Hallo zusammen,
ich versuche aktuell auch, 2 FritzBoxen miteinander zu verbinden. Auf der einen Seite handelt es sich um eine 7490 an einem VDSL-Anschluss von 1&1, auf der anderen Seite um eine 6360 an einem Unitymedia Anschluss. ich habe mich soweit der Konfiguration, gepostet im Start-Port bedient, an meine Umgebung angepasst. Beachtet habe ich dabei, dass die Box welche die Verbindung aufbaut, die ist, die auf der Unitymedia Seite (also mit DS-Lite) steht.
Leider wird die Verbindung aber nicht erfolgreich aufgebaut. Auf der 6360 kommen immer wieder folgende Einträge im Log:
Der Eintrag mit 0x2027 wiederholt sich hierbei am meisten. Auf der 7490 kommen diese Einträge:
Eintrag 1 und 2 wiederholen sich hier auch am ehesten.
Ich hab mal auf der 7490 in /var/tmp in die ike.log reingeschaut und da sieht es so aus:
Die 7490 hat FOS 06.24, die 6360 FOS 06.04. Bei der 7490 geht es sowohl mit der 06.24 nicht als auch mit der neusten Labor-Version, die ich davor drauf hatte. Ehrlich gesagt fehlt mir momentan die Idee, woran es liegen kann, dass die Verbindung nicht zustande kommt.
Die Konfigurationen:
FritzBox 7490
FritzBox 6360
Was läuft denn da schief?
ich versuche aktuell auch, 2 FritzBoxen miteinander zu verbinden. Auf der einen Seite handelt es sich um eine 7490 an einem VDSL-Anschluss von 1&1, auf der anderen Seite um eine 6360 an einem Unitymedia Anschluss. ich habe mich soweit der Konfiguration, gepostet im Start-Port bedient, an meine Umgebung angepasst. Beachtet habe ich dabei, dass die Box welche die Verbindung aufbaut, die ist, die auf der Unitymedia Seite (also mit DS-Lite) steht.
Leider wird die Verbindung aber nicht erfolgreich aufgebaut. Auf der 6360 kommen immer wieder folgende Einträge im Log:
Code:
03.04.15 12:30:36 VPN-Fehler: ipv4hostname, IKE-Error 0x2027
03.04.15 12:30:06 VPN-Fehler: ipv4hostname, IKE-Error 0x203d
Code:
03.04.15 12:34:08 VPN-Verbindung zu ipv6hostname wurde getrennt. Ursache: 3 IKE server
03.04.15 12:34:08 VPN-Verbindung zu ipv6hostname wurde erfolgreich hergestellt.
03.04.15 12:34:07 VPN-Fehler: ipv6hostname, IKE-Error 0x203d
Ich hab mal auf der 7490 in /var/tmp in die ike.log reingeschaut und da sieht es so aus:
Code:
2015-04-03 12:07:56 avmike:< cb_sa_create_failed(name=ipv6hostname,reason=IKE-Error 0x2027)
2015-04-03 12:07:56 avmike:mainmode ipv6hostname: del SA 15
2015-04-03 12:07:56 avmike:wolke_del_neighbour_sa_by_remote: no SAs available, set canceld = TRUE
2015-04-03 12:07:56 avmike:mainmode ipv6hostname: selected lifetime: 3600 sec(no notify)
2015-04-03 12:07:56 avmike:ipv6hostname remote peer supported XAUTH
2015-04-03 12:07:56 avmike:ipv6hostname remote peer supported DPD
2015-04-03 12:07:56 avmike:ipv6hostname remote peer supported NAT-T RFC 3947
2015-04-03 12:07:57 avmike:mainmode ipv6hostname: add SA 16
2015-04-03 12:07:57 avmike:ipv6hostname: Phase 1 ready
2015-04-03 12:07:57 avmike:ipv6hostname: current=37.201.xxx.xxx:4500 new=37.201.xxx.xxx:4500
2015-04-03 12:07:57 avmike:ipv6hostname: local is behind a nat
2015-04-03 12:07:57 avmike:ipv6hostname: remote is behind a nat
2015-04-03 12:07:57 avmike:ipv6hostname: sending initial contact message
2015-04-03 12:07:57 avmike:ipv6hostname: start waiting connections
2015-04-03 12:07:57 avmike:ipv6hostname: NO waiting connections
2015-04-03 12:07:58 avmike:ipv6hostname: Phase 2 ready
2015-04-03 12:07:58 avmike:< cb_sa_created(name=ipv6hostname,id=153,...,flags=0x00032103)
2015-04-03 12:07:58 avmike:ipv6hostname: start waiting connections
2015-04-03 12:07:58 avmike:ipv6hostname: NO waiting connections
2015-04-03 12:07:58 avmike:FreeIPsecSA: spi=91506026 protocol=3 iotype=2
2015-04-03 12:07:58 avmike:< cb_sa_deleted(name=ipv6hostname,id=153,what=2)
2015-04-03 12:07:58 avmike:FreeIPsecSA: spi=e7dd protocol=4 iotype=2
2015-04-03 12:07:58 avmike:< cb_sa_deleted(name=ipv6hostname,id=153,what=2)
2015-04-03 12:07:58 avmike:FreeIPsecSA: spi=6353350d protocol=3 iotype=1
2015-04-03 12:07:58 avmike:< cb_sa_deleted(name=ipv6hostname,id=153,what=1)
2015-04-03 12:07:58 avmike:FreeIPsecSA: spi=a5e0 protocol=4 iotype=1
2015-04-03 12:07:58 avmike:< cb_sa_deleted(name=ipv6hostname,id=153,what=1)
2015-04-03 12:07:59 avmike:ipv6hostname: Phase 2 ready
2015-04-03 12:07:59 avmike:< cb_sa_created(name=ipv6hostname,id=154,...,flags=0x00032003)
2015-04-03 12:07:59 avmike:ipv6hostname: start waiting connections
2015-04-03 12:07:59 avmike:ipv6hostname: NO waiting connections
2015-04-03 12:07:59 avmike:FreeIPsecSA: spi=3bcd7aaa protocol=3 iotype=2
2015-04-03 12:07:59 avmike:< cb_sa_deleted(name=ipv6hostname,id=154,what=2)
2015-04-03 12:07:59 avmike:FreeIPsecSA: spi=dc8d794e protocol=3 iotype=1
2015-04-03 12:07:59 avmike:FreeIPsecSA: spi=b2d0 protocol=4 iotype=1
2015-04-03 12:07:59 avmike:FreeIPsecSA: spi=de15 protocol=4 iotype=2
2015-04-03 12:07:59 avmike:< cb_sa_deleted(name=ipv6hostname,id=154,what=2)
2015-04-03 12:07:59 avmike:ipv6hostname: Phase 2 ready
2015-04-03 12:07:59 avmike:< cb_sa_created(name=ipv6hostname,id=155,...,flags=0x00032003)
2015-04-03 12:07:59 avmike:ipv6hostname: start waiting connections
2015-04-03 12:07:59 avmike:ipv6hostname: NO waiting connections
2015-04-03 12:07:59 avmike:FreeIPsecSA: spi=3f4ede92 protocol=3 iotype=2
2015-04-03 12:07:59 avmike:< cb_sa_deleted(name=ipv6hostname,id=155,what=2)
2015-04-03 12:07:59 avmike:FreeIPsecSA: spi=654 protocol=4 iotype=2
2015-04-03 12:07:59 avmike:< cb_sa_deleted(name=ipv6hostname,id=155,what=2)
2015-04-03 12:07:59 avmike:FreeIPsecSA: spi=eac03d26 protocol=3 iotype=1
2015-04-03 12:07:59 avmike:FreeIPsecSA: spi=207e protocol=4 iotype=1
2015-04-03 12:08:00 avmike:ipv6hostname: Phase 2 ready
2015-04-03 12:08:00 avmike:< cb_sa_created(name=ipv6hostname,id=156,...,flags=0x00032003)
2015-04-03 12:08:00 avmike:ipv6hostname: start waiting connections
2015-04-03 12:08:00 avmike:ipv6hostname: NO waiting connections
2015-04-03 12:08:00 avmike:FreeIPsecSA: spi=11d26bfa protocol=3 iotype=2
2015-04-03 12:08:00 avmike:< cb_sa_deleted(name=ipv6hostname,id=156,what=2)
2015-04-03 12:08:00 avmike:FreeIPsecSA: spi=5b26 protocol=4 iotype=2
2015-04-03 12:08:00 avmike:< cb_sa_deleted(name=ipv6hostname,id=156,what=2)
2015-04-03 12:08:00 avmike:FreeIPsecSA: spi=33bc6d47 protocol=3 iotype=1
2015-04-03 12:08:00 avmike:FreeIPsecSA: spi=98e7 protocol=4 iotype=1
2015-04-03 12:08:01 avmike:ipv6hostname: Phase 2 ready
2015-04-03 12:08:01 avmike:< cb_sa_created(name=ipv6hostname,id=157,...,flags=0x00032003)
2015-04-03 12:08:01 avmike:ipv6hostname: start waiting connections
2015-04-03 12:08:01 avmike:ipv6hostname: NO waiting connections
2015-04-03 12:08:01 avmike:FreeIPsecSA: spi=fd75c017 protocol=3 iotype=2
2015-04-03 12:08:01 avmike:< cb_sa_deleted(name=ipv6hostname,id=157,what=2)
2015-04-03 12:08:01 avmike:FreeIPsecSA: spi=eb03dc8 protocol=3 iotype=1
2015-04-03 12:08:01 avmike:FreeIPsecSA: spi=ddfe protocol=4 iotype=1
2015-04-03 12:08:01 avmike:FreeIPsecSA: spi=35d7 protocol=4 iotype=2
2015-04-03 12:08:01 avmike:< cb_sa_deleted(name=ipv6hostname,id=157,what=2)
2015-04-03 12:08:01 avmike:ipv6hostname: Phase 2 ready
2015-04-03 12:08:01 avmike:< cb_sa_created(name=ipv6hostname,id=158,...,flags=0x00032003)
2015-04-03 12:08:01 avmike:ipv6hostname: start waiting connections
2015-04-03 12:08:01 avmike:ipv6hostname: NO waiting connections
2015-04-03 12:08:01 avmike:FreeIPsecSA: spi=216728de protocol=3 iotype=2
2015-04-03 12:08:01 avmike:< cb_sa_deleted(name=ipv6hostname,id=158,what=2)
2015-04-03 12:08:01 avmike:FreeIPsecSA: spi=be9b9aa3 protocol=3 iotype=1
2015-04-03 12:08:01 avmike:FreeIPsecSA: spi=d1b protocol=4 iotype=1
2015-04-03 12:08:01 avmike:FreeIPsecSA: spi=cdce protocol=4 iotype=2
2015-04-03 12:08:01 avmike:< cb_sa_deleted(name=ipv6hostname,id=158,what=2)
2015-04-03 12:08:02 avmike:ipv6hostname: Phase 2 ready
2015-04-03 12:08:02 avmike:< cb_sa_created(name=ipv6hostname,id=159,...,flags=0x00032103)
2015-04-03 12:08:02 avmike:ipv6hostname: start waiting connections
2015-04-03 12:08:02 avmike:ipv6hostname: NO waiting connections
2015-04-03 12:08:02 avmike:ipv6hostname: Phase 2 ready
2015-04-03 12:08:02 avmike:< cb_sa_created(name=ipv6hostname,id=160,...,flags=0x00032003)
2015-04-03 12:08:02 avmike:ipv6hostname: start waiting connections
2015-04-03 12:08:02 avmike:ipv6hostname: NO waiting connections
2015-04-03 12:08:02 avmike:FreeIPsecSA: spi=4a5354e protocol=3 iotype=2
2015-04-03 12:08:02 avmike:< cb_sa_deleted(name=ipv6hostname,id=160,what=2)
2015-04-03 12:08:02 avmike:FreeIPsecSA: spi=485 protocol=4 iotype=2
2015-04-03 12:08:02 avmike:< cb_sa_deleted(name=ipv6hostname,id=160,what=2)
2015-04-03 12:08:02 avmike:FreeIPsecSA: spi=9e8197e8 protocol=3 iotype=1
2015-04-03 12:08:02 avmike:< cb_sa_deleted(name=ipv6hostname,id=160,what=1)
2015-04-03 12:08:02 avmike:FreeIPsecSA: spi=7d08 protocol=4 iotype=1
2015-04-03 12:08:02 avmike:< cb_sa_deleted(name=ipv6hostname,id=160,what=1)
2015-04-03 12:08:02 avmike:FreeIPsecSA: spi=da3b4739 protocol=3 iotype=2
2015-04-03 12:08:02 avmike:< cb_sa_deleted(name=ipv6hostname,id=159,what=2)
2015-04-03 12:08:03 avmike:FreeIPsecSA: spi=1d4a protocol=4 iotype=2
2015-04-03 12:08:03 avmike:< cb_sa_deleted(name=ipv6hostname,id=159,what=2)
2015-04-03 12:08:03 avmike:FreeIPsecSA: spi=616e59ac protocol=3 iotype=1
2015-04-03 12:08:03 avmike:FreeIPsecSA: spi=b77d protocol=4 iotype=1
2015-04-03 12:08:12 avmike:>>>4500 nat-t-keepalive[37.201.xxx.xxx:4500]
2015-04-03 12:08:32 avmike:< cb_sa_create_failed(name=ipv6hostname,reason=IKE-Error 0x203d)
2015-04-03 12:08:32 avmike:mainmode ipv6hostname: del SA 16
2015-04-03 12:08:32 avmike:wolke_del_neighbour_sa_by_remote: no SAs available, set canceld = TRUE
2015-04-03 12:08:32 avmike:mainmode ipv6hostname: selected lifetime: 3600 sec(no notify)
2015-04-03 12:08:32 avmike:ipv6hostname remote peer supported XAUTH
2015-04-03 12:08:32 avmike:ipv6hostname remote peer supported DPD
2015-04-03 12:08:32 avmike:ipv6hostname remote peer supported NAT-T RFC 3947
2015-04-03 12:08:33 avmike:mainmode ipv6hostname: add SA 17
2015-04-03 12:08:33 avmike:ipv6hostname: Phase 1 ready
2015-04-03 12:08:33 avmike:ipv6hostname: current=37.201.xxx.xxx:4500 new=37.201.xxx.xxx:4500
2015-04-03 12:08:33 avmike:ipv6hostname: local is behind a nat
2015-04-03 12:08:33 avmike:ipv6hostname: remote is behind a nat
2015-04-03 12:08:33 avmike:ipv6hostname: sending initial contact message
2015-04-03 12:08:33 avmike:ipv6hostname: start waiting connections
2015-04-03 12:08:33 avmike:ipv6hostname: NO waiting connections
2015-04-03 12:08:37 avmike:ipv6hostname: Phase 2 ready
2015-04-03 12:08:37 avmike:< cb_sa_created(name=ipv6hostname,id=161,...,flags=0x00032103)
2015-04-03 12:08:37 avmike:ipv6hostname: start waiting connections
2015-04-03 12:08:37 avmike:ipv6hostname: NO waiting connections
2015-04-03 12:08:37 avmike:FreeIPsecSA: spi=92ff971a protocol=3 iotype=2
2015-04-03 12:08:37 avmike:< cb_sa_deleted(name=ipv6hostname,id=161,what=2)
2015-04-03 12:08:37 avmike:FreeIPsecSA: spi=d9e3a06c protocol=3 iotype=1
2015-04-03 12:08:37 avmike:FreeIPsecSA: spi=7215 protocol=4 iotype=1
2015-04-03 12:08:37 avmike:FreeIPsecSA: spi=bc94 protocol=4 iotype=2
2015-04-03 12:08:37 avmike:< cb_sa_deleted(name=ipv6hostname,id=161,what=2)
2015-04-03 12:08:38 avmike:ipv6hostname: Phase 2 ready
2015-04-03 12:08:38 avmike:< cb_sa_created(name=ipv6hostname,id=162,...,flags=0x00032003)
2015-04-03 12:08:38 avmike:ipv6hostname: start waiting connections
2015-04-03 12:08:38 avmike:ipv6hostname: NO waiting connections
2015-04-03 12:08:38 avmike:FreeIPsecSA: spi=c4286588 protocol=3 iotype=2
2015-04-03 12:08:38 avmike:< cb_sa_deleted(name=ipv6hostname,id=162,what=2)
2015-04-03 12:08:38 avmike:FreeIPsecSA: spi=95c9 protocol=4 iotype=2
2015-04-03 12:08:38 avmike:< cb_sa_deleted(name=ipv6hostname,id=162,what=2)
2015-04-03 12:08:38 avmike:FreeIPsecSA: spi=8f091f0 protocol=3 iotype=1
2015-04-03 12:08:38 avmike:FreeIPsecSA: spi=1bd protocol=4 iotype=1
2015-04-03 12:08:38 avmike:ipv6hostname: Phase 2 ready
2015-04-03 12:08:38 avmike:< cb_sa_created(name=ipv6hostname,id=163,...,flags=0x00032003)
2015-04-03 12:08:38 avmike:ipv6hostname: start waiting connections
2015-04-03 12:08:38 avmike:ipv6hostname: NO waiting connections
2015-04-03 12:08:38 avmike:FreeIPsecSA: spi=bab43b6b protocol=3 iotype=2
2015-04-03 12:08:38 avmike:< cb_sa_deleted(name=ipv6hostname,id=163,what=2)
2015-04-03 12:08:38 avmike:FreeIPsecSA: spi=7f6 protocol=4 iotype=2
2015-04-03 12:08:38 avmike:< cb_sa_deleted(name=ipv6hostname,id=163,what=2)
2015-04-03 12:08:38 avmike:FreeIPsecSA: spi=a15edb47 protocol=3 iotype=1
2015-04-03 12:08:38 avmike:< cb_sa_deleted(name=ipv6hostname,id=163,what=1)
2015-04-03 12:08:38 avmike:FreeIPsecSA: spi=b2e3 protocol=4 iotype=1
2015-04-03 12:08:39 avmike:ipv6hostname: Phase 2 ready
2015-04-03 12:08:39 avmike:< cb_sa_created(name=ipv6hostname,id=164,...,flags=0x00032003)
2015-04-03 12:08:39 avmike:ipv6hostname: start waiting connections
2015-04-03 12:08:39 avmike:ipv6hostname: NO waiting connections
2015-04-03 12:08:39 avmike:FreeIPsecSA: spi=52d61636 protocol=3 iotype=2
2015-04-03 12:08:39 avmike:< cb_sa_deleted(name=ipv6hostname,id=164,what=2)
2015-04-03 12:08:39 avmike:FreeIPsecSA: spi=ead3806e protocol=3 iotype=1
2015-04-03 12:08:39 avmike:FreeIPsecSA: spi=e96e protocol=4 iotype=1
2015-04-03 12:08:39 avmike:FreeIPsecSA: spi=d33d protocol=4 iotype=2
2015-04-03 12:08:39 avmike:< cb_sa_deleted(name=ipv6hostname,id=164,what=2)
2015-04-03 12:08:40 avmike:ipv6hostname: Phase 2 ready
2015-04-03 12:08:40 avmike:< cb_sa_created(name=ipv6hostname,id=165,...,flags=0x00032003)
2015-04-03 12:08:40 avmike:ipv6hostname: start waiting connections
2015-04-03 12:08:40 avmike:ipv6hostname: Phase 2 starting (start waiting)
2015-04-03 12:08:40 avmike:FreeIPsecSA: spi=d077851a protocol=3 iotype=2
2015-04-03 12:08:40 avmike:< cb_sa_deleted(name=ipv6hostname,id=165,what=2)
2015-04-03 12:08:40 avmike:FreeIPsecSA: spi=c3e0 protocol=4 iotype=2
2015-04-03 12:08:40 avmike:< cb_sa_deleted(name=ipv6hostname,id=165,what=2)
2015-04-03 12:08:40 avmike:FreeIPsecSA: spi=f0928285 protocol=3 iotype=1
2015-04-03 12:08:40 avmike:FreeIPsecSA: spi=4ef1 protocol=4 iotype=1
2015-04-03 12:08:40 avmike:ipv6hostname: Phase 2 ready
2015-04-03 12:08:40 avmike:< cb_sa_created(name=ipv6hostname,id=166,...,flags=0x00032103)
2015-04-03 12:08:40 avmike:ipv6hostname: start waiting connections
2015-04-03 12:08:40 avmike:ipv6hostname: NO waiting connections
2015-04-03 12:08:40 avmike:ipv6hostname: Phase 2 ready
2015-04-03 12:08:40 avmike:< cb_sa_created(name=ipv6hostname,id=167,...,flags=0x00032003)
2015-04-03 12:08:40 avmike:ipv6hostname: start waiting connections
2015-04-03 12:08:40 avmike:ipv6hostname: NO waiting connections
2015-04-03 12:08:40 avmike:FreeIPsecSA: spi=24c103bf protocol=3 iotype=2
2015-04-03 12:08:40 avmike:< cb_sa_deleted(name=ipv6hostname,id=167,what=2)
2015-04-03 12:08:40 avmike:FreeIPsecSA: spi=702d protocol=4 iotype=2
2015-04-03 12:08:40 avmike:< cb_sa_deleted(name=ipv6hostname,id=167,what=2)
2015-04-03 12:08:40 avmike:FreeIPsecSA: spi=d29e383f protocol=3 iotype=1
2015-04-03 12:08:40 avmike:FreeIPsecSA: spi=d129 protocol=4 iotype=1
2015-04-03 12:08:41 avmike:FreeIPsecSA: spi=2285bc2d protocol=3 iotype=2
2015-04-03 12:08:41 avmike:< cb_sa_deleted(name=ipv6hostname,id=166,what=2)
2015-04-03 12:08:41 avmike:FreeIPsecSA: spi=74ef protocol=4 iotype=2
2015-04-03 12:08:41 avmike:< cb_sa_deleted(name=ipv6hostname,id=166,what=2)
2015-04-03 12:08:41 avmike:FreeIPsecSA: spi=94805a7c protocol=3 iotype=1
2015-04-03 12:08:41 avmike:FreeIPsecSA: spi=1035 protocol=4 iotype=1
2015-04-03 12:08:50 avmike:>>>4500 nat-t-keepalive[37.201.xxx.xxx:4500]
Die Konfigurationen:
FritzBox 7490
Code:
vpncfg {
connections {
enabled = yes;
conn_type = conntype_lan;
name = "ipv6hostname";
always_renew = no;
reject_not_encrypted = no;
dont_filter_netbios = yes;
localip = 0.0.0.0;
local_virtualip = 0.0.0.0;
remote_virtualip = 0.0.0.0;
localid {
fqdn = "ipv4hostname";
}
remoteid {
fqdn = "ipv6hostname";
}
mode = phase1_mode_aggressive;
phase1ss = "all/all/all";
keytype = connkeytype_pre_shared;
key = "qSQIwInN";
cert_do_server_auth = no;
use_nat_t = yes;
use_xauth = no;
use_cfgmode = no;
phase2localid {
ipnet {
ipaddr = 192.168.100.0;
mask = 255.255.255.0;
}
}
phase2remoteid {
ipnet {
ipaddr = 192.168.101.0;
mask = 255.255.255.0;
}
}
phase2ss = "esp-all-all/ah-none/comp-all/pfs";
accesslist = "permit ip any 192.168.101.0 255.255.255.0";
}
ike_forward_rules = "udp 0.0.0.0:500 0.0.0.0:500",
"udp 0.0.0.0:4500 0.0.0.0:4500";
}
Code:
vpncfg {
connections {
enabled = yes;
conn_type = conntype_lan;
name = "ipv4hostname";
always_renew = yes;
reject_not_encrypted = no;
dont_filter_netbios = yes;
localip = 0.0.0.0;
local_virtualip = 0.0.0.0;
remoteip = 0.0.0.0;
remote_virtualip = 0.0.0.0;
remotehostname = "ipv4hostname";
keepalive_ip = 192.168.100.254;
localid {
fqdn = "ipv6hostname";
}
remoteid {
fqdn = "ipv4hostname";
}
mode = phase1_mode_aggressive;
phase1ss = "all/all/all";
keytype = connkeytype_pre_shared;
key = "qSQIwInN";
cert_do_server_auth = no;
use_nat_t = yes;
use_xauth = no;
use_cfgmode = no;
phase2localid {
ipnet {
ipaddr = 192.168.101.0;
mask = 255.255.255.0;
}
}
phase2remoteid {
ipnet {
ipaddr = 192.168.100.0;
mask = 255.255.255.0;
}
}
phase2ss = "esp-all-all/ah-none/comp-all/pfs";
accesslist = "permit ip any 192.168.100.0 255.255.255.0";
}
ike_forward_rules = "udp 0.0.0.0:500 0.0.0.0:500",
"udp 0.0.0.0:4500 0.0.0.0:4500";
}