Помогите, пожалуйста. вот конфиг racoon:
#file with key
path pre_shared_key "/usr/local/etc/racoon/psk.txt";#incoming connector
listen
{
isakmp 11.11.11.11; для другого пк 22.22.22.22
}
#any host is anonymous. will insert ip remote server
remote anonymous
{
exchange_mode aggressive;
my_identifier address;
lifetime time 24 hour;
proposal {
encryption_algorithm 3des;
hash_algorithm sha1;
authentication_method pre_shared_key;
dh_group 2;
}
}
sainfo anonymous
{
pfs_group 2;
lifetime time 12 hour;
encryption_algorithm 3des, blowfish, des, rijndael;
authentication_algorithm hmac_sha1, hmac_md5;
compression_algorithm deflate;
}
есть лог с другого сервера:
2009-05-20 11:07:17: INFO: @(#)ipsec-tools 0.7.1 (http://ipsec-tools.sourceforge.net)
2009-05-20 11:07:17: INFO: @(#)This product linked OpenSSL 0.9.8e 23 Feb 2007 (http://www.openssl.org/)
2009-05-20 11:07:17: INFO: Reading configuration from "/usr/local/etc/racoon/racoon.conf"
2009-05-20 11:07:17: INFO: Resize address pool from 0 to 255
2009-05-20 11:07:17: INFO: 22.22.22.22[500] used as isakmp port (fd=5)
2009-05-20 11:08:09: INFO: IPsec-SA request for 11.11.11.11 queued due to no phase1 found.
2009-05-20 11:08:09: ERROR: unknown AF: 0
2009-05-20 11:08:09: INFO: initiate new phase 1 negotiation: 22.22.22.22[500]<=>11.11.11.11[500]
2009-05-20 11:08:09: INFO: begin Aggressive mode.
2009-05-20 11:08:40: ERROR: phase2 negotiation failed due to time up waiting for phase1. ESP 11.11.11.11[0]->22.22.22.22[0]
2009-05-20 11:08:40: INFO: delete phase 2 handler.
2009-05-20 11:08:59: ERROR: phase1 negotiation failed due to time up. 1cc0d92b1d1d23a5:0000000000000000
2009-05-20 11:09:04: INFO: respond new phase 1 negotiation: 22.22.22.22[500]<=>11.11.11.11[500]
2009-05-20 11:09:04: INFO: begin Aggressive mode.
2009-05-20 11:09:04: INFO: received Vendor ID: DPD
2009-05-20 11:09:04: ERROR: failed to open pre_share_key file psk.txt
2009-05-20 11:09:04: NOTIFY: couldn't find the proper pskey, try to get one by the peer's address.
2009-05-20 11:09:04: ERROR: failed to open pre_share_key file psk.txt
2009-05-20 11:09:04: ERROR: couldn't find the pskey for 11.11.11.11.
2009-05-20 11:09:04: ERROR: failed to process packet.
2009-05-20 11:09:04: ERROR: phase1 negotiation failed.
2009-05-20 11:09:14: INFO: respond new phase 1 negotiation: 22.22.22.22[500]<=>11.11.11.11[500]
2009-05-20 11:09:14: INFO: begin Aggressive mode.
2009-05-20 11:09:14: INFO: received Vendor ID: DPD
2009-05-20 11:09:14: ERROR: failed to open pre_share_key file psk.txt
2009-05-20 11:09:14: NOTIFY: couldn't find the proper pskey, try to get one by the peer's address.
2009-05-20 11:09:14: ERROR: failed to open pre_share_key file psk.txt
2009-05-20 11:09:14: ERROR: couldn't find the pskey for 11.11.11.11.
2009-05-20 11:09:14: ERROR: failed to process packet.
2009-05-20 11:09:14: ERROR: phase1 negotiation failed.
2009-05-20 11:09:24: INFO: respond new phase 1 negotiation: 22.22.22.22[500]<=>11.11.11.11[500]
2009-05-20 11:09:24: INFO: begin Aggressive mode.
2009-05-20 11:09:24: INFO: received Vendor ID: DPD
2009-05-20 11:09:24: ERROR: failed to open pre_share_key file psk.txt
2009-05-20 11:09:24: NOTIFY: couldn't find the proper pskey, try to get one by the peer's address.
2009-05-20 11:09:24: ERROR: failed to open pre_share_key file psk.txt
2009-05-20 11:09:24: ERROR: couldn't find the pskey for 11.11.11.11.
2009-05-20 11:09:24: ERROR: failed to process packet.
2009-05-20 11:09:24: ERROR: phase1 negotiation failed.
2009-05-20 11:09:34: INFO: respond new phase 1 negotiation: 22.22.22.22[500]<=>11.11.11.11[500]
2009-05-20 11:09:34: INFO: begin Aggressive mode.
2009-05-20 11:09:34: INFO: received Vendor ID: DPD
2009-05-20 11:09:34: ERROR: failed to open pre_share_key file psk.txt
2009-05-20 11:09:34: NOTIFY: couldn't find the proper pskey, try to get one by the peer's address.
2009-05-20 11:09:34: ERROR: failed to open pre_share_key file psk.txt
2009-05-20 11:09:34: ERROR: couldn't find the pskey for 11.11.11.11.
2009-05-20 11:09:34: ERROR: failed to process packet.
2009-05-20 11:09:34: ERROR: phase1 negotiation failed.
2009-05-20 11:09:40: INFO: IPsec-SA request for 11.11.11.11 queued due to no phase1 found.
2009-05-20 11:09:40: ERROR: unknown AF: 0
2009-05-20 11:09:40: INFO: initiate new phase 1 negotiation: 22.22.22.22[500]<=>11.11.11.11[500]
2009-05-20 11:09:40: INFO: begin Aggressive mode.
2009-05-20 11:09:44: INFO: respond new phase 1 negotiation: 22.22.22.22[500]<=>11.11.11.11[500]
2009-05-20 11:09:44: INFO: begin Aggressive mode.
2009-05-20 11:09:44: INFO: received Vendor ID: DPD
2009-05-20 11:09:44: ERROR: failed to open pre_share_key file psk.txt
2009-05-20 11:09:44: NOTIFY: couldn't find the proper pskey, try to get one by the peer's address.
2009-05-20 11:09:44: ERROR: failed to open pre_share_key file psk.txt
2009-05-20 11:09:44: ERROR: couldn't find the pskey for 11.11.11.11.
2009-05-20 11:09:44: ERROR: failed to process packet.
2009-05-20 11:09:44: ERROR: phase1 negotiation failed.
2009-05-20 11:09:52: INFO: phase2 sa expired 22.22.22.22-11.11.11.11
2009-05-20 11:09:52: INFO: request for establishing IPsec-SA was queued due to no phase1 found.
2009-05-20 11:09:53: INFO: phase2 sa deleted 22.22.22.22-11.11.11.11
2009-05-20 11:10:02: INFO: phase2 sa expired 22.22.22.22-11.11.11.11
2009-05-20 11:10:02: INFO: request for establishing IPsec-SA was queued due to no phase1 found.
2009-05-20 11:10:03: INFO: phase2 sa deleted 22.22.22.22-11.11.11.11
2009-05-20 11:10:14: INFO: phase2 sa expired 22.22.22.22-11.11.11.11
2009-05-20 11:10:14: INFO: request for establishing IPsec-SA was queued due to no phase1 found.
2009-05-20 11:10:15: INFO: phase2 sa deleted 22.22.22.22-11.11.11.11
2009-05-20 11:10:24: INFO: phase2 sa expired 22.22.22.22-11.11.11.11
2009-05-20 11:10:24: INFO: request for establishing IPsec-SA was queued due to no phase1 found.
2009-05-20 11:10:25: INFO: phase2 sa deleted 22.22.22.22-11.11.11.11
2009-05-20 11:10:30: ERROR: phase1 negotiation failed due to time up. b40a7c6b618ace50:0000000000000000
2009-05-20 11:10:36: INFO: phase2 sa expired 22.22.22.22-11.11.11.11
2009-05-20 11:10:36: INFO: IPsec-SA request for 11.11.11.11 queued due to no phase1 found.
2009-05-20 11:10:36: ERROR: unknown AF: 0
2009-05-20 11:10:36: INFO: initiate new phase 1 negotiation: 22.22.22.22[500]<=>11.11.11.11[500]
2009-05-20 11:10:36: INFO: begin Aggressive mode.
2009-05-20 11:10:37: INFO: phase2 sa deleted 22.22.22.22-11.11.11.11
2009-05-20 11:11:07: ERROR: phase2 negotiation failed due to time up waiting for phase1. ESP 11.11.11.11[0]->22.22.22.22[0]
2009-05-20 11:11:07: INFO: delete phase 2 handler.
2009-05-20 11:11:26: ERROR: phase1 negotiation failed due to time up. 6f35d209066086c1:0000000000000000
2009-05-20 11:11:43: INFO: IPsec-SA request for 11.11.11.11 queued due to no phase1 found.
2009-05-20 11:11:43: ERROR: unknown AF: 0
2009-05-20 11:11:43: INFO: initiate new phase 1 negotiation: 22.22.22.22[500]<=>11.11.11.11[500]
2009-05-20 11:11:43: INFO: begin Aggressive mode.
2009-05-20 11:12:15: ERROR: phase2 negotiation failed due to time up waiting for phase1. ESP 11.11.11.11[0]->22.22.22.22[0]
2009-05-20 11:12:15: INFO: delete phase 2 handler.
2009-05-20 11:12:33: ERROR: phase1 negotiation failed due to time up. fe65148b3522e3ac:0000000000000000