From owner-freebsd-security@FreeBSD.ORG Tue Nov 20 11:08:33 2007 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id AD85B16A41B for ; Tue, 20 Nov 2007 11:08:33 +0000 (UTC) (envelope-from bj@0x20.net) Received: from mail.0x20.net (mail.ipv6.0x20.net [IPv6:2001:aa8:fffb::3]) by mx1.freebsd.org (Postfix) with ESMTP id 4F61F13C459 for ; Tue, 20 Nov 2007 11:08:33 +0000 (UTC) (envelope-from bj@0x20.net) Received: by mail.0x20.net (Postfix, from userid 1001) id A2EB93A590; Tue, 20 Nov 2007 12:08:31 +0100 (CET) Date: Tue, 20 Nov 2007 12:08:31 +0100 From: Bjoern Engels To: john decot Message-ID: <20071120110831.GB90344@e.0x20.net> References: <20071119093829.GA22050@zen.inc> <216526.27461.qm@web55401.mail.re4.yahoo.com> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline In-Reply-To: <216526.27461.qm@web55401.mail.re4.yahoo.com> X-PGP-KeyID: FB601479 User-Agent: Mutt/1.5.16 (2007-06-09) Cc: freebsd-security@freebsd.org Subject: Re: IPSEC help X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 20 Nov 2007 11:08:33 -0000 On Tue, Nov 20, 2007 at 02:57:17AM -0800, john decot wrote: > Hi, > > I have checked with different mode that obey and found error no valid proposal and again i change lifetime too in bsd server. But I can't found where should i have to change those parameter in remote windows ipsec box. > > Could you please suggest me. [...] > 2007-11-17 13:46:22: DEBUG: Compared: DB:Peer > 2007-11-17 13:46:22: DEBUG: (lifetime = 1800:28800) I suggest you change the lifetime in racoon's config to 28800 seconds if you cannot change it at the peer. Aonther thing I'd check is encryption/hash algorithms. You'll probably have the best compatibility if you change everything to 3DES-MD5. -- Viele Gruesse // Best regards Bjoern Engels :wq!