Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 03 Jul 2001 11:35:33 -0400
From:      "Eric Ste-Marie" <eric@ste-marie.ca>
To:        freebsd-questions@freebsd.org
Subject:   IPSec phase1 problem
Message-ID:  <3B41E645.FC740EFA@ste-marie.ca>

next in thread | raw e-mail | index | archive | help
WHen I try to initiate an IPSEc connection,

I get the following in debug:


(lifetime = 28800:28800)
(lifebyte = 0:0)
enctype = DES-CBC:DES-CBC
(encklen = 0:0)
hashtype = MD5:MD5
authmethod = pre-shared key:pre-shared key
dh_group = 768-bit MODP group:768-bit MODP group
acceptable proposal found.



but then :
 ERROR: oakley.c:1150:oakley_validate_auth(): HASH mismatched



Any idea where what the problem can be?

Where can I get the source for oakley.c?

Someone can explain to me why, since I use dh group1, oackley is used
here?  Is it because oakley and dh share the same groups?

Note that the remote VPN is Nortel contivity agressive mode

Thanks.

-Eric




To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3B41E645.FC740EFA>