Господа , пытаюсь поднять тоннель межу cisco и linux
не проходит первая фаза со стороны cisco:
crypto isakmp policy 20
encr 3des
authentication pre-share
group 2
со стороны linux suse:
remote 10.136.104.126
{
exchange_mode main,aggressive;
initial_contact off;
proposal {
encryption_algorithm 3des;
hash_algorithm sha1;
authentication_method pre_shared_key;
dh_group 2;
}
}
в логах линукса:
Jul 23 16:02:41 router racoon: ERROR: no suitable proposal found.
Jul 23 16:02:41 router racoon: ERROR: failed to get valid proposal.
Jul 23 16:02:41 router racoon: ERROR: failed to pre-process packet.
Jul 23 16:02:41 router racoon: ERROR: phase1 negotiation failed.
в логах кошки:
Nov 12 12:00:12.451: ISAKMP (0): incrementing error counter on sa, attempt 1 of 5: retransmit phase 1
Nov 12 12:00:12.451: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE
Nov 12 12:00:12.451: ISAKMP:(0): sending packet to 10.136.181.145 my_port 500 peer_port 500 (I) MM_NO_STATE
Nov 12 12:00:12.451: ISAKMP:(0):Sending an IKE IPv4 Packet.
Nov 12 12:00:22.451: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE...
Nov 12 12:00:22.451: ISAKMP (0): incrementing error counter on sa, attempt 2 of 5: retransmit phase 1
Nov 12 12:00:22.451: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE
Nov 12 12:00:22.451: ISAKMP:(0): sending packet to 10.136.181.145 my_port 500 peer_port 500 (I) MM_NO_STATE
Nov 12 12:00:22.451: ISAKMP:(0):Sending an IKE IPv4 Packet.
Nov 12 12:00:22.455: ISAKMP:(0):purging node -1100773691
Nov 12 12:00:22.455: ISAKMP:(0):purging node -967412064
Nov 12 12:00:22.455: ISAKMP:(0):purging node -456892372
Nov 12 12:00:32.451: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE...
Nov 12 12:00:32.451: ISAKMP (0): incrementing error counter on sa, attempt 3 of 5: retransmit phase 1
Nov 12 12:00:32.451: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE
Nov 12 12:00:32.451: ISAKMP:(0): sending packet to 10.136.181.145 my_port 500 peer_port 500 (I) MM_NO_STATE
Nov 12 12:00:32.451: ISAKMP:(0):Sending an IKE IPv4 Packet.
Nov 12 12:00:32.451: ISAKMP: set new node 0 to QM_IDLE
Nov 12 12:00:32.451: ISAKMP:(0):SA is still budding. Attached new ipsec request to it. (local 10.136.104.126, remote 10.136.181.145)
Nov 12 12:00:32.451: ISAKMP: Error while processing SA request: Failed to initialize SA
Nov 12 12:00:32.451: ISAKMP: Error while processing KMI message 0, error 2.
Nov 12 12:00:32.455: ISAKMP:(0):purging SA., sa=2A2D7094, delme=2A2D7094
оперировал вот этой статьей http://inhibitz.ucoz.ru/publ/2-1-0-18
в чем может быть беда?