
vpnc at oldfield
Jul 25, 2004, 5:15 AM
Post #3 of 3
(608 views)
Permalink
|
On 21 Jul 2004, Maurice Massar typed: ] hi, ] ] > I had been connecting to a Cisco VPN 3060 concentrator using ] > vpnc-0.2-rm+zomb-pre9 without any problems using "Perfect Forward ] > Secrecy dh2" (of PFS dh2 for short) in my vpnc.conf ] ] since pre9, vpnc should work without setting PFS in vpnc.conf/commandline.. Just tried removing the PFS setting, but the connection fails at the same place ("check pfs setting"). ] > After upgrading to vpnc-0.2-rm+zomb.1 PFS dh2 no longer works, but PFS ] > dh5 does. ] ] hmm.. I can not see what should have caused such a change... ] ] could you try what happens if you use "--pfs server"? With zomb.1 I get the same problem, dh5 works and dh2 fails. ] also look at which dh-group setting is used at ike-phase1-sa Checking the concentrator: IKE Proposal, Diffie-Hellman Group: Group 2 Security Association, Perfect Forward Secrecy: Group 2 So both are set to dh2. ] this "check pfs setting" can be a bit misleading, because ] it is always print if an unexpected paket is received at a ] certain stage (vpnc error handling is practically nonexistant. ] vpnc does not understand error messages from the concentrator, ] it just notices that it is not the "expected" paket and dies). ] ] maybe it is something else.. Regards, Kim
|