Hello everyone.
Based on the following http://forums.freebsd.org/showthread.php?t=26755 I tried to setup a l2tp/ipsec server based on FreeBSD 9.0 with strongswan 5.0.0.
My network looks like this:
[ISP]->[FREEBSD 9.0 re0 public em0 private) em0 is in 192.168.1/0.
Trying to connect from outside (from another isp) the ike steps succeeds but mpd does not receive any traffic:
When I connect from a (network bridged to 192.168.1.0/24 virtualbox) Windows 7 to my external ip l2tp does get traffic and sets up an interface.
This look like this in the log:
and the mpd log:
I do not have any idea, the only difference to me seems to be the remote subnet is of another class, I have not the possible to check from a similar remote subnet.
I'm using pf after trying ipfw with the same result. I've set up a setkey.conf to require esp over 1701, and I'm allowing enc0 and esp,ah.
Any clues are highly appreciated.
Best regards.
Based on the following http://forums.freebsd.org/showthread.php?t=26755 I tried to setup a l2tp/ipsec server based on FreeBSD 9.0 with strongswan 5.0.0.
My network looks like this:
[ISP]->[FREEBSD 9.0 re0 public em0 private) em0 is in 192.168.1/0.
Trying to connect from outside (from another isp) the ike steps succeeds but mpd does not receive any traffic:
Code:
IKE_SA l2tp[8] established between x.x.x.x[x.x.x.x]...y.y.y.y[10.95.1.2]
Sep 18 18:46:04 hostname charon: 01[IKE] deleting IKE_SA l2tp[8] between x.x.x.x[x.x.x.x]...y.y.y.y[10.95.1.2]
When I connect from a (network bridged to 192.168.1.0/24 virtualbox) Windows 7 to my external ip l2tp does get traffic and sets up an interface.
This look like this in the log:
Code:
Sep 18 19:20:18 hostname charon: 13[IKE] 192.168.1.147 is initiating a Main Mode IKE_SA
Sep 18 19:20:19 hostname charon: 09[IKE] IKE_SA l2tp[10] established between x.x.x.x[x.x.x.x]...192.168.1.147[192.168.1.147]
Sep 18 19:20:19 hostname charon: 10[IKE] CHILD_SA l2tp{5} established with SPIs cb460e16_i 4c4c6c5d_o and TS x.x.x.x/32[udp/l2f] === 192.168.1.147/32[udp/l2f]
and the mpd log:
Code:
x mpd: [L_l2tp-1] LCP: authorization successful
Sep 18 19:20:22 hostname mpd: [L_l2tp-1] Link: Matched action 'bundle "B_l2tp" ""'
Sep 18 19:20:22 hostname mpd: [L_l2tp-1] Creating new bundle using template "B_l2tp".
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] Bundle: Interface ng0 created
Sep 18 19:20:22 hostname mpd: [L_l2tp-1] Link: Join bundle "B_l2tp-1"
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] Bundle: Status update: up 1 link, total bandwidth 64000 bps
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPCP: Open event
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPCP: state change Initial --> Starting
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPCP: LayerStart
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPCP: Up event
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPCP: Got IP 192.168.1.200 from pool "pool_l2tp" for peer
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPCP: state change Starting --> Req-Sent
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPCP: SendConfigReq #1
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPADDR x.x.x.x
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] COMPPROTO VJCOMP, 16 comp. channels, no comp-cid
Sep 18 19:20:22 hostname mpd: [L_l2tp-1] rec'd unexpected protocol IPV6CP, rejecting
Sep 18 19:20:22 hostname mpd: [L_l2tp-1] rec'd unexpected protocol CCP, rejecting
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPCP: rec'd Configure Request #7 (Req-Sent)
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPADDR 0.0.0.0
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] NAKing with 192.168.1.200
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] PRIDNS 0.0.0.0
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] NAKing with 192.168.1.1
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] PRINBNS 0.0.0.0
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] SECDNS 0.0.0.0
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] SECNBNS 0.0.0.0
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPCP: SendConfigRej #7
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] PRINBNS 0.0.0.0
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] SECDNS 0.0.0.0
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] SECNBNS 0.0.0.0
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPCP: rec'd Configure Reject #1 (Req-Sent)
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] COMPPROTO VJCOMP, 16 comp. channels, no comp-cid
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPCP: SendConfigReq #2
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPADDR x.x.x.x
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPCP: rec'd Configure Request #8 (Req-Sent)
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPADDR 0.0.0.0
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] NAKing with 192.168.1.200
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] PRIDNS 0.0.0.0
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] NAKing with 192.168.1.1
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPCP: SendConfigNak #8
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPADDR 192.168.1.200
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] PRIDNS 192.168.1.1
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPCP: rec'd Configure Ack #2 (Req-Sent)
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPADDR x.x.x.x
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPCP: state change Req-Sent --> Ack-Rcvd
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPCP: rec'd Configure Request #9 (Ack-Rcvd)
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPADDR 192.168.1.200
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] 192.168.1.200 is OK
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] PRIDNS 192.168.1.1
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPCP: SendConfigAck #9
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPADDR 192.168.1.200
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] PRIDNS 192.168.1.1
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPCP: state change Ack-Rcvd --> Opened
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IPCP: LayerUp
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] x.x.x.x -> 192.168.1.200
Sep 18 19:20:22 hostname mpd: [B_l2tp-1] IFACE: Up event
I'm using pf after trying ipfw with the same result. I've set up a setkey.conf to require esp over 1701, and I'm allowing enc0 and esp,ah.
Any clues are highly appreciated.
Best regards.