Mailing List Archive

INVALID_PAYLOAD_TYPE
Maurice Massar wrote:
> in short:
> vpnc progresses without problems until it starts the IPsec SA
> negotiation, at which point the concentrator sends a ISAKMP delete
> notice.
> This means that the concentrator did not look at the SA proposal at
> all, and was expecting vpnc to do "something else" first...

Ok, I've discovered what this is, I think. The concentrator is a Cisco 3000
that's been configured to insist that the client switched on its internal
firewall. I've tested the Linux Cisco client, however the Linux client does
not support the firewall functionality, hence it terminates with an error
like so...

Authenticating user.
Negotiating security policies.
Securing communication channel.
Secure VPN Connection terminated by Peer.
Reason: Firewall Policy Mismatch.
There are no new notification messages at this time.

Would a debug trace still be useful in this instance or should I install the
Windows version & get a log?

--
Ian Cass
INVALID_PAYLOAD_TYPE [ In reply to ]
hi,

> Ok, I've discovered what this is, I think. The concentrator is a Cisco 3000
> that's been configured to insist that the client switched on its internal
> firewall. I've tested the Linux Cisco client, however the Linux client does
> not support the firewall functionality, hence it terminates with an error
> like so...
[...]
> Reason: Firewall Policy Mismatch.
> There are no new notification messages at this time.
>
> Would a debug trace still be useful in this instance or should I install the
> Windows version & get a log?

a concentrator with some ""interesting"" settings...
if you could provide me with a log from a windows client,
maybe I'm then able to fake the required modecfg attributes..

a better way would be to get the admin fix the config..

cu
maurice