From owner-freebsd-net@FreeBSD.ORG Wed Jun 23 08:06:01 2010 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 574DF106566C for ; Wed, 23 Jun 2010 08:06:01 +0000 (UTC) (envelope-from vanhu@zeninc.net) Received: from smtp.zeninc.net (smtp.zeninc.net [80.67.176.25]) by mx1.freebsd.org (Postfix) with ESMTP id 0D5788FC15 for ; Wed, 23 Jun 2010 08:05:57 +0000 (UTC) Received: from astro.zen.inc (astro.zen.inc [192.168.1.239]) by smtp.zeninc.net (smtpd) with ESMTP id E164B2798BC; Wed, 23 Jun 2010 10:05:55 +0200 (CEST) Received: by astro.zen.inc (Postfix, from userid 1000) id B895717063; Wed, 23 Jun 2010 10:05:55 +0200 (CEST) Date: Wed, 23 Jun 2010 10:05:55 +0200 From: VANHULLEBUS Yvan To: ralf@dzie-ciuch.pl Message-ID: <20100623080555.GB74303@zeninc.net> References: <20100622143543.GA72020@zeninc.net> <20100622153541.GA72211@zeninc.net> <6caa9895ae1710b9f48a227116a4340c@ewipo.pl> <20100622190819.270aaa74@gda-arsenic> <4f378cfb416582c3081377ba714e508a@ewipo.pl> <20100622201130.5824d585@gda-arsenic> <20100622182242.GU2620@verio.net> <20100622204107.6c604c17@gda-arsenic> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: User-Agent: All mail clients suck. This one just sucks less. Cc: freebsd-net@freebsd.org Subject: Re: vpn trouble X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 23 Jun 2010 08:06:01 -0000 On Wed, Jun 23, 2010 at 09:53:56AM +0200, ralf@dzie-ciuch.pl wrote: > > Hi, Hi. > I set everything like you wrote and I can send and receice packets but > still I can't ping to host 10.10.1.90, > and when I type #setkey -D there is no SAD entry > > What could it be? > > This is part of racoon log: [....] Do you have a line which says: INFO: ISAKMP-SA established Until you have such line, you still have issues with your phase 1 negociation, and we'll need almost a full debug to be able to help you (be careful: there are some private informations in such debug, like public IPs, preshared-keys, etc....). Yvan.