguide I managed to create VPN policy stuff via the 'basic VPN Setup' menu. The guides says to use a wizard but there is no wizard for VPN setup.
    With that I have even created users (of every type) but I just can't make the connection.
    When I use the QuickVPN to connect... its goes from "Connecting", "Activating Policy" again "Connecting" and then a big error saying a couple of things that might have caused the error.
    I want to start from the beginning.
    Can somebody please help me.
    First... what I am I supposed to put in the fields of the following screenshot. Especially the fields "Remote WAN's IP Address", "Local WAN's IP Address" and "Local LAN IP Address".

    Once I knew about the bridge mode thing from this discussion, I started reading the manual of the modem in regard to the brigde mode setup.
    According to the manual, the 'Data' bulb on the modem would be off if the modem is in bridge mode. and I've successfully put the modem on bridge mode I guess. It was pretty easy. I just deleted all the WAN setup rules/configs and began with the initial setup wizard which basically had the option to set the modem to bridge mode. After so, the 'Data' bulb got off meaning the modem is now in bridge mode. I am happy about that
    But... still not done.
    I put one ethernet cable into of the LAN ports of the modem and put the other end in RV120W WAN port. Logged into to RV120W, configured new PPPoE profile (I have the user and pass details) and attached it to the WAN internet setup config.
    I went back to the dashboard of RV120W to see if WAN was up. It didn't. I gave some time. It didn't work. It says 'connecting' but never connects.
    What am I doing wrong? Am I putting the cable between the modem and router the right way?
    ...and also, when the modem is in bridge mode will it forward all packets from lan to wan and vice versa or is it like forwarding packets to all ports once recieved.
    (I am learning so much with this RV120W )

  • Simple VPN Setup Fails with "NOTIFY PROPOSAL_NOT_CHOSEN protocol"

    Hi,
    This is pulling my hair out! Must be overlooking something very simple!
    Simple lab setup with 3 routers. VPN setup between R1 & R3 with static routing. R2 connects R1 & R3. All interfaces are reachable, including loopbacks. I am trying to encrypt traffic between loopback on R1 (69.69.69.69) to loopback on R3 (192.168.100.223).
    With no Crypto Map applied to outgoing interfaces on R1 and R3 ping is successful (sourced via local loopback) between the loopbacks. As soon as I add the Crypto Map the same ping fails and and I get the following debug messages.
    When ping initiated via outgoing interface, ping successful!
    *Oct  6 11:44:26.121: ISAKMP: set new node 0 to QM_IDLE
    *Oct  6 11:44:26.125: SA has outstanding requests  (local 103.13.216.8 port 500, remote 103.13.215.236 port 500)
    *Oct  6 11:44:26.129: ISAKMP:(1002): sitting IDLE. Starting QM immediately (QM_IDLE      )
    *Oct  6 11:44:26.133: ISAKMP:(1002):beginning Quick Mode exchange, M-ID of -1381344893
    *Oct  6 11:44:26.137: ISAKMP:(1002):QM Initiator gets spi
    *Oct  6 11:44:26.145: ISAKMP:(1002): sending packet to 172.1.1.1 my_port 500 peer_port 500 (I) QM_IDLE
    *Oct  6 11:44:26.145: ISAKMP:(1002):Sending an IKE IPv4 Packet.
    *Oct  6 11:44:26.149: ISAKMP:(1002):Node -1381344893, Input = IKE_MESG_INTERNAL, IKE_INIT_QM
    *Oct  6 11:44:26.153: ISAKMP:(1002):Old State = IKE_QM_READY  New State = IKE_QM_I_QM1
    *Oct  6 11:44:26.301: ISAKMP (0:1002): received packet from 172.1.1.1 dport 500 sport 500 Global (I) QM_IDLE
    *Oct  6 11:44:26.305: ISAKMP: set new node -1825528760 to QM_IDLE
    *Oct  6 11:44:26.313: ISAKMP:(1002): processing HASH payload. message ID = -1825528760
    *Oct  6 11:44:26.317: ISAKMP:(1002): processing NOTIFY PROPOSAL_NOT_CHOSEN protocol 3
            spi 2376679447, message ID = -1825528760, sa = 670DD6A4
    *Oct  6 11:44:26.317: ISAKMP:(1002): deleting spi 2376679447 message ID = -1381344893
    *Oct  6 11:44:26.321: ISAKMP:(1002):deleting node -1381344893 error TRUE reason "Delete Larval"
    *Oct  6 11:44:26.325: ISAKMP:(1002):deleting node -1825528760 error FALSE reason "Informational (in) state 1"
    *Oct  6 11:44:26.329: ISAKMP:(1002):Input = IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY
    *Oct  6 11:44:26.329: ISAKMP:(1002):Old State = IKE_P1_COMPLETE  New State = IKE_P1_COMPLETE
    R1
    crypto isakmp policy 1
    authentication pre-share
    crypto isakmp key cisco address 172.1.1.1
    crypto ipsec transform-set TEST esp-3des esp-sha-hmac
    crypto map CRYPTO 1 ipsec-isakmp
    description IPSec Peer to R3
    set peer 172.1.1.1
    set transform-set TEST
    match address ACL1
    interface GigabitEthernet1/0
    ip address 192.250.156.6 255.255.255.0
    no ip route-cache cef
    no ip route-cache
    negotiation auto
    crypto map CRYPTO
    ip access-list extended ACL1
    permit ip host 69.69.69.69 host 192.168.100.223
    R1#sh crypto isakmp sa
    IPv4 Crypto ISAKMP SA
    dst             src             state          conn-id slot status
    172.1.1.1       192.250.156.6   QM_IDLE           1002    0 ACTIVE
    R3
    crypto isakmp policy 1
    authentication pre-share
    crypto isakmp key cisco address 192.250.156.6
    crypto ipsec transform-set TEST esp-3des esp-sha-hmac
    crypto map TEST 1 ipsec-isakmp
    description Primary IPSec Peer to R1
    set peer 192.250.156.6
    set transform-set TEST
    match address ACL1
    interface GigabitEthernet1/0
    ip address 172.1.1.1 255.255.255.0
    no ip route-cache cef
    no ip route-cache
    negotiation auto
    crypto map CRYPTO
    ip access-list extended ACL1
    permit ip host 192.168.100.223 host 69.69.69.69
    R3#sh crypto isakmp sa
    IPv4 Crypto ISAKMP SA
    dst             src             state          conn-id slot status
    172.1.1.1       192.250.156.6   QM_IDLE           1002    0 ACTIVE
    Any help appreciated,
    Thanks.

    Hi Paul,
    "processing NOTIFY PROPOSAL_NOT_CHOSEN protocol 3" indicates the remote VPN peer rejected the phase 2 proposal.
    The configuration snippet you have shared here seems fine, ISAKMP and IPSec debugs (debug crypto isakmp and debug crypto ipsec) from the remote VPN peer will be helpful in troubleshooting further.
    Following is a useful doc on VPN troubleshooting:
    IPsec Troubleshooting: Understanding and Using debug Commands
    Cheers,
    Rudresh V

  • VPN connection problem

    I am currently unable to connect to my VPN server with either of 2 Lion machines 2010 white MacBook and a black MacBook .  I run iVPN (L2TP) on an old PPC Mac Mini, my iPhone and iPad still connect instantly.  When the Lion machines try to connect for they try for about a minute and fail returning  "The L2TP-VPN server did not respond. Try reconnecting. If the problem continues, verify your settings and contact your Administrator."  I currently have my router setup to port foward and use a dynamic DNS.  I tried connecting straight to the VPN directly by changing to the internal LAN IP still no luck.  Any suggestions

    I've been out of my SonicWall VPN since I upgraded to Lion last week.  Found a trick and succeeded.  I had to reconfigure the settings on the Sonicwall and make sure that the phase 1 and phase 2 authentications were using AES encryption rather than 3DES.
    That did the trick and I was back in.
    Of course now my 10.6.8 clients are out - I'll post more on that front if I figure it out.

  • VPN Connection Problems

    I have an apple TC at home, running firmware version 7.6.1, and I can't connect to a VPN server at my work through the TC wifi.  If I connect my macbook directly to my modem with an ethernet cable, I can connect without difficulties.  When attempting to connect through the TC wifi, the VPN status indicator says that I connect and authenticate, but when I attemp to access a secured, internal website or computer at my work nothing connects.
    Any suggestions?  Happy to provide more info on my setup and devices if you need it.
    Thanks for your help.

    mwjaeger wrote:
    I turned off 'Back to my Mac' after reading an article about it using ports soemtimes used for VPN connection but it didn't seem to help.
    Turning off BTMM does not change the port allocation in the TC.. that is where the problem is.
    Can you be more specific about the ports required for my VPN?  The setup in my network connections on the MPBP points to my work website and everything else (except for my my password) seems to be automatic without mentioning any specific port numbers.  If I did find the required port number from the tech support guys at work, how exactly do I set them on my MBP.
    This setup again has nothing to do with the MBP.. it is the router where the issue is.. as clearly your initial experiment connecting directly to the modem shows.. it is open ports on the router that you need to do.
    I cannot tell you which ports without knowing what vpn client you are using. That is why my previous post began.. what vpn and what client??? Perhaps I should put it in bold.. WHAT VPN CLIENT DO YOU USE?
    Is it a built in client in Mac OS.. or is it a Cisco client or some other brand software client.. tell me that.. and I can probably figure out the ports.
    The vpn client should also have a log.. that will likely have useful information about why the VPN cannot connect.
    Also, I have an old linksys router.  How do I connect this into my setup if I put the TC into bridge mode?
    Connect the Linksys up to the modem in router mode.. bridge the TC. The Linksys will now be the main router and handle the connection. The TC becomes a dumb WAP and switch plus network hard disk.
    Will all my devices setup to run from and back-up to the TC still work?
    Yes, the network will still function as it did. You do not need to change the TC wireless or other settings.. just bridge instead of main router.
    Look in the Linksys for VPN pass-through. Some have it set automatically.. others require it checked.
    If you run into issues.. I need the exact model number and firmware revision to work out how to fix vpn.

  • Can someone interpret this vpn setup directions?

    http://vpn.bcc.bilkent.edu.tr/mac/
    this is my school's website with the instructions about how to setup the vpn. but im using mountain lion and somehow all my attempts are failing. and options in mountain lion are not the same with the pictures in the website. I think there is no problem with the vpn server because I used it with a pc before.

    Hello TimmyCoogs21,
    I may not be able to give you a direct answer on this. I am not sure of your familiarity with log files. PID refers to a Proceess ID. I am not sure which process has an ID of 94 that is causing you this non-sleep issue. Others have had similar issues in the past, i.e.The HIDD after could possibly mean it is some form of Human Interface Device. If you have a USB or something plugged into your mac at night, or a faulty hardware piece entirely. (These are just speculations)
    Bluetooth drivers prevent system from sleeping in Mavericks - what's going on!?
    Do not let the title fool you as he states that it is not a problem that is caused by bluetooth. Ultimately he sought support from apple, which in your case, I would do the same.
    You could restore/refresh your system and see if this continues if not I would recommend seeking apple support.
    I know this does not fix your problem, however I hope you find some help in it.
    Cheers.

  • Two RV042 VPN setup

    We are a small business in Indiana and have someone in Idaho connected to us via VPN that does freelance graphic design for us.  She is currently connected to us via a VPN on two Linksys WRV54g routers but our connection is dropped constantly.  I have read online this seems to be a problem so I have purchased 2 RV042 routers to do this since people seem to be much happier with them.  Is there some documentation that will walk me through setting this up?  I will probably want to set them up to be the internet router for the two locations as well (right now in Indiana we have a separate router for that purpose).  We would like to see each other both ways.  She also uses our server as her DNS server since she is in our domain.  Does this make sense?  I know enough to get myself in trouble on this!  Thanks

    There are two ways to do this. one is Gateway to Gateway. This uses two RV042 Router praferably with static or reserved IP addresses on both ends.
    The second is Client to Gateway this uses one RV042 Router and the built in Microsoft VPN Client. This requires one static or reservered IP on your end.     Best way to test this is build it between two internet connections like work and home or if you have two internet connections at work.
    If you chose VPN Gateway to Gateway
    add a new tunnel
    give the tunnel a name like "business name city name"
    chose the LAN port to use WAN1
    next is local group setup.
    I use IP Only
    the router WAN ip address is there and greyed out. take note of this IP
    Local Security Group Type SUBNET
    enter your internal IP segmant. (if you are using 192.168.1.1 then enter 192.168.1.0
    enter subnet 255.255.255.0
    Remote group setup is next.
    again IP only
    enter Her WAN IP address
    Choose Subnet
    then enter her internal IP segmant. note it has to be different then yours. (if you are using 192.168.2.1 enter 192.168.2.0)
    Ike with preshared
    Group 1
    DES
    MD5
    28800 and so on
    Enter the pre shared key and take not of it
    Look at page 36    http://www.cisco.com/en/US/docs/routers/csbr/rv042/admin/guide/RV042_V10_UG_C-WEB.pdf
    Now do the same thing on the other router just revers the local and remote security groups. it is important that the two router are on different Ip segments.
    if you have any question just ask.
    Peter Labelle

Maybe you are looking for

  • How do I move iPhoto library to an external hard drive?

    I'm Running iPhoto 08 under leopard, and because my old laptop hard drive is just too small, I've cloned it onto an external hard drive.  I have relocated my iTunes library to the external drive and would now like to do the same to my iPhoto library

  • PDF arrives is gibberish rather than an attachment

    What makes a PDF arrive not as a file but many lines of gibberish? Below are lines right before the gibberish. Thanks --Apple-Mail-5--14516743 Content-Transfer-Encoding: base64 Content-Type: application/pdf; x-mac-type=50444620; x-unix-mode=0644; x-m

  • Final Cut (& other app) direction

    Greetings. I'm a longtime "lurker", first time discussion participant... appreciate all the knowledge you guys share here. Two part question for you. The first to help me with a current situation, the second for long-term direction. 1.) After editing

  • After reinstall, SSL certificates not accepted.

    Hello there! I've reinstalled my Macbook Air (Mid 2012, OS X Mountain Lion 10.8.2) due to a problem when I lost my password. When I launched an app like Safari, Mail or Chrome, I've experienced the same problem. Pages using the SSL encryption were un

  • Records are getting overwritten in the internal table using Select query.

    Hi All, I have following query : Loop at i_salesplant.        select maramatnr mvkeVKORG mvkeVTWEG maraZZCOEAFE maraZZCOEAFEUOM mvkeZZALLPOL        into corresponding fields of table i_zallocpol from mara inner join mvke on        mvkematnr = maramat