Quantcast
Channel: Sophos User Bulletin Board
Viewing all articles
Browse latest Browse all 14361

[9.000-8] Android L2TP-IPsec-VPN Connection Problem

$
0
0
Hi,

We are trying to set up a L2TP-IPsec-VPN with an Android 4.0.3 Phone (Samsung Galaxy S2).
A Connection to this VPN with an iphone works without any problems even when using the android-phone as mobile hotspot. So the UMTS-Connection should be fine.
When trying to connect the Android phone we are getting the following log-entries:
Code:

2012:07:25-09:48:24 astaro-1 pluto[16075]: packet from 109.84.0.102:60596: received Vendor ID payload [RFC 3947]
2012:07:25-09:48:24 astaro-1 pluto[16075]: packet from 109.84.0.102:60596: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02]
2012:07:25-09:48:24 astaro-1 pluto[16075]: packet from 109.84.0.102:60596: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n]
2012:07:25-09:48:24 astaro-1 pluto[16075]: packet from 109.84.0.102:60596: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]
2012:07:25-09:48:24 astaro-1 pluto[16075]: packet from 109.84.0.102:60596: ignoring Vendor ID payload [FRAGMENTATION 80000000]
2012:07:25-09:48:24 astaro-1 pluto[16075]: packet from 109.84.0.102:60596: received Vendor ID payload [Dead Peer Detection]
2012:07:25-09:48:24 astaro-1 pluto[16075]: "S_for L2TP-IPsec-VPN-User"[3] 109.84.0.102:60596 #2: responding to Main Mode from unknown peer 109.84.0.102:60596
2012:07:25-09:48:24 astaro-1 pluto[16075]: "S_for L2TP-IPsec-VPN-User"[3] 109.84.0.102:60596 #2: NAT-Traversal: Result using RFC 3947: peer is NATed
2012:07:25-09:48:25 astaro-1 pluto[16075]: "S_for L2TP-IPsec-VPN-User"[3] 109.84.0.102:60596 #2: Peer ID is ID_IPV4_ADDR: '10.7.196.102'
2012:07:25-09:48:25 astaro-1 pluto[16075]: "S_for L2TP-IPsec-VPN-User"[4] 109.84.0.102:60596 #2: deleting connection "S_for L2TP-IPsec-VPN-User"[3] instance with peer 109.84.0.102 {isakmp=#0/ipsec=#0}
2012:07:25-09:48:25 astaro-1 pluto[16075]: "S_for L2TP-IPsec-VPN-User"[4] 109.84.0.102:60596 #2: Dead Peer Detection (RFC 3706) enabled
2012:07:25-09:48:25 astaro-1 pluto[16075]: | NAT-T: new mapping 109.84.0.102:60596/47551)
2012:07:25-09:48:25 astaro-1 pluto[16075]: "S_for L2TP-IPsec-VPN-User"[4] 109.84.0.102:47551 #2: sent MR3, ISAKMP SA established
2012:07:25-09:48:25 astaro-1 pluto[16075]: "S_for L2TP-IPsec-VPN-User"[4] 109.84.0.102:47551 #2: ignoring informational payload, type IPSEC_INITIAL_CONTACT
2012:07:25-09:48:25 astaro-1 pluto[16075]: "S_for L2TP-IPsec-VPN-User"[4] 109.84.0.102:47551 #2: byte 7 of ISAKMP NAT-OA Payload must be zero, but is not
2012:07:25-09:48:25 astaro-1 pluto[16075]: "S_for L2TP-IPsec-VPN-User"[4] 109.84.0.102:47551 #2: malformed payload in packet
2012:07:25-09:48:25 astaro-1 pluto[16075]: "S_for L2TP-IPsec-VPN-User"[4] 109.84.0.102:47551 #2: sending encrypted notification PAYLOAD_MALFORMED to 109.84.0.102:47551
2012:07:25-09:48:28 astaro-1 pluto[16075]: "S_for L2TP-IPsec-VPN-User"[4] 109.84.0.102:47551 #2: Quick Mode I1 message is unacceptable because it uses a previously used Message ID 0x88a0b2df (perhaps this is a duplicated packet)
.....
2012:07:25-09:48:49 astaro-1 pluto[16075]: "S_for L2TP-IPsec-VPN-User"[4] 109.84.0.102:47551 #2: sending encrypted notification INVALID_MESSAGE_ID to 109.84.0.102:47551
2012:07:25-09:48:52 astaro-1 pluto[16075]: "S_for L2TP-IPsec-VPN-User"[4] 109.84.0.102:47551 #2: Quick Mode I1 message is unacceptable because it uses a previously used Message ID 0x88a0b2df (perhaps this is a duplicated packet)
2012:07:25-09:48:52 astaro-1 pluto[16075]: "S_for L2TP-IPsec-VPN-User"[4] 109.84.0.102:47551 #2: sending encrypted notification INVALID_MESSAGE_ID to 109.84.0.102:47551
2012:07:25-09:48:57 astaro-1 pluto[16075]: "S_for L2TP-IPsec-VPN-User"[4] 109.84.0.102:47551 #2: byte 7 of ISAKMP NAT-OA Payload must be zero, but is not
2012:07:25-09:48:57 astaro-1 pluto[16075]: "S_for L2TP-IPsec-VPN-User"[4] 109.84.0.102:47551 #2: malformed payload in packet
2012:07:25-09:48:57 astaro-1 pluto[16075]: "S_for L2TP-IPsec-VPN-User"[4] 109.84.0.102:47551 #2: sending encrypted notification PAYLOAD_MALFORMED to 109.84.0.102:47551
2012:07:25-09:49:00 astaro-1 pluto[16075]: "S_for L2TP-IPsec-VPN-User"[4] 109.84.0.102:47551 #2: Quick Mode I1 message is unacceptable because it uses a previously used Message ID 0x2057f3f5 (perhaps this is a duplicated packet)
....
2012:07:25-09:49:21 astaro-1 pluto[16075]: "S_for L2TP-IPsec-VPN-User"[4] 109.84.0.102:47551 #2: sending encrypted notification INVALID_MESSAGE_ID to 109.84.0.102:47551
2012:07:25-09:49:24 astaro-1 pluto[16075]: "S_for L2TP-IPsec-VPN-User"[4] 109.84.0.102:47551 #2: Quick Mode I1 message is unacceptable because it uses a previously used Message ID 0x2057f3f5 (perhaps this is a duplicated packet)
2012:07:25-09:49:24 astaro-1 pluto[16075]: "S_for L2TP-IPsec-VPN-User"[4] 109.84.0.102:47551 #2: sending encrypted notification INVALID_MESSAGE_ID to 109.84.0.102:47551
2012:07:25-09:49:51 astaro-1 pluto[16075]: ERROR: asynchronous network error report on eth1 for message to 109.84.0.102 port 47551, complainant 109.84.0.102: Connection refused [errno 111, origin ICMP type 3 code 3 (not authenticated)]
....
2012:07:25-09:51:25 astaro-1 pluto[16075]: ERROR: asynchronous network error report on eth1 for message to 109.84.0.102 port 47551, complainant 109.84.0.102: Connection refused [errno 111, origin ICMP type 3 code 3 (not authenticated)]
2012:07:25-09:51:51 astaro-1 pluto[16075]: "S_for L2TP-IPsec-VPN-User"[4] 109.84.0.102:47551 #2: DPD: No response from peer - declaring peer dead
2012:07:25-09:51:51 astaro-1 pluto[16075]: "S_for L2TP-IPsec-VPN-User"[4] 109.84.0.102:47551 #2: DPD: Terminating all SAs using this connection
2012:07:25-09:51:51 astaro-1 pluto[16075]: "S_for L2TP-IPsec-VPN-User"[4] 109.84.0.102:47551 #2: deleting connection "S_for L2TP-IPsec-VPN-User"[4] instance with peer 109.84.0.102 {isakmp=#2/ipsec=#0}
2012:07:25-09:51:51 astaro-1 pluto[16075]: "S_for L2TP-IPsec-VPN-User" #2: deleting state (STATE_MAIN_R3)
2012:07:25-09:51:55 astaro-1 pluto[16075]: ERROR: asynchronous network error report on eth1 for message to 109.84.0.102 port 47551, complainant 109.84.0.102: Connection refused [errno 111, origin ICMP type 3 code 3 (not authenticated)]

The ASG320 is connected directly to the internet.
Any suggestions?

Intruder73

Viewing all articles
Browse latest Browse all 14361

Trending Articles