LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 11-17-2006, 08:50 AM   #1
louiscastoria
LQ Newbie
 
Registered: Oct 2003
Posts: 5

Rep: Reputation: 0
Suse 10.1 Gateway intercepting udp port 500


I'm having a problem that I just can't seem to figure out. I have a suse 10.1 server configured as an internet gateway. I manage the network for a small ISP. I have a customer who has a 1710 cisco on the internal side of my network and 7140 cisco on theirs. All the Ip address used are internet accessible. The problem that seems to be happening is that the gateway seems to be intercepting the IKE negations instead of letting them pass on to the 1710. The ports/protocols that are being used are Gre, Udp 500,and Esp.

Note: I changed the ip address to 123.123.123.1 from the original ip address.
123.123.123.1 signifies my suse 10.1 gateway.

Any help on this will be most appreciated.

This log is from the 7140 cisco device.

1d01h: ISAKMP (0:0): received packet from 123.123.123.1 (N) NEW SA
1d01h: ISAKMP: local port 500, remote port 500
1d01h: ISAKMP (0:195): Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH
Old State = IKE_READY New State = IKE_R_MM1

1d01h: ISAKMP (0:195): processing SA payload. message ID = 0
1d01h: ISAKMP (0:195): No pre-shared key with 123.123.123.1!
1d01h: ISAKMP (0:195): Checking ISAKMP transform 1 against priority 1 policy
1d01h: ISAKMP: encryption DES-CBC
1d01h: ISAKMP: hash MD5
1d01h: ISAKMP: default group 1
1d01h: ISAKMP: auth pre-share
1d01h: ISAKMP: life type in seconds
1d01h: ISAKMP: life duration (VPI) of 0x0 0x1 0x51 0x80
1d01h: ISAKMP (0:195): Preshared authentication offered but does not match policy!
1d01h: ISAKMP (0:195): atts are not acceptable. Next payload is 3
1d01h: ISAKMP (0:195): Checking ISAKMP transform 2 against priority 1 policy
1d01h: ISAKMP: encryption 3DES-CBC
1d01h: ISAKMP: hash MD5
1d01h: ISAKMP: default group 2
1d01h: ISAKMP: auth pre-share
1d01h: ISAKMP: life type in seconds
1d01h: ISAKMP: life duration (VPI) of 0x0 0x1 0x51 0x80
1d01h: ISAKMP (0:195): Encryption algorithm offered does not match policy!
1d01h: ISAKMP (0:195): atts are not acceptable. Next payload is 0
1d01h: ISAKMP (0:195): Checking ISAKMP transform 1 against priority 65535 policy
1d01h: ISAKMP: encryption DES-CBC
1d01h: ISAKMP: hash MD5
1d01h: ISAKMP: default group 1
1d01h: ISAKMP: auth pre-share
1d01h: ISAKMP: life type in seconds
1d01h: ISAKMP: life duration (VPI) of 0x0 0x1 0x51 0x80
1d01h: ISAKMP (0:195): Hash algorithm offered does not match policy!
1d01h: ISAKMP (0:195): atts are not acceptable. Next payload is 3
1d01h: ISAKMP (0:195): Checking ISAKMP transform 2 against priority 65535 policy
1d01h: ISAKMP: encryption 3DES-CBC
1d01h: ISAKMP: hash MD5
1d01h: ISAKMP: default group 2
1d01h: ISAKMP: auth pre-share
1d01h: ISAKMP: life type in seconds
1d01h: ISAKMP: life duration (VPI) of 0x0 0x1 0x51 0x80
1d01h: ISAKMP (0:195): Encryption algorithm offered does not match policy!
1d01h: ISAKMP (0:195): atts are not acceptable. Next payload is 0
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
udp on port 5005 gabsik Linux - Security 4 07-17-2006 11:12 PM
how to add & register filter for intercepting the packets outgoing on port 80? jayashri Programming 2 11-08-2004 01:30 PM
Port Forwarding on MN-500 The Pentium Guy Linux - Networking 6 10-18-2004 11:15 AM
closing port 68/udp? antik Linux - Security 1 09-26-2003 12:26 PM
VPN port 500 50 and 51 ollie Linux - Networking 2 01-16-2002 10:44 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 06:14 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration