LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 08-30-2013, 02:14 AM   #1
shams
Member
 
Registered: Jan 2004
Posts: 535

Rep: Reputation: 30
ipsec doesn't comming up?


My pc is behind the ADSL router my pc ip address is 192.168.1.10, the router private address is 192.168.1.1 and the vpn server ip address is 95.154.217.24.
I installed the openswan and xl2tpd in debian wheezy, i want to setup the l2tpd tunnel, the problem is whein i run the command:
Quote:
ipsec auto --up L2tp-Client
Quote:
"L2tp-Client" #1: Can't authenticate: no preshared key found for `@left' and `@righ'. Attribute OAKLEY_AUTHENTICATION_METHOD
"L2tp-Client" #1: no acceptable Oakley Transform
"L2tp-Client" #1: sending notification NO_PROPOSAL_CHOSEN to 95.154.217.24:500
"L2tp-Client" #1: ignoring unknown Vendor ID payload [882fe56d6fd20dbc2251613b2ebe5beb]
"L2tp-Client" #1: received Vendor ID payload [XAUTH]
"L2tp-Client" #1: received Vendor ID payload [Dead Peer Detection]
"L2tp-Client" #1: received Vendor ID payload [RFC 3947] method set to=115
"L2tp-Client" #1: Can't authenticate: no preshared key found for `@left' and `@righ'. Attribute OAKLEY_AUTHENTICATION_METHOD
"L2tp-Client" #1: no acceptable Oakley Transform
"L2tp-Client" #1: sending notification NO_PROPOSAL_CHOSEN to 95.154.217.24:500
I opened the all necessary ports in my firewall, this is /etc/ipsec.conf:
Quote:
version 2.0
config setup
dumpdir=/var/run/pluto/
nat_traversal=yes
virtual_private=%v4:10.0.0.0/8,%v4:192.168.1.0/24,%v4:567.16.0.0/12
oe=off
protostack=netkey
plutostderrlog=/var/log/pluto.log
interfaces=%defaultroute

conn L2tp-Client
authby=secret
pfs=no
auto=add
rekey=no
type=tunnel
esp=aes128-sha1
ike=aes128-sha-modp1024
ikelifetime=8h
keylife=1h
left=192.168.1.10
leftid=@left
leftnexthop=192.168.1.1
leftsourceip=192.168.1.10
leftsubnet=192.168.1.0/24
leftprotoport=17/1701
right=95.154.217.24
rightid=@righ
rightnexthop=95.154.217.24
rightprotoport=17/1701
dpddelay=30
dpdtimeout=120
dpdaction=clear
and this is /etc/ipsec.secrets:
Quote:
192.168.1.10 95.154.217.24 : PSK "toyvpn.com"

Last edited by shams; 08-30-2013 at 05:16 AM.
 
Old 08-30-2013, 05:21 AM   #2
shams
Member
 
Registered: Jan 2004
Posts: 535

Original Poster
Rep: Reputation: 30
i correct some mistakes please read again and help.

i correct some mistakes please read again and help.
 
Old 08-30-2013, 05:34 AM   #3
zhjim
Senior Member
 
Registered: Oct 2004
Distribution: Debian Squeeze x86_64
Posts: 1,748
Blog Entries: 11

Rep: Reputation: 233Reputation: 233Reputation: 233
Just a guess. But should it be rightid=@right and not like yours rightid=@righ? You are a t short .
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
ipsec update command doesn't seem to work seldom vishalwithme Linux - Security 0 07-14-2012 06:43 AM
vpn-ipsec : Failed to parse config setup portion of ipsec.conf hari85 Linux - Newbie 1 07-17-2010 08:12 PM
When is LFS 6.4 comming out? chutsu Linux From Scratch 1 01-24-2008 07:01 PM
GPS: Comming and Going wwnexc Linux - Hardware 0 08-14-2006 04:30 PM
RedHat 9 is comming!!!!! boreo Linux - General 1 03-24-2003 06:34 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 11:00 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration