<?xml version="1.0" encoding="koi8-r"?>
<rss version="0.91">
<channel>
    <title>OpenForum RSS: Easy VPN Site-to-Site</title>
    <link>https://opennet.ru/openforum/vsluhforumID6/20090.html</link>
    <description>замучался уже с site-to-site VPN (коннекты с PC VPN Client проходят отлично). А циски между собой не цепляются. Вернее цепляются очень иногда - что и как я не смог отловить. Судя по мануалу - там настраивать-то нечего. Но что-то не растет кокос третий день. Помогите, а ? )&lt;br&gt;&lt;br&gt;Easy VPN Server (лишнее убрал):&lt;br&gt;&lt;br&gt;&lt;br&gt;!&lt;br&gt;hostname VPN_server&lt;br&gt;!&lt;br&gt;!&lt;br&gt;aaa new-model&lt;br&gt;!&lt;br&gt;!&lt;br&gt;aaa authentication login userauth local&lt;br&gt;aaa authorization network vpnclient local&lt;br&gt;!&lt;br&gt;username cisco password 0 cisco123&lt;br&gt;!&lt;br&gt;!&lt;br&gt;!&lt;br&gt;!&lt;br&gt;crypto isakmp policy 3&lt;br&gt; encr 3des&lt;br&gt; hash md5&lt;br&gt; authentication pre-share&lt;br&gt; group 2&lt;br&gt;crypto isakmp key cisco123 address 192.168.50.200 no-xauth&lt;br&gt;!&lt;br&gt;crypto isakmp client configuration group vpnclient&lt;br&gt; key cisco123&lt;br&gt; dns 10.10.10.10&lt;br&gt; wins 10.10.10.20&lt;br&gt; domain test.com&lt;br&gt; pool remote_user&lt;br&gt;!&lt;br&gt;!&lt;br&gt;crypto ipsec transform-set myset esp-3des esp-md5-hmac&lt;br&gt;!&lt;br&gt;crypto dynamic-map dynmap 1&lt;br&gt; set transform-set myset&lt;br&gt; reverse-route&lt;br&gt;!&lt;br&gt;!&lt;br&gt;crypto map dynmap client authentication list userauth&lt;br&gt;crypto map dynmap isakmp authorization </description>

<item>
    <title>Easy VPN Site-to-Site (mansell)</title>
    <link>https://opennet.ru/openforum/vsluhforumID6/20090.html#4</link>
    <pubDate>Tue, 24 Nov 2009 07:00:37 GMT</pubDate>
    <description>&amp;gt;&#091;оверквотинг удален&#093;&lt;br&gt;&amp;gt; mode network-plus &lt;br&gt;&amp;gt; username XXXX password XXXX &lt;br&gt;&amp;gt; xauth userid mode local &lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt;interface FastEthernet4 &lt;br&gt;&amp;gt; crypto ipsec client ezvpn XXXX &lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt;interface Vlan1 &lt;br&gt;&amp;gt;  crypto ipsec client ezvpn XXXX inside &lt;br&gt;&lt;br&gt;спасибо ))) завелось ))) &lt;br&gt;&lt;br&gt;после удаления crypto isakmp key cisco123 address 192.168.50.200 no-xauth&lt;br&gt;&lt;br&gt;</description>
</item>

<item>
    <title>Easy VPN Site-to-Site (mansell)</title>
    <link>https://opennet.ru/openforum/vsluhforumID6/20090.html#3</link>
    <pubDate>Tue, 24 Nov 2009 05:52:04 GMT</pubDate>
    <description>VPN_server#&lt;br&gt;*Nov 24 05:40:52.619: ISAKMP:(0:0:N/A:0):Authentication method offered does not match policy!&lt;br&gt;*Nov 24 05:40:52.619: ISAKMP:(0:0:N/A:0):atts are not acceptable. Next payload is 3&lt;br&gt;*Nov 24 05:40:52.619: ISAKMP:(0:0:N/A:0):Checking ISAKMP transform 20 against priority 65535 policy&lt;br&gt;*Nov 24 05:40:52.623: ISAKMP:      encryption DES-CBC&lt;br&gt;*Nov 24 05:40:52.623: ISAKMP:      hash MD5&lt;br&gt;*Nov 24 05:40:52.623: ISAKMP:      default group 2&lt;br&gt;*Nov 24 05:40:52.623: ISAKMP:      auth pre-share&lt;br&gt;*Nov 24 05:40:52.623: ISAKMP:      life type in seconds&lt;br&gt;*Nov 24 05:40:52.623: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B&lt;br&gt;*Nov 24 05:40:52.623: ISAKMP:(0:0:N/A:0):Hash algorithm offered does not match policy!&lt;br&gt;*Nov 24 05:40:52.623: ISAKMP:(0:0:N/A:0):atts are not acceptable. Next payload is 0&lt;br&gt;*Nov 24 05:40:52.623: ISAKMP:(0:0:N/A:0):no offers accepted!&lt;br&gt;*Nov 24 05:40:52.623: ISAKMP:(0:0:N/A:0): phase 1 SA policy not acceptable! (local 192.168.50.100 remote 192.168.50.200)&lt;br&gt;*Nov 24 05:40:52.623: ISAKMP (0:0)</description>
</item>

<item>
    <title>Easy VPN Site-to-Site (mansell)</title>
    <link>https://opennet.ru/openforum/vsluhforumID6/20090.html#2</link>
    <pubDate>Tue, 24 Nov 2009 05:50:58 GMT</pubDate>
    <description>команды ввел) не помогло - те же самые логи.&lt;br&gt;&lt;br&gt;VPN_client#&lt;br&gt;*Mar  5 23:28:31.767: ISAKMP:(0):purging SA., sa=829AE5C0, delme=829AE5C0&lt;br&gt;*Mar  5 23:28:48.311: ISAKMP: quick mode timer expired.&lt;br&gt;*Mar  5 23:28:48.311: ISAKMP:(0):src 192.168.50.200 dst 192.168.50.100, SA is not authenticated&lt;br&gt;*Mar  5 23:28:48.311: ISAKMP:(0):peer does not do paranoid keepalives.&lt;br&gt;&lt;br&gt;*Mar  5 23:28:48.311: ISAKMP:(0):deleting SA reason &quot;QM_TIMER expired&quot; state (I) AG_INIT_EXCH (peer 192.168.50.100)&lt;br&gt;*Mar  5 23:28:48.311: ISAKMP:(0):deleting SA reason &quot;QM_TIMER expired&quot; state (I) AG_INIT_EXCH (peer 192.168.50.100)&lt;br&gt;*Mar  5 23:28:48.311: ISAKMP: Unlocking peer struct 0x82642E50 for isadb_mark_sa_deleted(), count 0&lt;br&gt;*Mar  5 23:28:48.311: ISAKMP: Deleting peer node by peer_reap for 192.168.50.100: 82642E50&lt;br&gt;*Mar  5 23:28:48.311: ISAKMP:(0):Input = IKE_MESG_INTERNAL, IKE_PHASE1_DEL&lt;br&gt;*Mar  5 23:28:48.311: ISAKMP:(0):Old State = IKE_I_AM1  New State = IKE_DEST_SA&lt;br&gt;&lt;br&gt;*Mar  5 23:28:48.311: &#037;CRYPTO-6-EZVPN_CONNECTION_DOWN: (Client)  User=  Gr</description>
</item>

<item>
    <title>Easy VPN Site-to-Site (denp)</title>
    <link>https://opennet.ru/openforum/vsluhforumID6/20090.html#1</link>
    <pubDate>Mon, 23 Nov 2009 13:58:43 GMT</pubDate>
    <description>КЛЮЧЕВЫЕ КОМАНДЫ:&lt;br&gt;&lt;br&gt;1) на сервере:&lt;br&gt;&lt;br&gt;username XXX privilege 0 password XXXX&lt;br&gt;&lt;br&gt;crypto isakmp client configuration group XXXX&lt;br&gt; key XXXX&lt;br&gt; pool XXXX&lt;br&gt; save-password&lt;br&gt;&lt;br&gt;&lt;br&gt;2) на клиенте:&lt;br&gt;&lt;br&gt;crypto ipsec client ezvpn XXXX&lt;br&gt; connect auto&lt;br&gt; group XXXX key XXXX&lt;br&gt; mode network-plus&lt;br&gt; username XXXX password XXXX&lt;br&gt; xauth userid mode local&lt;br&gt;&lt;br&gt;&lt;br&gt;interface FastEthernet4&lt;br&gt; crypto ipsec client ezvpn XXXX&lt;br&gt;&lt;br&gt;interface Vlan1&lt;br&gt;  crypto ipsec client ezvpn XXXX inside&lt;br&gt;</description>
</item>

</channel>
</rss>
