Hello,
I am struggling putting up a tunnel (Site-to-site\IPsec) between UTM9 and a Watchguard box.
I read various posts but I yet to see if anyone has actually succeeded.
NAT Traversal is disabled on UTM9 and Watchguard.
I have attached screen-shots of my setting so that you can see what I have done from the UTM9 side. Similar policy settings is in place on the Watchguard.
Additionally this is the log I see
2012:08:15-14:45:41 SophosUTM9-1 pluto[22074]: "S_ADSL" #1093: discarding duplicate packet; already STATE_MAIN_I3
2012:08:15-14:45:44 SophosUTM9-1 pluto[22074]: "S_ADSL" #1093: discarding duplicate packet; already STATE_MAIN_I3
2012:08:15-14:46:46 SophosUTM9-1 pluto[22074]: "S_ADSL" #1093: max number of retransmissions (2) reached STATE_MAIN_I3. Possible authentication failure: no acceptable response to our first encrypted message
2012:08:15-14:46:46 SophosUTM9-1 pluto[22074]: "S_ADSL" #1093: starting keying attempt 1094 of an unlimited number
2012:08:15-14:46:46 SophosUTM9-1 pluto[22074]: "S_ADSL" #1094: initiating Main Mode to replace #1093
2012:08:15-14:46:47 SophosUTM9-1 pluto[22074]: "S_ADSL" #1094: received Vendor ID payload [XAUTH]
2012:08:15-14:46:47 SophosUTM9-1 pluto[22074]: "S_ADSL" #1094: received Vendor ID payload [Dead Peer Detection]
2012:08:15-14:46:49 SophosUTM9-1 pluto[22074]: "S_ADSL" #1094: discarding duplicate packet; already STATE_MAIN_I3
2012:08:15-14:46:52 SophosUTM9-1 pluto[22074]: "S_ADSL" #1094: discarding duplicate packet; already STATE_MAIN_I3
2012:08:15-14:46:55 SophosUTM9-1 pluto[22074]: "S_ADSL" #1094: discarding duplicate packet; already STATE_MAIN_I3
2012:08:15-14:47:57 SophosUTM9-1 pluto[22074]: "S_ADSL" #1094: max number of retransmissions (2) reached STATE_MAIN_I3. Possible authentication failure: no acceptable response to our first encrypted message
2012:08:15-14:47:57 SophosUTM9-1 pluto[22074]: "S_ADSL" #1094: starting keying attempt 1095 of an unlimited number
2012:08:15-14:47:57 SophosUTM9-1 pluto[22074]: "S_ADSL" #1095: initiating Main Mode to replace #1094
2012:08:15-14:47:57 SophosUTM9-1 pluto[22074]: "S_ADSL" #1095: received Vendor ID payload [XAUTH]
2012:08:15-14:47:57 SophosUTM9-1 pluto[22074]: "S_ADSL" #1095: received Vendor ID payload [Dead Peer Detection]
2012:08:15-14:48:00 SophosUTM9-1 pluto[22074]: "S_ADSL" #1095: discarding duplicate packet; already STATE_MAIN_I3
2012:08:15-14:48:04 SophosUTM9-1 pluto[22074]: "S_ADSL" #1095: discarding duplicate packet; already STATE_MAIN_I3
2012:08:15-14:48:06 SophosUTM9-1 pluto[22074]: "S_ADSL" #1095: discarding duplicate packet; already STATE_MAIN_I3[/I]
Any idea anyone?
Regards
orbi
I am struggling putting up a tunnel (Site-to-site\IPsec) between UTM9 and a Watchguard box.
I read various posts but I yet to see if anyone has actually succeeded.
NAT Traversal is disabled on UTM9 and Watchguard.
I have attached screen-shots of my setting so that you can see what I have done from the UTM9 side. Similar policy settings is in place on the Watchguard.
Additionally this is the log I see
2012:08:15-14:45:41 SophosUTM9-1 pluto[22074]: "S_ADSL" #1093: discarding duplicate packet; already STATE_MAIN_I3
2012:08:15-14:45:44 SophosUTM9-1 pluto[22074]: "S_ADSL" #1093: discarding duplicate packet; already STATE_MAIN_I3
2012:08:15-14:46:46 SophosUTM9-1 pluto[22074]: "S_ADSL" #1093: max number of retransmissions (2) reached STATE_MAIN_I3. Possible authentication failure: no acceptable response to our first encrypted message
2012:08:15-14:46:46 SophosUTM9-1 pluto[22074]: "S_ADSL" #1093: starting keying attempt 1094 of an unlimited number
2012:08:15-14:46:46 SophosUTM9-1 pluto[22074]: "S_ADSL" #1094: initiating Main Mode to replace #1093
2012:08:15-14:46:47 SophosUTM9-1 pluto[22074]: "S_ADSL" #1094: received Vendor ID payload [XAUTH]
2012:08:15-14:46:47 SophosUTM9-1 pluto[22074]: "S_ADSL" #1094: received Vendor ID payload [Dead Peer Detection]
2012:08:15-14:46:49 SophosUTM9-1 pluto[22074]: "S_ADSL" #1094: discarding duplicate packet; already STATE_MAIN_I3
2012:08:15-14:46:52 SophosUTM9-1 pluto[22074]: "S_ADSL" #1094: discarding duplicate packet; already STATE_MAIN_I3
2012:08:15-14:46:55 SophosUTM9-1 pluto[22074]: "S_ADSL" #1094: discarding duplicate packet; already STATE_MAIN_I3
2012:08:15-14:47:57 SophosUTM9-1 pluto[22074]: "S_ADSL" #1094: max number of retransmissions (2) reached STATE_MAIN_I3. Possible authentication failure: no acceptable response to our first encrypted message
2012:08:15-14:47:57 SophosUTM9-1 pluto[22074]: "S_ADSL" #1094: starting keying attempt 1095 of an unlimited number
2012:08:15-14:47:57 SophosUTM9-1 pluto[22074]: "S_ADSL" #1095: initiating Main Mode to replace #1094
2012:08:15-14:47:57 SophosUTM9-1 pluto[22074]: "S_ADSL" #1095: received Vendor ID payload [XAUTH]
2012:08:15-14:47:57 SophosUTM9-1 pluto[22074]: "S_ADSL" #1095: received Vendor ID payload [Dead Peer Detection]
2012:08:15-14:48:00 SophosUTM9-1 pluto[22074]: "S_ADSL" #1095: discarding duplicate packet; already STATE_MAIN_I3
2012:08:15-14:48:04 SophosUTM9-1 pluto[22074]: "S_ADSL" #1095: discarding duplicate packet; already STATE_MAIN_I3
2012:08:15-14:48:06 SophosUTM9-1 pluto[22074]: "S_ADSL" #1095: discarding duplicate packet; already STATE_MAIN_I3[/I]
Any idea anyone?
Regards
orbi