1

Temat: strongSwan za NATem

Witam wszystkich
Skonfigurowałem sobie strongSwana na OpenWrt według tego prostego poradnika http://eko.one.pl/?p=openwrt-ipsec  postawienie go przebiegło bez żadnych problemów, jednak jak chce połączyć się z androida to wyskakuje mi "niepowodzenie". Czy trzeba w tej konfiguracji coś zmienić żeby działało to za NATem?

2

Odp: strongSwan za NATem

Na 12.09 działało. We współczesnych wydaniach coś się mogło zmienić i tu już musisz sobie poszukać po logach o co się rozchodzi.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

3

Odp: strongSwan za NATem

W logach nie za ciekawie sytuacja wygląda
Feb 17 12:56:35 Gargoyle kern.debug kernel: [75741.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:35 Gargoyle kern.debug kernel: [75741.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:35 Gargoyle kern.debug kernel: [75741.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:38 Gargoyle kern.debug kernel: [75744.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:38 Gargoyle kern.debug kernel: [75744.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:38 Gargoyle kern.debug kernel: [75744.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:38 Gargoyle kern.debug kernel: [75744.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:38 Gargoyle kern.debug kernel: [75744.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:41 Gargoyle kern.debug kernel: [75747.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:41 Gargoyle kern.debug kernel: [75747.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:41 Gargoyle kern.debug kernel: [75747.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:41 Gargoyle kern.debug kernel: [75747.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:41 Gargoyle kern.debug kernel: [75747.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:44 Gargoyle kern.debug kernel: [75750.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:44 Gargoyle kern.debug kernel: [75750.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:44 Gargoyle kern.debug kernel: [75750.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:44 Gargoyle kern.debug kernel: [75750.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:44 Gargoyle kern.debug kernel: [75750.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:47 Gargoyle kern.debug kernel: [75753.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:47 Gargoyle kern.debug kernel: [75753.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:47 Gargoyle kern.debug kernel: [75753.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:47 Gargoyle kern.debug kernel: [75753.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:47 Gargoyle kern.debug kernel: [75753.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:50 Gargoyle kern.debug kernel: [75756.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:50 Gargoyle kern.debug kernel: [75756.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:50 Gargoyle kern.debug kernel: [75756.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:50 Gargoyle kern.debug kernel: [75756.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:50 Gargoyle kern.debug kernel: [75756.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:53 Gargoyle kern.debug kernel: [75759.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:53 Gargoyle kern.debug kernel: [75759.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:53 Gargoyle kern.debug kernel: [75759.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:53 Gargoyle kern.debug kernel: [75759.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:53 Gargoyle kern.debug kernel: [75759.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:56 Gargoyle kern.debug kernel: [75762.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:56 Gargoyle kern.debug kernel: [75762.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:56 Gargoyle kern.debug kernel: [75762.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:56 Gargoyle kern.debug kernel: [75762.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:56 Gargoyle kern.debug kernel: [75762.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:59 Gargoyle kern.debug kernel: [75765.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:59 Gargoyle kern.debug kernel: [75765.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:59 Gargoyle kern.debug kernel: [75765.620000] icmpv6_send: no reply to icmp error
Feb 17 12:56:59 Gargoyle kern.debug kernel: [75765.620000] icmpv6_send: no reply to icmp error
Feb 17 12:57:02 Gargoyle kern.debug kernel: [75768.620000] icmpv6_send: no reply to icmp error
Feb 17 12:57:02 Gargoyle kern.debug kernel: [75768.620000] icmpv6_send: no reply to icmp error
Feb 17 12:57:02 Gargoyle kern.debug kernel: [75768.620000] icmpv6_send: no reply to icmp error
Feb 17 12:57:05 Gargoyle kern.debug kernel: [75771.630000] icmpv6_send: no reply to icmp error
Feb 17 12:57:05 Gargoyle kern.debug kernel: [75771.630000] icmpv6_send: no reply to icmp error
Feb 17 12:57:05 Gargoyle kern.debug kernel: [75771.630000] icmpv6_send: no reply to icmp error
Feb 17 12:57:05 Gargoyle kern.debug kernel: [75771.640000] icmpv6_send: no reply to icmp error
Feb 17 12:57:08 Gargoyle kern.debug kernel: [75774.640000] icmpv6_send: no reply to icmp error
Success
Nie mam pojęcia o co chodzi

4

Odp: strongSwan za NATem

Coś od ipv6 masz zainstalowane.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

5

Odp: strongSwan za NATem

Zresetowałem router do ustawień fabrycznych i zrobiłem wszystko od nowa. Teraz sytuacja w logach wygląda tak.


Jan  1 01:00:39 Gargoyle syslog.info syslogd started: BusyBox v1.19.4
Jan  1 01:00:39 Gargoyle kern.info kernel: [    0.410000] squashfs: version 4.0 (2009/01/31) Phillip Lougher
Jan  1 01:00:39 Gargoyle kern.info kernel: [    0.420000] JFFS2 version 2.2 (NAND) (SUMMARY) (LZMA) (RTIME) (CMODE_PRIORITY) (c) 2001-2006 Red Hat, Inc.
Jan  1 01:00:39 Gargoyle kern.info kernel: [    0.430000] msgmni has been set to 246
Jan  1 01:00:39 Gargoyle kern.info kernel: [    0.430000] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 254)
Jan  1 01:00:39 Gargoyle kern.info kernel: [    0.440000] io scheduler noop registered
Jan  1 01:00:39 Gargoyle kern.info kernel: [    0.440000] io scheduler deadline registered (default)
Jan  1 01:00:39 Gargoyle kern.info kernel: [    0.450000] Serial: 8250/16550 driver, 16 ports, IRQ sharing enabled
Jan  1 01:00:39 Gargoyle kern.info kernel: [    0.480000] serial8250.0: ttyS0 at MMIO 0x18020000 (irq = 11) is a 16550A
Jan  1 01:00:39 Gargoyle kern.info kernel: [    0.490000] console [ttyS0] enabled, bootconsole disabled
Jan  1 01:00:39 Gargoyle kern.warn kernel: [    0.500000] m25p80 spi0.0: found s25fl064k, expected m25p80
Jan  1 01:00:39 Gargoyle kern.info kernel: [    0.510000] m25p80 spi0.0: s25fl064k (8192 Kbytes)
Jan  1 01:00:39 Gargoyle kern.notice kernel: [    0.510000] 5 tp-link partitions found on MTD device spi0.0
Jan  1 01:00:39 Gargoyle kern.notice kernel: [    0.520000] Creating 5 MTD partitions on "spi0.0":
Jan  1 01:00:39 Gargoyle kern.notice kernel: [    0.520000] 0x000000000000-0x000000020000 : "u-boot"
Jan  1 01:00:39 Gargoyle kern.notice kernel: [    0.530000] 0x000000020000-0x00000010ef78 : "kernel"
Jan  1 01:00:39 Gargoyle kern.warn kernel: [    0.530000] mtd: partition "kernel" must either start or end on erase block boundary or be smaller than an erase block -- forcing read-only
Jan  1 01:00:39 Gargoyle kern.notice kernel: [    0.550000] 0x00000010ef78-0x0000007f0000 : "rootfs"
Jan  1 01:00:39 Gargoyle kern.warn kernel: [    0.550000] mtd: partition "rootfs" must either start or end on erase block boundary or be smaller than an erase block -- forcing read-only
Jan  1 01:00:39 Gargoyle kern.notice kernel: [    0.570000] mtd: partition "rootfs" set to be root filesystem
Jan  1 01:00:39 Gargoyle kern.info kernel: [    0.570000] mtd: partition "rootfs_data" created automatically, ofs=680000, len=170000
Jan  1 01:00:39 Gargoyle kern.notice kernel: [    0.580000] 0x000000680000-0x0000007f0000 : "rootfs_data"
Jan  1 01:00:39 Gargoyle kern.notice kernel: [    0.590000] 0x0000007f0000-0x000000800000 : "art"
Jan  1 01:00:39 Gargoyle kern.notice kernel: [    0.590000] 0x000000020000-0x0000007f0000 : "firmware"
Jan  1 01:00:39 Gargoyle kern.info kernel: [    0.730000] ag71xx_mdio: probed
Jan  1 01:00:39 Gargoyle kern.info kernel: [    0.730000] eth0: Atheros AG71xx at 0xb9000000, irq 4
Jan  1 01:00:39 Gargoyle kern.info kernel: [    1.310000] eth0: Atheros AR8327 switch driver attached.
Jan  1 01:00:39 Gargoyle kern.info kernel: [    2.470000] ag71xx ag71xx.0: eth0: connected to PHY at ag71xx-mdio.0:00 [uid=004dd034, driver=Atheros AR8216/AR8236/AR8316]
Jan  1 01:00:39 Gargoyle kern.info kernel: [    2.490000] TCP cubic registered
Jan  1 01:00:39 Gargoyle kern.info kernel: [    2.490000] NET: Registered protocol family 17
Jan  1 01:00:39 Gargoyle kern.notice kernel: [    2.490000] Bridge firewalling registered
Jan  1 01:00:39 Gargoyle kern.info kernel: [    2.500000] Ebtables v2.0 registered
Jan  1 01:00:39 Gargoyle kern.info kernel: [    2.500000] 8021q: 802.1Q VLAN Support v1.8
Jan  1 01:00:39 Gargoyle kern.info kernel: [    2.510000] VFS: Mounted root (squashfs filesystem) readonly on device 31:2.
Jan  1 01:00:39 Gargoyle kern.info kernel: [    2.520000] Freeing unused kernel memory: 220k freed
Jan  1 01:00:39 Gargoyle kern.debug kernel: [    4.480000] Registered led device: tp-link:blue:qss
Jan  1 01:00:39 Gargoyle kern.debug kernel: [    4.480000] Registered led device: tp-link:blue:system
Jan  1 01:00:39 Gargoyle kern.debug kernel: [    4.480000] Registered led device: tp-link:green:usb1
Jan  1 01:00:39 Gargoyle kern.debug kernel: [    4.480000] Registered led device: tp-link:green:usb2
Jan  1 01:00:39 Gargoyle kern.debug kernel: [    4.480000] Registered led device: tp-link:blue:wlan2g
Jan  1 01:00:39 Gargoyle kern.info kernel: [    5.490000] eth0: link up (1000Mbps/Full duplex)
Jan  1 01:00:39 Gargoyle kern.notice kernel: [    7.740000] JFFS2 notice: (493) jffs2_build_xattr_subsystem: complete building xattr subsystem, 1 of xdatum (1 unchecked, 0 orphan) and 35 of xref (0 dead, 7 orphan) found.
Jan  1 01:00:39 Gargoyle kern.notice kernel: [    8.420000] SCSI subsystem initialized
Jan  1 01:00:39 Gargoyle kern.info kernel: [    8.610000] usbcore: registered new interface driver usbfs
Jan  1 01:00:39 Gargoyle kern.info kernel: [    8.620000] usbcore: registered new interface driver hub
Jan  1 01:00:39 Gargoyle kern.info kernel: [    8.620000] usbcore: registered new device driver usb
Jan  1 01:00:39 Gargoyle kern.info kernel: [    9.040000] ehci_hcd: USB 2.0 'Enhanced' Host Controller (EHCI) Driver
Jan  1 01:00:39 Gargoyle kern.info kernel: [    9.040000] ehci-platform ehci-platform: Generic Platform EHCI Controller
Jan  1 01:00:39 Gargoyle kern.info kernel: [    9.050000] ehci-platform ehci-platform: new USB bus registered, assigned bus number 1
Jan  1 01:00:39 Gargoyle kern.info kernel: [    9.090000] ehci-platform ehci-platform: irq 3, io mem 0x1b000000
Jan  1 01:00:39 Gargoyle kern.info kernel: [    9.110000] ehci-platform ehci-platform: USB 2.0 started, EHCI 1.00
Jan  1 01:00:39 Gargoyle kern.info kernel: [    9.110000] hub 1-0:1.0: USB hub found
Jan  1 01:00:39 Gargoyle kern.info kernel: [    9.120000] hub 1-0:1.0: 1 port detected
Jan  1 01:00:39 Gargoyle kern.info kernel: [    9.170000] Initializing USB Mass Storage driver...
Jan  1 01:00:39 Gargoyle kern.info kernel: [    9.170000] usbcore: registered new interface driver usb-storage
Jan  1 01:00:42 Gargoyle kern.info kernel: [   42.400000] ADDRCONF(NETDEV_UP): eth0: link is not ready
Jan  1 01:00:43 Gargoyle kern.info kernel: [   43.250000] eth0: link up (1000Mbps/Full duplex)
Jan  1 01:00:43 Gargoyle kern.info kernel: [   43.270000] ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready
Jan  1 01:00:43 Gargoyle kern.info kernel: [   43.950000] eth0: link down
Jan  1 01:00:43 Gargoyle kern.info kernel: [   43.960000] ADDRCONF(NETDEV_UP): eth0: link is not ready
Jan  1 01:00:43 Gargoyle kern.info kernel: [   43.970000] ADDRCONF(NETDEV_UP): eth0.1: link is not ready
Jan  1 01:00:43 Gargoyle kern.info kernel: [   43.970000] device eth0.1 entered promiscuous mode
Jan  1 01:00:43 Gargoyle kern.info kernel: [   43.980000] device eth0 entered promiscuous mode
Jan  1 01:00:43 Gargoyle daemon.notice netifd: Interface 'lan' is now up
Jan  1 01:00:43 Gargoyle kern.info kernel: [   43.990000] ADDRCONF(NETDEV_UP): br-lan: link is not ready
Jan  1 01:00:44 Gargoyle kern.info kernel: [   44.010000] ADDRCONF(NETDEV_UP): eth0.2: link is not ready
Jan  1 01:00:44 Gargoyle kern.info kernel: [   44.010000] device eth0.2 entered promiscuous mode
Jan  1 01:00:44 Gargoyle daemon.notice netifd: Interface 'loopback' is now up
Jan  1 01:00:44 Gargoyle user.notice firewall: Reloading firewall due to ifup of lan (br-lan)
Jan  1 01:00:44 Gargoyle kern.info kernel: [   44.260000] eth0: link up (1000Mbps/Full duplex)
Jan  1 01:00:44 Gargoyle kern.info kernel: [   44.280000] ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready
Jan  1 01:00:44 Gargoyle kern.info kernel: [   44.300000] br-lan: port 1(eth0.1) entered forwarding state
Jan  1 01:00:44 Gargoyle kern.info kernel: [   44.300000] br-lan: port 1(eth0.1) entered forwarding state
Jan  1 01:00:44 Gargoyle kern.info kernel: [   44.310000] ADDRCONF(NETDEV_CHANGE): eth0.1: link becomes ready
Jan  1 01:00:44 Gargoyle kern.info kernel: [   44.310000] br-lan: port 2(eth0.2) entered forwarding state
Jan  1 01:00:44 Gargoyle kern.info kernel: [   44.320000] br-lan: port 2(eth0.2) entered forwarding state
Jan  1 01:00:44 Gargoyle kern.info kernel: [   44.330000] ADDRCONF(NETDEV_CHANGE): eth0.2: link becomes ready
Jan  1 01:00:44 Gargoyle kern.info kernel: [   44.340000] ADDRCONF(NETDEV_CHANGE): br-lan: link becomes ready
Jan  1 01:00:46 Gargoyle kern.info kernel: [   46.300000] br-lan: port 1(eth0.1) entered forwarding state
Jan  1 01:00:46 Gargoyle kern.info kernel: [   46.320000] br-lan: port 2(eth0.2) entered forwarding state
Jan  1 01:00:46 Gargoyle user.notice usb-modeswitch: 1-0:1.0: Manufacturer=Linux_3.3.8_ehci_hcd Product=Generic_Platform_EHCI_Controller Serial=ehci-platform
Jan  1 01:00:49 Gargoyle kern.info kernel: [   49.620000] ADDRCONF(NETDEV_UP): wlan0: link is not ready
Jan  1 01:00:49 Gargoyle kern.info kernel: [   49.620000] device wlan0 entered promiscuous mode
Jan  1 01:00:49 Gargoyle kern.info kernel: [   49.840000] br-lan: port 3(wlan0) entered forwarding state
Jan  1 01:00:49 Gargoyle kern.info kernel: [   49.850000] br-lan: port 3(wlan0) entered forwarding state
Jan  1 01:00:49 Gargoyle kern.info kernel: [   49.860000] ADDRCONF(NETDEV_CHANGE): wlan0: link becomes ready
Jan  1 01:00:51 Gargoyle kern.info kernel: [   51.850000] br-lan: port 3(wlan0) entered forwarding state
Jan  1 01:00:52 Gargoyle kern.info kernel: [   52.890000] ADDRCONF(NETDEV_UP): wlan1: link is not ready
Jan  1 01:00:52 Gargoyle kern.info kernel: [   52.900000] device wlan1 entered promiscuous mode
Jan  1 01:00:53 Gargoyle kern.info kernel: [   53.120000] br-lan: port 4(wlan1) entered forwarding state
Jan  1 01:00:53 Gargoyle kern.info kernel: [   53.130000] br-lan: port 4(wlan1) entered forwarding state
Jan  1 01:00:53 Gargoyle kern.info kernel: [   53.130000] ADDRCONF(NETDEV_CHANGE): wlan1: link becomes ready
Jan  1 01:00:55 Gargoyle kern.info kernel: [   55.130000] br-lan: port 4(wlan1) entered forwarding state
Jan  1 01:00:01 Gargoyle user.notice usb-modeswitch: 1-1:1.0: Manufacturer=? Product=USB2.0_Hub Serial=?
Jan  1 01:00:02 Gargoyle authpriv.info dropbear[1399]: Running in background
Jan  1 01:00:02 Gargoyle daemon.crit httpd_gargoyle[1427]: bind 0.0.0.0 - Address already in use
Jan  1 01:00:02 Gargoyle daemon.crit httpd_gargoyle[1427]: bind 0.0.0.0 - Address already in use
Jan  1 01:00:03 Gargoyle daemon.warn httpd_gargoyle[1436]: started as root without requesting chroot(), warning only
Jan  1 01:00:03 Gargoyle daemon.notice httpd_gargoyle[1436]: httpd_gargoyle/1.0 14mar2008 starting on Gargoyle, port 80
Jan  1 01:00:04 Gargoyle user.notice dnsmasq: DNS rebinding protection is active, will discard upstream RFC1918 responses!
Jan  1 01:00:04 Gargoyle user.notice dnsmasq: Allowing 127.0.0.0/8 responses
Jan  1 01:00:04 Gargoyle user.notice dnsmasq: Allowing RFC1918 responses for domain free.aero2.net.pl
Jan  1 01:00:04 Gargoyle daemon.info dnsmasq[1525]: started, version 2.66 cachesize 150
Jan  1 01:00:04 Gargoyle daemon.info dnsmasq[1525]: compile time options: IPv6 GNU-getopt no-DBus no-i18n no-IDN DHCP no-DHCPv6 no-Lua TFTP no-conntrack no-ipset no-auth
Jan  1 01:00:04 Gargoyle daemon.info dnsmasq[1525]: using local addresses only for domain lan
Jan  1 01:00:04 Gargoyle daemon.info dnsmasq[1525]: reading /tmp/resolv.conf.auto
Jan  1 01:00:04 Gargoyle daemon.info dnsmasq[1525]: using nameserver 192.168.1.1#53
Jan  1 01:00:04 Gargoyle daemon.info dnsmasq[1525]: using local addresses only for domain lan
Jan  1 01:00:04 Gargoyle daemon.info dnsmasq[1525]: read /etc/hosts - 2 addresses
Jan  1 01:00:05 Gargoyle user.err syslog: error starting threads: errno 89 (Function not implemented)
Jan  1 01:00:05 Gargoyle user.info sysinit: exportfs: could not open /var/lib/nfs/.etab.lock for locking: errno 2 (No such file or directory)
Jan  1 01:00:05 Gargoyle user.info sysinit: exportfs: can't lock /var/lib/nfs/etab for writing
Jan  1 01:00:05 Gargoyle user.info sysinit: exportfs: could not open /var/lib/nfs/.xtab.lock for locking: errno 2 (No such file or directory)
Jan  1 01:00:05 Gargoyle user.info sysinit: exportfs: can't lock /var/lib/nfs/xtab for writing
Jan  1 01:00:06 Gargoyle user.info sysinit: ERROR: No valid dynamic DNS service configurations defined
Jan  1 01:00:06 Gargoyle user.info sysinit: (Did you specify correct configuration file path?)
Jan  1 01:00:09 Gargoyle kern.warn kernel: [   64.040000] ipt_bandwidth: timezone shift of 60 minutes detected, adjusting
Jan  1 01:00:09 Gargoyle kern.warn kernel: [   64.050000]                old minutes west=0, new minutes west=-60
Feb 17 13:21:13 Gargoyle user.notice root: vsftpd init: mounted = 0
Feb 17 13:21:13 Gargoyle user.info sysinit: ERROR: No drives attached, no directories to share!
Feb 17 13:21:13 Gargoyle user.info sysinit: setting up led USB1
Feb 17 13:21:13 Gargoyle user.info sysinit: setting up led USB2
Feb 17 13:21:13 Gargoyle user.info sysinit: setting up led WLAN2G
Feb 17 13:21:15 Gargoyle daemon.info hostapd: wlan0: STA 74:e5:43:24:04:6b IEEE 802.11: authenticated
Feb 17 13:21:15 Gargoyle daemon.info hostapd: wlan0: STA 74:e5:43:24:04:6b IEEE 802.11: associated (aid 1)
Feb 17 13:21:15 Gargoyle daemon.info hostapd: wlan0: STA 74:e5:43:24:04:6b WPA: pairwise key handshake completed (WPA)
Feb 17 13:21:15 Gargoyle daemon.info hostapd: wlan0: STA 74:e5:43:24:04:6b WPA: group key handshake completed (WPA)
Feb 17 13:21:43 Gargoyle cron.err crond[1338]: time disparity of 7956741 minutes detected
Feb 17 13:23:41 Gargoyle authpriv.info dropbear[2874]: Child connection from 192.168.1.13:65095
Feb 17 13:23:51 Gargoyle authpriv.notice dropbear[2874]: Password auth succeeded for 'root' from 192.168.1.13:65095
Feb 17 13:24:55 Gargoyle kern.info kernel: [  308.260000] NET: Registered protocol family 15
Feb 17 13:24:55 Gargoyle kern.info kernel: [  308.300000] Initializing XFRM netlink socket
Feb 17 13:27:16 Gargoyle authpriv.info dropbear[3585]: Child connection from 192.168.1.13:65161
Feb 17 13:27:21 Gargoyle authpriv.notice dropbear[3585]: Password auth succeeded for 'root' from 192.168.1.13:65161
Feb 17 13:27:45 Gargoyle authpriv.info dropbear[3667]: Child connection from 192.168.1.13:65164
Feb 17 13:27:48 Gargoyle authpriv.notice dropbear[3667]: Password auth succeeded for 'root' from 192.168.1.13:65164
Feb 17 13:30:36 Gargoyle daemon.info hostapd: wlan0: STA 74:e5:43:24:04:6b WPA: group key handshake completed (WPA)
Success

6

Odp: strongSwan za NATem

Czyli nie ma nic. Włączyłeś w ogóle ipsec?

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

7

Odp: strongSwan za NATem

No tak. Wszystko wykonałem tak jak w poradniku do którego link podałem wyżej i żadnego błędu nie było

8

Odp: strongSwan za NATem

Wpisz

/etc/init.d/ipsec start

i pokaz co wyszło na konsoli.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

9

Odp: strongSwan za NATem

Właśnie po wpisaniu tej komendy nic nie zwraca, myślałem że tak ma być

10

Odp: strongSwan za NATem

To zrób ps i zobacz czy proces jest uruchomiony. Jak nie - rób ręcznie ipsec start i zobacz.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

11

Odp: strongSwan za NATem

Po wpisaniu ipsec start wysypuje sie taki błąd:
Starting strongSwan 5.1.3 IPsec [starter]...
/etc/ipsec.conf:3: syntax error, unexpected CONN, expecting EOL [conn]
unable to start strongSwan -- fatal errors in config

12

Odp: strongSwan za NATem

Co wpisałeś do /etc/ipsec.conf?

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

13

Odp: strongSwan za NATem

config setup                     
conn android
      keyexchange=ikev1
      authby=xauthpsk
      xauth=server
      left=%defaultroute
      leftsubnet=0.0.0.0/0
      leftfirewall=yes
      right=%any
      rightsourceip=%dhcp
      forceencaps=yes
      auto=add

Tylko serwer działa za natem więc na openwrt jest wyłączony dhcp. Może mieć to coś wspólnego?

14

Odp: strongSwan za NATem

Przed wysłaniem poprzedniego posta w pliku /etc/ipsec.conf miałem odstęp między
config setup                     

conn android
po jego usunięciu mam inny komunikat:

root@Gargoyle:~# ipsec start
Starting strongSwan 5.1.3 IPsec [starter]...
charon is already running (/var/run/charon.pid exists) -- skipping daemon start
/bin/sh: modprobe: not found
/bin/sh: modprobe: not found
/bin/sh: modprobe: not found
/bin/sh: modprobe: not found
/bin/sh: modprobe: not found
starter is already running (/var/run/starter.charon.pid exists) -- no fork done

15

Odp: strongSwan za NATem

Masz już ipsec uruchomiony w tle...

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

16

Odp: strongSwan za NATem

Ipsec wystartował ale android dalej nie może się połączyć

17

Odp: strongSwan za NATem

Patrz w logi. Coś musi wyświetlić, a samo "nie może się połączyć" w niczym nie pomaga.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

18

Odp: strongSwan za NATem

Sorki racja. Ja dopiero zaczynam zabawę z OpenWrt więc wiele w tych logach nie widzę

Feb 17 15:04:01 Gargoyle daemon.info syslog: 12[ENC] parsed ID_PROT request 0 [ SA V V V V V ]
Feb 17 15:04:01 Gargoyle daemon.info syslog: 12[IKE] received XAuth vendor ID
Feb 17 15:04:01 Gargoyle daemon.info syslog: 12[IKE] received DPD vendor ID
Feb 17 15:04:01 Gargoyle daemon.info syslog: 12[IKE] received Cisco Unity vendor ID
Feb 17 15:04:01 Gargoyle daemon.info syslog: 12[IKE] received NAT-T (RFC 3947) vendor ID
Feb 17 15:04:01 Gargoyle daemon.info syslog: 12[IKE] received draft-ietf-ipsec-nat-t-ike-02\n vendor ID
Feb 17 15:04:01 Gargoyle daemon.info syslog: 12[IKE] 37.47.84.208 is initiating a Main Mode IKE_SA
Feb 17 15:04:01 Gargoyle authpriv.info syslog: 12[IKE] 37.47.84.208 is initiating a Main Mode IKE_SA
Feb 17 15:04:01 Gargoyle daemon.info syslog: 12[CFG] received proposals: IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CBC_192/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CBC_128/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CB
Feb 17 15:04:01 Gargoyle daemon.info syslog: 12[CFG] configured proposals: IKE:AES_CBC_128/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_2048, IKE:3DES_CBC/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1536, IKE:3DES_CBC/AES_CBC_128/AES_CBC_192/AES_CBC_256/HMAC_MD5_96/HMAC_SHA1_96/AES_XCBC_96/HMAC_S
Feb 17 15:04:29 Gargoyle daemon.info syslog: 02[NET] received packet: from 37.47.84.208[11410] to 192.168.1.2[500] (528 bytes)
Feb 17 15:04:29 Gargoyle daemon.info syslog: 02[ENC] parsed ID_PROT request 0 [ SA V V V V V ]
Feb 17 15:04:29 Gargoyle daemon.info syslog: 02[IKE] received XAuth vendor ID
Feb 17 15:04:29 Gargoyle daemon.info syslog: 02[IKE] received DPD vendor ID
Feb 17 15:04:29 Gargoyle daemon.info syslog: 02[IKE] received Cisco Unity vendor ID
Feb 17 15:04:29 Gargoyle daemon.info syslog: 02[IKE] received NAT-T (RFC 3947) vendor ID
Feb 17 15:04:29 Gargoyle daemon.info syslog: 02[IKE] received draft-ietf-ipsec-nat-t-ike-02\n vendor ID
Feb 17 15:04:29 Gargoyle daemon.info syslog: 02[IKE] 37.47.84.208 is initiating a Main Mode IKE_SA
Feb 17 15:04:29 Gargoyle authpriv.info syslog: 02[IKE] 37.47.84.208 is initiating a Main Mode IKE_SA
Feb 17 15:04:29 Gargoyle daemon.info syslog: 02[CFG] received proposals: IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CBC_192/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CBC_128/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CB
Feb 17 15:04:29 Gargoyle daemon.info syslog: 02[CFG] configured proposals: IKE:AES_CBC_128/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_2048, IKE:3DES_CBC/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1536, IKE:3DES_CBC/AES_CBC_128/AES_CBC_192/AES_CBC_256/HMAC_MD5_96/HMAC_SHA1_96/AES_XCBC_96/HMAC_S
Feb 17 15:04:29 Gargoyle daemon.info syslog: 01[NET] received packet: from 37.47.84.208[11410] to 192.168.1.2[500] (528 bytes)
Feb 17 15:04:29 Gargoyle daemon.info syslog: 01[ENC] parsed ID_PROT request 0 [ SA V V V V V ]
Feb 17 15:04:29 Gargoyle daemon.info syslog: 01[IKE] received XAuth vendor ID
Feb 17 15:04:29 Gargoyle daemon.info syslog: 01[IKE] received DPD vendor ID
Feb 17 15:04:29 Gargoyle daemon.info syslog: 01[IKE] received Cisco Unity vendor ID
Feb 17 15:04:29 Gargoyle daemon.info syslog: 01[IKE] received NAT-T (RFC 3947) vendor ID
Feb 17 15:04:29 Gargoyle daemon.info syslog: 01[IKE] received draft-ietf-ipsec-nat-t-ike-02\n vendor ID
Feb 17 15:04:29 Gargoyle daemon.info syslog: 01[IKE] 37.47.84.208 is initiating a Main Mode IKE_SA
Feb 17 15:04:29 Gargoyle authpriv.info syslog: 01[IKE] 37.47.84.208 is initiating a Main Mode IKE_SA
Feb 17 15:04:29 Gargoyle daemon.info syslog: 01[CFG] received proposals: IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CBC_192/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CBC_128/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CB
Feb 17 15:04:29 Gargoyle daemon.info syslog: 01[CFG] configured proposals: IKE:AES_CBC_128/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_2048, IKE:3DES_CBC/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1536, IKE:3DES_CBC/AES_CBC_128/AES_CBC_192/AES_CBC_256/HMAC_MD5_96/HMAC_SHA1_96/AES_XCBC_96/HMAC_S
Feb 17 15:05:11 Gargoyle authpriv.info ipsec_starter[6994]: Starting strongSwan 5.1.3 IPsec [starter]...
Feb 17 15:05:11 Gargoyle authpriv.info ipsec_starter[6994]: charon is already running (/var/run/charon.pid exists) -- skipping daemon start
Feb 17 15:05:11 Gargoyle authpriv.info ipsec_starter[6994]: starter is already running (/var/run/starter.charon.pid exists) -- no fork done
Feb 17 15:08:05 Gargoyle daemon.info syslog: 16[NET] received packet: from 37.47.84.208[13114] to 192.168.1.2[500] (528 bytes)
Feb 17 15:08:05 Gargoyle daemon.info syslog: 16[ENC] parsed ID_PROT request 0 [ SA V V V V V ]
Feb 17 15:08:05 Gargoyle daemon.info syslog: 16[IKE] received XAuth vendor ID
Feb 17 15:08:05 Gargoyle daemon.info syslog: 16[IKE] received DPD vendor ID
Feb 17 15:08:05 Gargoyle daemon.info syslog: 16[IKE] received Cisco Unity vendor ID
Feb 17 15:08:05 Gargoyle daemon.info syslog: 16[IKE] received NAT-T (RFC 3947) vendor ID
Feb 17 15:08:05 Gargoyle daemon.info syslog: 16[IKE] received draft-ietf-ipsec-nat-t-ike-02\n vendor ID
Feb 17 15:08:05 Gargoyle daemon.info syslog: 16[IKE] 37.47.84.208 is initiating a Main Mode IKE_SA
Feb 17 15:08:05 Gargoyle authpriv.info syslog: 16[IKE] 37.47.84.208 is initiating a Main Mode IKE_SA
Feb 17 15:08:05 Gargoyle daemon.info syslog: 16[CFG] received proposals: IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CBC_192/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CBC_128/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CB
Feb 17 15:08:05 Gargoyle daemon.info syslog: 16[CFG] configured proposals: IKE:AES_CBC_128/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_2048, IKE:3DES_CBC/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1536, IKE:3DES_CBC/AES_CBC_128/AES_CBC_192/AES_CBC_256/HMAC_MD5_96/HMAC_SHA1_96/AES_XCBC_96/HMAC_S
Feb 17 15:08:05 Gargoyle daemon.info syslog: 16[IKE] no proposal found
Feb 17 15:08:05 Gargoyle daemon.info syslog: 16[ENC] generating INFORMATIONAL_V1 request 86378348 [ N(NO_PROP) ]
Feb 17 15:08:05 Gargoyle daemon.info syslog: 16[NET] sending packet: from 192.168.1.2[500] to 37.47.84.208[13114] (56 bytes)
Feb 17 15:10:36 Gargoyle daemon.info hostapd: wlan0: STA 74:e5:43:24:04:6b WPA: group key handshake completed (WPA)
Feb 17 15:12:45 Gargoyle daemon.info syslog: 15[NET] received packet: from 37.47.84.208[21589] to 192.168.1.2[500] (528 bytes)
Feb 17 15:12:45 Gargoyle daemon.info syslog: 15[ENC] parsed ID_PROT request 0 [ SA V V V V V ]
Feb 17 15:12:45 Gargoyle daemon.info syslog: 15[IKE] received XAuth vendor ID
Feb 17 15:12:45 Gargoyle daemon.info syslog: 15[IKE] received DPD vendor ID
Feb 17 15:12:45 Gargoyle daemon.info syslog: 15[IKE] received Cisco Unity vendor ID
Feb 17 15:12:45 Gargoyle daemon.info syslog: 15[IKE] received NAT-T (RFC 3947) vendor ID
Feb 17 15:12:45 Gargoyle daemon.info syslog: 15[IKE] received draft-ietf-ipsec-nat-t-ike-02\n vendor ID
Feb 17 15:12:45 Gargoyle daemon.info syslog: 15[IKE] 37.47.84.208 is initiating a Main Mode IKE_SA
Feb 17 15:12:45 Gargoyle authpriv.info syslog: 15[IKE] 37.47.84.208 is initiating a Main Mode IKE_SA
Feb 17 15:12:45 Gargoyle daemon.info syslog: 15[CFG] received proposals: IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CBC_192/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CBC_128/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CB
Feb 17 15:12:45 Gargoyle daemon.info syslog: 15[CFG] configured proposals: IKE:AES_CBC_128/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_2048, IKE:3DES_CBC/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1536, IKE:3DES_CBC/AES_CBC_128/AES_CBC_192/AES_CBC_256/HMAC_MD5_96/HMAC_SHA1_96/AES_XCBC_96/HMAC_S
Feb 17 15:12:45 Gargoyle daemon.info syslog: 15[NET] sending packet: from 192.168.1.2[500] to 37.47.84.208[21589] (56 bytes)
Feb 17 15:12:53 Gargoyle daemon.info syslog: 07[NET] received packet: from 37.47.84.208[12525] to 192.168.1.2[500] (528 bytes)
Feb 17 15:12:53 Gargoyle daemon.info syslog: 07[ENC] parsed ID_PROT request 0 [ SA V V V V V ]
Feb 17 15:12:53 Gargoyle daemon.info syslog: 07[IKE] received XAuth vendor ID
Feb 17 15:12:53 Gargoyle daemon.info syslog: 07[IKE] received DPD vendor ID
Feb 17 15:12:53 Gargoyle daemon.info syslog: 07[IKE] received Cisco Unity vendor ID
Feb 17 15:12:53 Gargoyle daemon.info syslog: 07[IKE] received NAT-T (RFC 3947) vendor ID
Feb 17 15:12:53 Gargoyle daemon.info syslog: 07[IKE] received draft-ietf-ipsec-nat-t-ike-02\n vendor ID
Feb 17 15:12:53 Gargoyle daemon.info syslog: 07[IKE] 37.47.84.208 is initiating a Main Mode IKE_SA
Feb 17 15:12:53 Gargoyle authpriv.info syslog: 07[IKE] 37.47.84.208 is initiating a Main Mode IKE_SA
Feb 17 15:12:53 Gargoyle daemon.info syslog: 07[CFG] received proposals: IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CBC_192/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CBC_128/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CB
Feb 17 15:12:53 Gargoyle daemon.info syslog: 07[CFG] configured proposals: IKE:AES_CBC_128/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_2048, IKE:3DES_CBC/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1536, IKE:3DES_CBC/AES_CBC_128/AES_CBC_192/AES_CBC_256/HMAC_MD5_96/HMAC_SHA1_96/AES_XCBC_96/HMAC_S
Feb 17 15:12:53 Gargoyle daemon.info syslog: 08[NET] received packet: from 37.47.84.208[12525] to 192.168.1.2[500] (528 bytes)
Feb 17 15:12:53 Gargoyle daemon.info syslog: 08[ENC] parsed ID_PROT request 0 [ SA V V V V V ]
Feb 17 15:12:53 Gargoyle daemon.info syslog: 08[IKE] received XAuth vendor ID
Feb 17 15:12:53 Gargoyle daemon.info syslog: 08[IKE] received DPD vendor ID
Feb 17 15:12:53 Gargoyle daemon.info syslog: 08[IKE] received Cisco Unity vendor ID
Feb 17 15:12:53 Gargoyle daemon.info syslog: 08[IKE] received NAT-T (RFC 3947) vendor ID
Feb 17 15:12:53 Gargoyle daemon.info syslog: 08[IKE] received draft-ietf-ipsec-nat-t-ike-02\n vendor ID
Feb 17 15:12:53 Gargoyle daemon.info syslog: 08[IKE] 37.47.84.208 is initiating a Main Mode IKE_SA
Feb 17 15:12:53 Gargoyle authpriv.info syslog: 08[IKE] 37.47.84.208 is initiating a Main Mode IKE_SA
Feb 17 15:12:53 Gargoyle daemon.info syslog: 08[CFG] received proposals: IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CBC_192/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CBC_128/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CB
Feb 17 15:12:53 Gargoyle daemon.info syslog: 08[CFG] configured proposals: IKE:AES_CBC_128/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_2048, IKE:3DES_CBC/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1536, IKE:3DES_CBC/AES_CBC_128/AES_CBC_192/AES_CBC_256/HMAC_MD5_96/HMAC_SHA1_96/AES_XCBC_96/HMAC_S
Feb 17 15:12:53 Gargoyle daemon.info syslog: 08[IKE] no proposal found
Feb 17 15:12:53 Gargoyle daemon.info syslog: 08[ENC] generating INFORMATIONAL_V1 request 2845322569 [ N(NO_PROP) ]
Feb 17 15:12:53 Gargoyle daemon.info syslog: 08[NET] sending packet: from 192.168.1.2[500] to 37.47.84.208[12525] (56 bytes)
Feb 17 15:15:38 Gargoyle daemon.info syslog: 08[NET] received packet: from 37.47.84.208[19507] to 192.168.1.2[500] (528 bytes)
Feb 17 15:15:38 Gargoyle daemon.info syslog: 08[ENC] parsed ID_PROT request 0 [ SA V V V V V ]
Feb 17 15:15:38 Gargoyle daemon.info syslog: 08[IKE] received XAuth vendor ID
Feb 17 15:15:38 Gargoyle daemon.info syslog: 08[IKE] received DPD vendor ID
Feb 17 15:15:38 Gargoyle daemon.info syslog: 08[IKE] received Cisco Unity vendor ID
Feb 17 15:15:38 Gargoyle daemon.info syslog: 08[IKE] received NAT-T (RFC 3947) vendor ID
Feb 17 15:15:38 Gargoyle daemon.info syslog: 08[IKE] received draft-ietf-ipsec-nat-t-ike-02\n vendor ID
Feb 17 15:15:38 Gargoyle daemon.info syslog: 08[IKE] 37.47.84.208 is initiating a Main Mode IKE_SA
Feb 17 15:15:38 Gargoyle authpriv.info syslog: 08[IKE] 37.47.84.208 is initiating a Main Mode IKE_SA
Feb 17 15:15:38 Gargoyle daemon.info syslog: 08[CFG] received proposals: IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CBC_192/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CBC_128/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CB
Feb 17 15:15:38 Gargoyle daemon.info syslog: 08[CFG] configured proposals: IKE:AES_CBC_128/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_2048, IKE:3DES_CBC/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1536, IKE:3DES_CBC/AES_CBC_128/AES_CBC_192/AES_CBC_256/HMAC_MD5_96/HMAC_SHA1_96/AES_XCBC_96/HMAC_S
Feb 17 15:15:38 Gargoyle daemon.info syslog: 08[IKE] no proposal found
Feb 17 15:15:38 Gargoyle daemon.info syslog: 08[ENC] generating INFORMATIONAL_V1 request 2606155651 [ N(NO_PROP) ]
Feb 17 15:15:38 Gargoyle daemon.info syslog: 08[NET] sending packet: from 192.168.1.2[500] to 37.47.84.208[19507] (56 bytes)
Feb 17 15:15:45 Gargoyle daemon.info syslog: 05[NET] received packet: from 37.47.84.208[6561] to 192.168.1.2[500] (528 bytes)
Feb 17 15:15:45 Gargoyle daemon.info syslog: 05[ENC] parsed ID_PROT request 0 [ SA V V V V V ]
Feb 17 15:15:45 Gargoyle daemon.info syslog: 05[IKE] received XAuth vendor ID
Feb 17 15:15:45 Gargoyle daemon.info syslog: 05[IKE] received DPD vendor ID
Feb 17 15:15:45 Gargoyle daemon.info syslog: 05[IKE] received Cisco Unity vendor ID
Feb 17 15:15:45 Gargoyle daemon.info syslog: 05[IKE] received NAT-T (RFC 3947) vendor ID
Feb 17 15:15:45 Gargoyle daemon.info syslog: 05[IKE] received draft-ietf-ipsec-nat-t-ike-02\n vendor ID
Feb 17 15:15:45 Gargoyle daemon.info syslog: 05[IKE] 37.47.84.208 is initiating a Main Mode IKE_SA
Feb 17 15:15:45 Gargoyle authpriv.info syslog: 05[IKE] 37.47.84.208 is initiating a Main Mode IKE_SA
Feb 17 15:15:45 Gargoyle daemon.info syslog: 05[CFG] received proposals: IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CBC_192/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CBC_128/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CB
Feb 17 15:15:45 Gargoyle daemon.info syslog: 05[CFG] configured proposals: IKE:AES_CBC_128/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_2048, IKE:3DES_CBC/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1536, IKE:3DES_CBC/AES_CBC_128/AES_CBC_192/AES_CBC_256/HMAC_MD5_96/HMAC_SHA1_96/AES_XCBC_96/HMAC_S
Feb 17 15:15:45 Gargoyle daemon.info syslog: 05[IKE] no proposal found
Feb 17 15:15:45 Gargoyle daemon.info syslog: 05[ENC] generating INFORMATIONAL_V1 request 1929300407 [ N(NO_PROP) ]
Feb 17 15:15:45 Gargoyle daemon.info syslog: 05[NET] sending packet: from 192.168.1.2[500] to 37.47.84.208[6561] (56 bytes)
Feb 17 15:16:20 Gargoyle authpriv.info ipsec_starter[7028]: Starting strongSwan 5.1.3 IPsec [starter]...
Feb 17 15:16:20 Gargoyle authpriv.info ipsec_starter[7028]: charon is already running (/var/run/charon.pid exists) -- skipping daemon start
Feb 17 15:16:20 Gargoyle authpriv.info ipsec_starter[7028]: starter is already running (/var/run/starter.charon.pid exists) -- no fork done
Feb 17 15:20:36 Gargoyle daemon.info hostapd: wlan0: STA 74:e5:43:24:04:6b WPA: group key handshake completed (WPA)
Feb 17 15:22:33 Gargoyle daemon.info syslog: 08[NET] received packet: from 37.47.84.208[9454] to 192.168.1.2[500] (528 bytes)
Feb 17 15:22:33 Gargoyle daemon.info syslog: 08[ENC] parsed ID_PROT request 0 [ SA V V V V V ]
Feb 17 15:22:33 Gargoyle daemon.info syslog: 08[IKE] received XAuth vendor ID
Feb 17 15:22:33 Gargoyle daemon.info syslog: 08[IKE] received DPD vendor ID
Feb 17 15:22:33 Gargoyle daemon.info syslog: 08[IKE] received Cisco Unity vendor ID
Feb 17 15:22:33 Gargoyle daemon.info syslog: 08[IKE] received NAT-T (RFC 3947) vendor ID
Feb 17 15:22:33 Gargoyle daemon.info syslog: 08[IKE] received draft-ietf-ipsec-nat-t-ike-02\n vendor ID
Feb 17 15:22:33 Gargoyle daemon.info syslog: 08[IKE] 37.47.84.208 is initiating a Main Mode IKE_SA
Feb 17 15:22:33 Gargoyle authpriv.info syslog: 08[IKE] 37.47.84.208 is initiating a Main Mode IKE_SA
Feb 17 15:22:33 Gargoyle daemon.info syslog: 08[CFG] received proposals: IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CBC_192/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CBC_128/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CB
Feb 17 15:22:33 Gargoyle daemon.info syslog: 08[CFG] configured proposals: IKE:AES_CBC_128/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_2048, IKE:3DES_CBC/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1536, IKE:3DES_CBC/AES_CBC_128/AES_CBC_192/AES_CBC_256/HMAC_MD5_96/HMAC_SHA1_96/AES_XCBC_96/HMAC_S
Succe

19

Odp: strongSwan za NATem

Wie ktoś może co jest nie tak?

Feb 20 12:18:16 Gargoyle daemon.info syslog: 14[NET] received packet: from 37.47.124.110[24525] to 192.168.1.2[500] (528 bytes)
Feb 20 12:18:16 Gargoyle daemon.info syslog: 14[ENC] parsed ID_PROT request 0 [ SA V V V V V ]
Feb 20 12:18:16 Gargoyle daemon.info syslog: 14[IKE] no IKE config found for 192.168.1.2...37.47.124.110, sending NO_PROPOSAL_CHOSEN
Feb 20 12:18:16 Gargoyle daemon.info syslog: 14[ENC] generating INFORMATIONAL_V1 request 3210370458 [ N(NO_PROP) ]
Feb 20 12:18:16 Gargoyle daemon.info syslog: 14[NET] sending packet: from 192.168.1.2[500] to 37.47.124.110[24525] (40 bytes)
Success

20

Odp: strongSwan za NATem

mam dokładnie taki sam problem
"no IKE config found for..."

ktoś rozwiązał taki problem?

21

Odp: strongSwan za NATem

kidler napisał/a:

mam dokładnie taki sam problem
"no IKE config found for..."

ktoś rozwiązał taki problem?

wklej konfigi ja z tym walczylem i udalo mi sie