========================================================================================================================
FB7490FA164-beIPFe4-Imp1.cfg
========================================================================================================================
/* manually created 2018-09-21 hg */
vpncfg {
connections {
enabled = yes;
editable = yes;
conn_type = conntype_lan;
name = "FB7490FA164-beIPFe4-Imp1";
always_renew = no;
reject_not_encrypted = no;
dont_filter_netbios = yes;
localip = 0.0.0.0;
local_virtualip = 0.0.0.0;
remoteip = 0.0.0.0;
remote_virtualip = 0.0.0.0;
remotehostname = "xxxxxxxxxxxxxx.ddnss.de";
localid {
user_fqdn = "[email protected]";
}
remoteid {
user_fqdn = "[email protected]";
}
mode = phase1_mode_aggressive;
phase1ss = "all/all/all";
keytype = connkeytype_pre_shared;
key = "xxxxxxxxxxxxxxxxxxxx";
cert_do_server_auth = no;
use_nat_t = yes;
use_xauth = no;
use_cfgmode = no;
phase2localid {
ipnet {
ipaddr = 192.168.164.0;
mask = 255.255.255.0;
}
}
phase2remoteid {
ipnet {
ipaddr = 172.16.1.0;
mask = 255.255.255.0;
}
}
phase2ss = "esp-all-all/ah-none/comp-all/pfs";
accesslist = "permit ip any 172.16.1.0 255.255.255.0";
}
}
========================================================================================================================
FB7490FA164-beIPFe4-Imp1i_ReadBack.cfg
========================================================================================================================
vpncfg {
connections {
enabled = yes;
editable = yes;
conn_type = conntype_lan;
name = "FB7490FA164-beIPFe4-Imp1";
boxuser_id = 0;
always_renew = no;
reject_not_encrypted = no;
dont_filter_netbios = yes;
localip = 0.0.0.0;
local_virtualip = 0.0.0.0;
remoteip = 0.0.0.0;
remote_virtualip = 0.0.0.0;
remotehostname = "xxxxxxxxxxxxxx.ddnss.de";
keepalive_ip = 0.0.0.0;
localid {
user_fqdn = "$$$$4T1X56IIM2IN6EB4B3ENJHQHB1BIZ2JNSFKXHQPGHRIJZJCTQDZR63BVR416AQUMSK4F2JAEWCMFS4ZG";
}
remoteid {
user_fqdn = "$$$$JN5VT4UAIQUTPP6Z3QJ1EFGYH3TVZW1TWDRAJ4WZ34FTZOYOHEN3EGTKS1MNL6F413EWE6OEH3IZG4ZG";
}
mode = phase1_mode_aggressive;
phase1ss = "all/all/all";
keytype = connkeytype_pre_shared;
key = "$$$$EJMW352KGKC1I4KZFPOXJNNTGBDH6CFMY1J5FYNPDQFHO3VVPGOQBWL6Y4PIYENFYGOFAFDPKRD6SAAA";
cert_do_server_auth = no;
use_nat_t = yes;
use_xauth = no;
use_cfgmode = no;
phase2localid {
ipnet {
ipaddr = 192.168.164.0;
mask = 255.255.255.0;
}
}
phase2remoteid {
ipnet {
ipaddr = 172.16.1.0;
mask = 255.255.255.0;
}
}
phase2ss = "esp-all-all/ah-none/comp-all/pfs";
accesslist = "permit ip any 172.16.1.0 255.255.255.0";
app_id = 0;
}
ike_forward_rules = "udp 0.0.0.0:500 0.0.0.0:500",
"udp 0.0.0.0:4500 0.0.0.0:4500";
}
========================================================================================================================
Support_Data
========================================================================================================================
##### TITLE Version 113.06.93
##### TITLE SubVersion
##### TITLE Produkt Fritz_Box_HW185
##### TITLE Datum Sun Sep 23 10:44:44 CEST 2018
##### BEGIN SECTION Support_Data Supportdata Linux fritz.box 3.10.73 #1 SMP Mon Nov 27 18:31:19 CET 2017 mips GNU/Linux Version 113.06.93
Support Data
------------
Sun Sep 23 10:44:45 CEST 2018
3.10.73
HWRevision 185
HWSubRevision 6
ProductID Fritz_Box_HW185
SerialNumber 0000000000000000
<snip>
##### BEGIN SECTION vpn VPN
VPN avmike
-------
-rw-r--r-- 1 root root 10766 Sep 23 03:30 /var/tmp/ike.log
-rw-r--r-- 1 root root 20526 Sep 22 16:36 /var/tmp/ike.old
<snip>
<import FB7490FA164-beIPFe4-Imp1.cfg>
2018-09-21 17:31:44 avmike:< add(appl=dsld,cname=xxxxxxxxxxxxxxxx.myfritz.net,localip=xx.xx.xxx.xxx, remoteip=255.255.255.255, p1ss=all/all/all, p2ss=esp-all-all/ah-none/comp-all/pfs p1mode=4 keepalive_ip=0.0.0.0 flags=0x8001 tunnel no_xauth no_cfgmode nat_t no_certsrv_server_auth)
2018-09-21 17:31:44 avmike:new neighbour xxxxxxxxxxxxxxxx.myfritz.net: nat_t
2018-09-21 17:31:44 avmike:< add(appl=dsld,cname=xxxxxxxxxxxxxxxx.myfritz.net,localip=xx.xx.xxx.xxx, remoteip=255.255.255.255, p1ss=all/all/all, p2ss=esp-all-all/ah-none/comp-all/pfs p1mode=4 keepalive_ip=0.0.0.0 flags=0x8001 tunnel no_xauth no_cfgmode nat_t no_certsrv_server_auth)
2018-09-21 17:31:44 avmike:new neighbour xxxxxxxxxxxxxxxx.myfritz.net: nat_t
2018-09-21 17:32:06 avmike:< add(appl=dsld,cname=xxxxxxxxxxxxxxxx.myfritz.net,localip=xx.xx.xxx.xxx, remoteip=255.255.255.255, p1ss=all/all/all, p2ss=esp-all-all/ah-none/comp-all/pfs p1mode=4 keepalive_ip=0.0.0.0 flags=0x8001 tunnel no_xauth no_cfgmode nat_t no_certsrv_server_auth)
2018-09-21 17:32:06 avmike:new neighbour xxxxxxxxxxxxxxxx.myfritz.net: nat_t
2018-09-21 17:32:06 avmike:< add(appl=dsld,cname=xxxxxxxxxxxxxxxx.myfritz.net,localip=xx.xx.xxx.xxx, remoteip=255.255.255.255, p1ss=all/all/all, p2ss=esp-all-all/ah-none/comp-all/pfs p1mode=4 keepalive_ip=0.0.0.0 flags=0x8001 tunnel no_xauth no_cfgmode nat_t no_certsrv_server_auth)
2018-09-21 17:32:06 avmike:new neighbour xxxxxxxxxxxxxxxx.myfritz.net: nat_t
2018-09-21 17:32:48 avmike:< add(appl=dsld,cname=xxxxxxxxxxxxxxxx.myfritz.net,localip=xx.xx.xxx.xxx, remoteip=255.255.255.255, p1ss=all/all/all, p2ss=esp-all-all/ah-none/comp-all/pfs p1mode=4 keepalive_ip=0.0.0.0 flags=0x8001 tunnel no_xauth no_cfgmode nat_t no_certsrv_server_auth)
2018-09-21 17:32:48 avmike:new neighbour xxxxxxxxxxxxxxxx.myfritz.net: nat_t
2018-09-21 17:32:48 avmike:< add(appl=dsld,cname=xxxxxxxxxxxxxxxx.myfritz.net,localip=xx.xx.xxx.xxx, remoteip=255.255.255.255, p1ss=all/all/all, p2ss=esp-all-all/ah-none/comp-all/pfs p1mode=4 keepalive_ip=0.0.0.0 flags=0x8001 tunnel no_xauth no_cfgmode nat_t no_certsrv_server_auth)
2018-09-21 17:32:48 avmike:new neighbour xxxxxxxxxxxxxxxx.myfritz.net: nat_t
2018-09-21 17:32:48 avmike:< add(appl=dsld,cname=FB7490FA164-beIPFe4-Imp1,localip=xx.xx.xxx.xxx, remoteip=255.255.255.255, p1ss=all/all/all, p2ss=esp-all-all/ah-none/comp-all/pfs p1mode=4 keepalive_ip=0.0.0.0 flags=0x8001 tunnel no_xauth no_cfgmode nat_t no_certsrv_server_auth)
2018-09-21 17:32:48 avmike:new neighbour FB7490FA164-beIPFe4-Imp1: nat_t
<snip>
<data transfer starts>
2018-09-22 15:38:51 avmike:mainmode FB7490FA164-beIPFe4-Imp1: selected lifetime: 3600 sec(no notify)
2018-09-22 15:38:51 avmike:FB7490FA164-beIPFe4-Imp1 remote peer supported XAUTH
2018-09-22 15:38:51 avmike:FB7490FA164-beIPFe4-Imp1 remote peer supported DPD
2018-09-22 15:38:52 avmike:mainmode FB7490FA164-beIPFe4-Imp1: add SA 1
2018-09-22 15:38:52 avmike:FB7490FA164-beIPFe4-Imp1: Warning: source changed from 0.0.0.0:500 to xx.xx.xxx.xx:50104
2018-09-22 15:38:52 avmike:FB7490FA164-beIPFe4-Imp1: switching to NAT-T (Responder)
2018-09-22 15:38:52 avmike:FB7490FA164-beIPFe4-Imp1: embedded inital contact message received
2018-09-22 15:38:52 avmike:FB7490FA164-beIPFe4-Imp1: Phase 1 ready
2018-09-22 15:38:52 avmike:FB7490FA164-beIPFe4-Imp1: current=0.0.0.0 new=xx.xx.xxx.xx:50104
2018-09-22 15:38:52 avmike:FB7490FA164-beIPFe4-Imp1: no valid sa, reseting initialcontactdone flag
2018-09-22 15:38:52 avmike:FB7490FA164-beIPFe4-Imp1: local is behind a nat
2018-09-22 15:38:52 avmike:FB7490FA164-beIPFe4-Imp1: remote is behind a nat
2018-09-22 15:38:52 avmike:FB7490FA164-beIPFe4-Imp1: start waiting connections
2018-09-22 15:38:52 avmike:FB7490FA164-beIPFe4-Imp1: NO waiting connections
2018-09-22 15:38:52 avmike:FB7490FA164-beIPFe4-Imp1: Phase 2 ready
2018-09-22 15:38:52 avmike:< cb_sa_created(name=FB7490FA164-beIPFe4-Imp1,id=1,...,flags=0x00032001)
2018-09-22 15:38:52 avmike:FB7490FA164-beIPFe4-Imp1: start waiting connections
2018-09-22 15:38:52 avmike:FB7490FA164-beIPFe4-Imp1: NO waiting connections
2018-09-22 15:39:02 avmike:>>>4500 nat-t-keepalive[xx.xx.xxx.xx:50104]
2018-09-22 16:26:53 avmike:FB7490FA164-beIPFe4-Imp1: Phase 2 ready
2018-09-22 16:26:53 avmike:< cb_sa_created(name=FB7490FA164-beIPFe4-Imp1,id=2,...,flags=0x00032001)
2018-09-22 16:26:53 avmike:FB7490FA164-beIPFe4-Imp1: start waiting connections
2018-09-22 16:26:53 avmike:FB7490FA164-beIPFe4-Imp1: NO waiting connections
2018-09-22 16:27:03 avmike:>>>4500 nat-t-keepalive[xx.xx.xxx.xx:50104]
<snip>
VPN assocs
----------
/proc/kdsld/dsliface/internet/ipsec/assocs:
xxxxxxxxxxxxxxxx.myfritz.net: xx.xx.xxx.xxx:0.0.0.0 xx.xxx.xxx.xx:0.0.0.0 0 SAs valid enabled dynlocalip
permit ip any 172.16.0.0 255.255.255.0
Forbidden Clients: 192.168.179.0/24
xxxxxxxxxxxxxxxx.myfritz.net: xx.xx.xxx.xxx:0.0.0.0 xx.xxx.xxx.xxx:0.0.0.0 0 SAs valid enabled dynlocalip
permit ip any 192.168.178.0 255.255.255.0
Forbidden Clients: 192.168.179.0/24
FB7490FA164-beIPFe4-Imp1: xx.xx.xxx.xxx:0.0.0.0 xx.xx.xxx.xx:0.0.0.0 0 SAs valid enabled dynlocalip
permit ip any 172.16.1.0 255.255.255.0
Forbidden Clients: 192.168.179.0/24
VPN connections
----------
/proc/kdsld/dsliface/internet/ipsec/connections:
xxxxxxxxxxxxxxxx.myfritz.net: pmtu 0 mtu 1492 dpd_supported dont_filter_netbios
xxxxxxxxxxxxxxxx.myfritz.net: pmtu 0 mtu 1492 dpd_supported dont_filter_netbios
FB7490FA164-beIPFe4-Imp1: pmtu 0 mtu 1492 dpd_supported dont_filter_netbios local_nat remote_nat
##### END SECTION vpn
========================================================================================================================