help needed setting up a IPSec VPN Please
Posted: Thu Jul 24, 2014 5:28 pm
Hi, I'm attempting to setup a LAN to LAN IPSec VPN between my Billion 7800dx and my friend's TP-Link TD-W8970 but am having problems, the settings I'm using are shown in the screens attached steve.jpg is my end, tony.jpg is his - there is one further setting on the TD-W8970 which is IPSec VPN passthrough and is set to disable.
In the log of my 7800dx there are the following entries- can anyone point out where I've gone wrong please, I'm using 2.32d firmware?
Jul 24 16:34:12 authpriv warn pluto[9677]: "tony": deleting connection
Jul 24 16:34:12 authpriv warn pluto[9677]: "tony" #1: deleting state (STATE_MAIN_I1)
Jul 24 16:34:13 daemon err ipsec_setup: Stopping Openswan IPsec...
Jul 24 16:34:13 authpriv warn pluto[9677]: shutting down
Jul 24 16:34:13 authpriv warn pluto[9677]: forgetting secrets
Jul 24 16:34:13 authpriv warn pluto[9677]: shutting down interface lo/lo ::1:500
Jul 24 16:34:13 authpriv warn pluto[9677]: shutting down interface lo/lo 127.0.0.1:4500
Jul 24 16:34:13 authpriv warn pluto[9677]: shutting down interface lo/lo 127.0.0.1:500
Jul 24 16:34:13 authpriv warn pluto[9677]: shutting down interface br0/br0 192.168.1.254:4500
Jul 24 16:34:13 authpriv warn pluto[9677]: shutting down interface br0/br0 192.168.1.254:500
Jul 24 16:34:13 authpriv warn pluto[9677]: shutting down interface pppoa0/pppoa0 (My Wan IP):4500
Jul 24 16:34:13 authpriv warn pluto[9677]: shutting down interface pppoa0/pppoa0 (My Wan IP):500
Jul 24 16:34:13 authpriv warn pluto[9683]: pluto_crypto_helper: helper (0) is normal exiting
Jul 24 16:34:14 daemon err ipsec_setup: ...Openswan IPsec stopped
Jul 24 16:34:15 daemon err ipsec_setup: Starting Openswan IPsec U2.6.38/K2.6.30...
Jul 24 16:34:16 daemon err ipsec_setup: Using NETKEY(XFRM) stack
Jul 24 16:34:17 authpriv err ipsec__plutorun: Starting Pluto subsystem...
Jul 24 16:34:17 user warn syslog: adjusting ipsec.d to /var/ipsec.d
Jul 24 16:34:17 authpriv warn pluto[10802]: WARNING: 1DES is enabled
Jul 24 16:34:17 authpriv warn pluto[10802]: LEAK_DETECTIVE support [disabled]
Jul 24 16:34:17 authpriv warn pluto[10802]: OCF support for IKE [disabled]
Jul 24 16:34:17 authpriv warn pluto[10802]: NSS support [disabled]
Jul 24 16:34:17 authpriv warn pluto[10802]: HAVE_STATSD notification support not compiled in
Jul 24 16:34:18 authpriv warn pluto[10802]: Setting NAT-Traversal port-4500 floating to on
Jul 24 16:34:18 authpriv warn pluto[10802]: port floating activation criteria nat_t=1/port_float=1
Jul 24 16:34:18 authpriv warn pluto[10802]: NAT-Traversal support [enabled]
Jul 24 16:34:18 authpriv warn pluto[10802]: using /dev/urandom as source of random entropy
Jul 24 16:34:18 daemon err ipsec__plutorun: adjusting ipsec.d to /var/ipsec.d
Jul 24 16:34:18 authpriv warn pluto[10802]: starting up 1 cryptographic helpers
Jul 24 16:34:18 authpriv warn pluto[10802]: started helper pid=10808 (fd:6)
Jul 24 16:34:18 authpriv warn pluto[10808]: using /dev/urandom as source of random entropy
Jul 24 16:34:18 daemon err ipsec_setup: ...Openswan IPsec started
Jul 24 16:34:20 authpriv warn pluto[10802]: Could not change to directory '/var/ipsec.d/cacerts': No such file or directory
Jul 24 16:34:20 authpriv warn pluto[10802]: Could not change to directory '/var/ipsec.d/aacerts': No such file or directory
Jul 24 16:34:20 authpriv warn pluto[10802]: Could not change to directory '/var/ipsec.d/ocspcerts': No such file or directory
Jul 24 16:34:20 authpriv warn pluto[10802]: Could not change to directory '/var/ipsec.d/crls': 2 No such file or directory
Jul 24 16:34:20 authpriv warn pluto[10802]: added connection description "tony"
Jul 24 16:34:20 daemon err ipsec__plutorun: 002 added connection description "tony"
Jul 24 16:34:20 authpriv warn pluto[10802]: listening for IKE messages
Jul 24 16:34:20 authpriv warn pluto[10802]: adding interface pppoa0/pppoa0 (My Wan IP):500
Jul 24 16:34:20 authpriv warn pluto[10802]: adding interface pppoa0/pppoa0 (my Wan IP):4500
Jul 24 16:34:20 authpriv warn pluto[10802]: adding interface br0/br0 192.168.1.254:500
Jul 24 16:34:20 authpriv warn pluto[10802]: adding interface br0/br0 192.168.1.254:4500
Jul 24 16:34:20 authpriv warn pluto[10802]: adding interface lo/lo 127.0.0.1:500
Jul 24 16:34:20 authpriv warn pluto[10802]: adding interface lo/lo 127.0.0.1:4500
Jul 24 16:34:20 authpriv warn pluto[10802]: adding interface lo/lo ::1:500
Jul 24 16:34:20 authpriv warn pluto[10802]: loading secrets from "/var/ipsec.secrets"
Jul 24 16:34:22 authpriv warn pluto[10802]: "tony": deleting connection
Jul 24 16:34:22 authpriv warn pluto[10802]: added connection description "tony"
Jul 24 16:34:22 authpriv warn pluto[10802]: "tony" #1: initiating Main Mode
Jul 24 16:34:32 authpriv warn pluto[10802]: "tony": deleting connection
Jul 24 16:34:32 authpriv warn pluto[10802]: "tony" #1: deleting state (STATE_MAIN_I1)
Jul 24 16:34:33 daemon err ipsec_setup: Stopping Openswan IPsec...
Jul 24 16:34:33 authpriv warn pluto[10802]: shutting down
Jul 24 16:34:33 authpriv warn pluto[10802]: forgetting secrets
Jul 24 16:34:33 authpriv warn pluto[10802]: shutting down interface lo/lo ::1:500
Jul 24 16:34:33 authpriv warn pluto[10802]: shutting down interface lo/lo 127.0.0.1:4500
Jul 24 16:34:33 authpriv warn pluto[10802]: shutting down interface lo/lo 127.0.0.1:500
Jul 24 16:34:33 authpriv warn pluto[10802]: shutting down interface br0/br0 192.168.1.254:4500
Jul 24 16:34:33 authpriv warn pluto[10802]: shutting down interface br0/br0 192.168.1.254:500
Jul 24 16:34:33 authpriv warn pluto[10802]: shutting down interface pppoa0/pppoa0 (My WAN IP):4500
Jul 24 16:34:33 authpriv warn pluto[10802]: shutting down interface pppoa0/pppoa0 (My WAN IP):500
Jul 24 16:34:33 authpriv warn pluto[10808]: pluto_crypto_helper: helper (0) is normal exiting
Jul 24 16:34:35 daemon err ipsec_setup: ...Openswan IPsec stopped
Jul 24 16:34:36 daemon err ipsec_setup: Starting Openswan IPsec U2.6.38/K2.6.30...
Jul 24 16:34:37 daemon err ipsec_setup: Using NETKEY(XFRM) stack
Jul 24 16:34:38 authpriv err ipsec__plutorun: Starting Pluto subsystem...
Jul 24 16:34:38 user warn syslog: adjusting ipsec.d to /var/ipsec.d
Jul 24 16:34:38 authpriv warn pluto[11727]: WARNING: 1DES is enabled
Jul 24 16:34:38 authpriv warn pluto[11727]: LEAK_DETECTIVE support [disabled]
Jul 24 16:34:38 authpriv warn pluto[11727]: OCF support for IKE [disabled]
Jul 24 16:34:38 authpriv warn pluto[11727]: NSS support [disabled]
Jul 24 16:34:38 authpriv warn pluto[11727]: HAVE_STATSD notification support not compiled in
Jul 24 16:34:38 authpriv warn pluto[11727]: Setting NAT-Traversal port-4500 floating to off
Jul 24 16:34:38 authpriv warn pluto[11727]: port floating activation criteria nat_t=0/port_float=1
Jul 24 16:34:38 authpriv warn pluto[11727]: NAT-Traversal support [disabled]
Jul 24 16:34:38 authpriv warn pluto[11727]: using /dev/urandom as source of random entropy
Jul 24 16:34:39 daemon err ipsec__plutorun: adjusting ipsec.d to /var/ipsec.d
Jul 24 16:34:39 authpriv warn pluto[11727]: starting up 1 cryptographic helpers
Jul 24 16:34:39 authpriv warn pluto[11732]: using /dev/urandom as source of random entropy
Jul 24 16:34:39 authpriv warn pluto[11727]: started helper pid=11732 (fd:6)
Jul 24 16:34:39 daemon err ipsec_setup: ...Openswan IPsec started
Jul 24 16:34:41 authpriv warn pluto[11727]: Could not change to directory '/var/ipsec.d/cacerts': No such file or directory
Jul 24 16:34:41 authpriv warn pluto[11727]: Could not change to directory '/var/ipsec.d/aacerts': No such file or directory
Jul 24 16:34:41 authpriv warn pluto[11727]: Could not change to directory '/var/ipsec.d/ocspcerts': No such file or directory
Jul 24 16:34:41 authpriv warn pluto[11727]: Could not change to directory '/var/ipsec.d/crls': 2 No such file or directory
Jul 24 16:34:41 authpriv warn pluto[11727]: added connection description "tony"
Jul 24 16:34:41 daemon err ipsec__plutorun: 002 added connection description "tony"
Jul 24 16:34:41 authpriv warn pluto[11727]: listening for IKE messages
Jul 24 16:34:41 authpriv warn pluto[11727]: adding interface pppoa0/pppoa0 (My WAN IP):500
Jul 24 16:34:41 authpriv warn pluto[11727]: adding interface br0/br0 192.168.1.254:500
Jul 24 16:34:41 authpriv warn pluto[11727]: adding interface lo/lo 127.0.0.1:500
Jul 24 16:34:41 authpriv warn pluto[11727]: adding interface lo/lo ::1:500
Jul 24 16:34:41 authpriv warn pluto[11727]: loading secrets from "/var/ipsec.secrets"
Jul 24 16:34:42 authpriv warn pluto[11727]: "tony": deleting connection
Jul 24 16:34:42 authpriv warn pluto[11727]: added connection description "tony"
Jul 24 16:34:42 authpriv warn pluto[11727]: "tony" #1: initiating Main Mode
In the log of my 7800dx there are the following entries- can anyone point out where I've gone wrong please, I'm using 2.32d firmware?
Jul 24 16:34:12 authpriv warn pluto[9677]: "tony": deleting connection
Jul 24 16:34:12 authpriv warn pluto[9677]: "tony" #1: deleting state (STATE_MAIN_I1)
Jul 24 16:34:13 daemon err ipsec_setup: Stopping Openswan IPsec...
Jul 24 16:34:13 authpriv warn pluto[9677]: shutting down
Jul 24 16:34:13 authpriv warn pluto[9677]: forgetting secrets
Jul 24 16:34:13 authpriv warn pluto[9677]: shutting down interface lo/lo ::1:500
Jul 24 16:34:13 authpriv warn pluto[9677]: shutting down interface lo/lo 127.0.0.1:4500
Jul 24 16:34:13 authpriv warn pluto[9677]: shutting down interface lo/lo 127.0.0.1:500
Jul 24 16:34:13 authpriv warn pluto[9677]: shutting down interface br0/br0 192.168.1.254:4500
Jul 24 16:34:13 authpriv warn pluto[9677]: shutting down interface br0/br0 192.168.1.254:500
Jul 24 16:34:13 authpriv warn pluto[9677]: shutting down interface pppoa0/pppoa0 (My Wan IP):4500
Jul 24 16:34:13 authpriv warn pluto[9677]: shutting down interface pppoa0/pppoa0 (My Wan IP):500
Jul 24 16:34:13 authpriv warn pluto[9683]: pluto_crypto_helper: helper (0) is normal exiting
Jul 24 16:34:14 daemon err ipsec_setup: ...Openswan IPsec stopped
Jul 24 16:34:15 daemon err ipsec_setup: Starting Openswan IPsec U2.6.38/K2.6.30...
Jul 24 16:34:16 daemon err ipsec_setup: Using NETKEY(XFRM) stack
Jul 24 16:34:17 authpriv err ipsec__plutorun: Starting Pluto subsystem...
Jul 24 16:34:17 user warn syslog: adjusting ipsec.d to /var/ipsec.d
Jul 24 16:34:17 authpriv warn pluto[10802]: WARNING: 1DES is enabled
Jul 24 16:34:17 authpriv warn pluto[10802]: LEAK_DETECTIVE support [disabled]
Jul 24 16:34:17 authpriv warn pluto[10802]: OCF support for IKE [disabled]
Jul 24 16:34:17 authpriv warn pluto[10802]: NSS support [disabled]
Jul 24 16:34:17 authpriv warn pluto[10802]: HAVE_STATSD notification support not compiled in
Jul 24 16:34:18 authpriv warn pluto[10802]: Setting NAT-Traversal port-4500 floating to on
Jul 24 16:34:18 authpriv warn pluto[10802]: port floating activation criteria nat_t=1/port_float=1
Jul 24 16:34:18 authpriv warn pluto[10802]: NAT-Traversal support [enabled]
Jul 24 16:34:18 authpriv warn pluto[10802]: using /dev/urandom as source of random entropy
Jul 24 16:34:18 daemon err ipsec__plutorun: adjusting ipsec.d to /var/ipsec.d
Jul 24 16:34:18 authpriv warn pluto[10802]: starting up 1 cryptographic helpers
Jul 24 16:34:18 authpriv warn pluto[10802]: started helper pid=10808 (fd:6)
Jul 24 16:34:18 authpriv warn pluto[10808]: using /dev/urandom as source of random entropy
Jul 24 16:34:18 daemon err ipsec_setup: ...Openswan IPsec started
Jul 24 16:34:20 authpriv warn pluto[10802]: Could not change to directory '/var/ipsec.d/cacerts': No such file or directory
Jul 24 16:34:20 authpriv warn pluto[10802]: Could not change to directory '/var/ipsec.d/aacerts': No such file or directory
Jul 24 16:34:20 authpriv warn pluto[10802]: Could not change to directory '/var/ipsec.d/ocspcerts': No such file or directory
Jul 24 16:34:20 authpriv warn pluto[10802]: Could not change to directory '/var/ipsec.d/crls': 2 No such file or directory
Jul 24 16:34:20 authpriv warn pluto[10802]: added connection description "tony"
Jul 24 16:34:20 daemon err ipsec__plutorun: 002 added connection description "tony"
Jul 24 16:34:20 authpriv warn pluto[10802]: listening for IKE messages
Jul 24 16:34:20 authpriv warn pluto[10802]: adding interface pppoa0/pppoa0 (My Wan IP):500
Jul 24 16:34:20 authpriv warn pluto[10802]: adding interface pppoa0/pppoa0 (my Wan IP):4500
Jul 24 16:34:20 authpriv warn pluto[10802]: adding interface br0/br0 192.168.1.254:500
Jul 24 16:34:20 authpriv warn pluto[10802]: adding interface br0/br0 192.168.1.254:4500
Jul 24 16:34:20 authpriv warn pluto[10802]: adding interface lo/lo 127.0.0.1:500
Jul 24 16:34:20 authpriv warn pluto[10802]: adding interface lo/lo 127.0.0.1:4500
Jul 24 16:34:20 authpriv warn pluto[10802]: adding interface lo/lo ::1:500
Jul 24 16:34:20 authpriv warn pluto[10802]: loading secrets from "/var/ipsec.secrets"
Jul 24 16:34:22 authpriv warn pluto[10802]: "tony": deleting connection
Jul 24 16:34:22 authpriv warn pluto[10802]: added connection description "tony"
Jul 24 16:34:22 authpriv warn pluto[10802]: "tony" #1: initiating Main Mode
Jul 24 16:34:32 authpriv warn pluto[10802]: "tony": deleting connection
Jul 24 16:34:32 authpriv warn pluto[10802]: "tony" #1: deleting state (STATE_MAIN_I1)
Jul 24 16:34:33 daemon err ipsec_setup: Stopping Openswan IPsec...
Jul 24 16:34:33 authpriv warn pluto[10802]: shutting down
Jul 24 16:34:33 authpriv warn pluto[10802]: forgetting secrets
Jul 24 16:34:33 authpriv warn pluto[10802]: shutting down interface lo/lo ::1:500
Jul 24 16:34:33 authpriv warn pluto[10802]: shutting down interface lo/lo 127.0.0.1:4500
Jul 24 16:34:33 authpriv warn pluto[10802]: shutting down interface lo/lo 127.0.0.1:500
Jul 24 16:34:33 authpriv warn pluto[10802]: shutting down interface br0/br0 192.168.1.254:4500
Jul 24 16:34:33 authpriv warn pluto[10802]: shutting down interface br0/br0 192.168.1.254:500
Jul 24 16:34:33 authpriv warn pluto[10802]: shutting down interface pppoa0/pppoa0 (My WAN IP):4500
Jul 24 16:34:33 authpriv warn pluto[10802]: shutting down interface pppoa0/pppoa0 (My WAN IP):500
Jul 24 16:34:33 authpriv warn pluto[10808]: pluto_crypto_helper: helper (0) is normal exiting
Jul 24 16:34:35 daemon err ipsec_setup: ...Openswan IPsec stopped
Jul 24 16:34:36 daemon err ipsec_setup: Starting Openswan IPsec U2.6.38/K2.6.30...
Jul 24 16:34:37 daemon err ipsec_setup: Using NETKEY(XFRM) stack
Jul 24 16:34:38 authpriv err ipsec__plutorun: Starting Pluto subsystem...
Jul 24 16:34:38 user warn syslog: adjusting ipsec.d to /var/ipsec.d
Jul 24 16:34:38 authpriv warn pluto[11727]: WARNING: 1DES is enabled
Jul 24 16:34:38 authpriv warn pluto[11727]: LEAK_DETECTIVE support [disabled]
Jul 24 16:34:38 authpriv warn pluto[11727]: OCF support for IKE [disabled]
Jul 24 16:34:38 authpriv warn pluto[11727]: NSS support [disabled]
Jul 24 16:34:38 authpriv warn pluto[11727]: HAVE_STATSD notification support not compiled in
Jul 24 16:34:38 authpriv warn pluto[11727]: Setting NAT-Traversal port-4500 floating to off
Jul 24 16:34:38 authpriv warn pluto[11727]: port floating activation criteria nat_t=0/port_float=1
Jul 24 16:34:38 authpriv warn pluto[11727]: NAT-Traversal support [disabled]
Jul 24 16:34:38 authpriv warn pluto[11727]: using /dev/urandom as source of random entropy
Jul 24 16:34:39 daemon err ipsec__plutorun: adjusting ipsec.d to /var/ipsec.d
Jul 24 16:34:39 authpriv warn pluto[11727]: starting up 1 cryptographic helpers
Jul 24 16:34:39 authpriv warn pluto[11732]: using /dev/urandom as source of random entropy
Jul 24 16:34:39 authpriv warn pluto[11727]: started helper pid=11732 (fd:6)
Jul 24 16:34:39 daemon err ipsec_setup: ...Openswan IPsec started
Jul 24 16:34:41 authpriv warn pluto[11727]: Could not change to directory '/var/ipsec.d/cacerts': No such file or directory
Jul 24 16:34:41 authpriv warn pluto[11727]: Could not change to directory '/var/ipsec.d/aacerts': No such file or directory
Jul 24 16:34:41 authpriv warn pluto[11727]: Could not change to directory '/var/ipsec.d/ocspcerts': No such file or directory
Jul 24 16:34:41 authpriv warn pluto[11727]: Could not change to directory '/var/ipsec.d/crls': 2 No such file or directory
Jul 24 16:34:41 authpriv warn pluto[11727]: added connection description "tony"
Jul 24 16:34:41 daemon err ipsec__plutorun: 002 added connection description "tony"
Jul 24 16:34:41 authpriv warn pluto[11727]: listening for IKE messages
Jul 24 16:34:41 authpriv warn pluto[11727]: adding interface pppoa0/pppoa0 (My WAN IP):500
Jul 24 16:34:41 authpriv warn pluto[11727]: adding interface br0/br0 192.168.1.254:500
Jul 24 16:34:41 authpriv warn pluto[11727]: adding interface lo/lo 127.0.0.1:500
Jul 24 16:34:41 authpriv warn pluto[11727]: adding interface lo/lo ::1:500
Jul 24 16:34:41 authpriv warn pluto[11727]: loading secrets from "/var/ipsec.secrets"
Jul 24 16:34:42 authpriv warn pluto[11727]: "tony": deleting connection
Jul 24 16:34:42 authpriv warn pluto[11727]: added connection description "tony"
Jul 24 16:34:42 authpriv warn pluto[11727]: "tony" #1: initiating Main Mode