I'm trying to connect a Watchguard Firebox to ISA 2004 using an IPSec
tunnel. Quick mode SEEMS to be working, but it fails is ISAKMP
informational exchange. Any ideas? Here's the oakley.log:
9-13: 15:11:28:312:17f8 Acquire from driver: op=00000019 src=XX.XX.XX.XX.0
dst=192.168.YY.56.0 proto = 0, SrcMask=255.255.255.255,
DstMask=255.255.255.0, Tunnel 1, TunnelEndpt=YY.YY.YY.YY Inbound
TunnelEndpt=XX.XX.XX.XX
9-13: 15:11:28:312:1590 outstanding_kernel_req returned 0
9-13: 15:11:28:312:1590 Created new SA 50bf718
9-13: 15:11:28:312:1590 Filter to match: Src YY.YY.YY.YY Dst XX.XX.XX.XX
9-13: 15:11:28:328:1590 MM PolicyName: ISA Server London MM Policy
9-13: 15:11:28:328:1590 MMPolicy dwFlags 0 SoftSAExpireTime 28800
9-13: 15:11:28:328:1590 MMOffer[0] LifetimeSec 28800 QMLimit 0 DHGroup 1
9-13: 15:11:28:328:1590 MMOffer[0] Encrypt: Triple DES CBC Hash: SHA
9-13: 15:11:28:328:1590 Auth[0]:PresharedKey KeyLen 20
9-13: 15:11:28:328:1590 QM PolicyName: ISA Server London QM Policy dwFlags
0
9-13: 15:11:28:328:1590 QMOffer[0] LifetimeKBytes 0 LifetimeSec 28800
9-13: 15:11:28:328:1590 QMOffer[0] dwFlags 0 dwPFSGroup 0
9-13: 15:11:28:328:1590 Algo[0] Operation: ESP Algo: Triple DES CBC HMAC:
SHA
9-13: 15:11:28:328:1590 Starting Negotiation: src = XX.XX.XX.XX.0500, dst =
YY.YY.YY.YY.0500, proto = 00, context = 00000019, ProxySrc =
XX.XX.XX.XX.0000, ProxyDst = 192.168.YY.0.0000 SrcMask = 255.255.255.255
DstMask = 255.255.255.0
9-13: 15:11:28:328:1590 constructing ISAKMP Header
9-13: 15:11:28:328:1590 constructing SA (ISAKMP)
9-13: 15:11:28:328:1590 Constructing Vendor MS NT5 ISAKMPOAKLEY
9-13: 15:11:28:328:1590 Constructing Vendor FRAGMENTATION
9-13: 15:11:28:328:1590 Constructing Vendor draft-ietf-ipsec-nat-t-ike-02
9-13: 15:11:28:328:1590 Constructing Vendor Vid-Initial-Contact
9-13: 15:11:28:328:1590 send_request SA 050BF718 centry 00000000 RetryType
2 Context 00000000
9-13: 15:11:28:328:1590 TotalActiveTimers++ 1
9-13: 15:11:28:328:1590 Inserting entry 05B743A0 in slot 33 CurWheelIndex
32 delta 1000
9-13: 15:11:28:328:1590 Setting Retransmit: sa 50bf718 handle 5b743a0
context 5b293a0
9-13: 15:11:28:328:1590
9-13: 15:11:28:328:1590 Sending: SA = 0x050BF718 to YY.YY.YY.YY:Type 2.500
9-13: 15:11:28:328:1590 ISAKMP Header: (V1.0), len = 168
9-13: 15:11:28:328:1590 I-COOKIE 813695f686840e34
9-13: 15:11:28:328:1590 R-COOKIE 0000000000000000
9-13: 15:11:28:328:1590 exchange: Oakley Main Mode
9-13: 15:11:28:328:1590 flags: 0
9-13: 15:11:28:328:1590 next payload: SA
9-13: 15:11:28:328:1590 message ID: 00000000
9-13: 15:11:28:328:1590 Ports S:f401 D:f401
9-13: 15:11:28:484:10e0 Queuing work item, packetsize 100
9-13: 15:11:28:484:1590
9-13: 15:11:28:484:1590 Receive: (get) SA = 0x050bf718 from YY.YY.YY.YY.500
9-13: 15:11:28:484:1590 ISAKMP Header: (V1.0), len = 100
9-13: 15:11:28:484:1590 I-COOKIE 813695f686840e34
9-13: 15:11:28:484:1590 R-COOKIE 087b6e34e9c768b7
9-13: 15:11:28:484:1590 exchange: Oakley Main Mode
9-13: 15:11:28:484:1590 flags: 0
9-13: 15:11:28:484:1590 next payload: SA
9-13: 15:11:28:484:1590 message ID: 00000000
9-13: 15:11:28:484:1590 processing payload SA
9-13: 15:11:28:484:1590 Received Phase 1 Transform 1
9-13: 15:11:28:484:1590 Encryption Alg Triple DES CBC(5)
9-13: 15:11:28:484:1590 Hash Alg SHA(2)
9-13: 15:11:28:484:1590 Auth Method Preshared Key(1)
9-13: 15:11:28:484:1590 Life type in Seconds
9-13: 15:11:28:484:1590 Life duration of 28800
9-13: 15:11:28:484:1590 Oakley Group 1
9-13: 15:11:28:484:1590 Phase 1 SA accepted: transform=1
9-13: 15:11:28:484:1590 SA - Oakley proposal accepted
9-13: 15:11:28:484:1590 processing payload VENDOR ID
9-13: 15:11:28:484:1590 Vendor ID 90cb80913ebb696e086381b5ec427b1f
9-13: 15:11:28:484:1590
9-13: 15:11:28:484:1590 Received VendorId draft-ietf-ipsec-nat-t-ike-02
9-13: 15:11:28:484:1590 Setting VendorId 4
9-13: 15:11:28:484:1590 ClearFragList
9-13: 15:11:28:484:1590 In state OAK_MM_SA_SETUP
9-13: 15:11:28:484:1590 constructing ISAKMP Header
9-13: 15:11:28:515:1590 constructing KE
9-13: 15:11:28:515:1590 constructing NONCE (ISAKMP)
9-13: 15:11:28:515:1590 Constructing NatDisc
9-13: 15:11:28:515:1590 send_request SA 050BF718 centry 00000000 RetryType
2 Context 05B293A0
9-13: 15:11:28:515:1590 TotalActiveTimers--2 0
9-13: 15:11:28:515:1590 TotalActiveTimers++ 1
9-13: 15:11:28:515:1590 Inserting entry 05B743A0 in slot 33 CurWheelIndex
32 delta 1000
9-13: 15:11:28:515:1590
9-13: 15:11:28:515:1590 Sending: SA = 0x050BF718 to YY.YY.YY.YY:Type 2.500
9-13: 15:11:28:515:1590 ISAKMP Header: (V1.0), len = 200
9-13: 15:11:28:515:1590 I-COOKIE 813695f686840e34
9-13: 15:11:28:515:1590 R-COOKIE 087b6e34e9c768b7
9-13: 15:11:28:515:1590 exchange: Oakley Main Mode
9-13: 15:11:28:515:1590 flags: 0
9-13: 15:11:28:515:1590 next payload: KE
9-13: 15:11:28:515:1590 message ID: 00000000
9-13: 15:11:28:515:1590 Ports S:f401 D:f401
9-13: 15:11:28:515:1590 Worker exiting
9-13: 15:11:28:703:10e0 Queuing work item, packetsize 200
9-13: 15:11:28:750:1590
9-13: 15:11:28:750:1590 Receive: (get) SA = 0x050bf718 from YY.YY.YY.YY.500
9-13: 15:11:28:750:1590 ISAKMP Header: (V1.0), len = 200
9-13: 15:11:28:750:1590 I-COOKIE 813695f686840e34
9-13: 15:11:28:750:1590 R-COOKIE 087b6e34e9c768b7
9-13: 15:11:28:750:1590 exchange: Oakley Main Mode
9-13: 15:11:28:750:1590 flags: 0
9-13: 15:11:28:750:1590 next payload: KE
9-13: 15:11:28:750:1590 message ID: 00000000
9-13: 15:11:28:750:1590 processing payload KE
9-13: 15:11:28:750:1590 Generated 96 byte Shared Secret
9-13: 15:11:28:750:1590 KE processed; DH shared secret computed
9-13: 15:11:28:750:1590 processing payload NONCE
9-13: 15:11:28:750:1590 PTID 129 PKTYPE 130
9-13: 15:11:28:750:1590 PTID 130 PKTYPE 130
9-13: 15:11:28:750:1590 processing payload NATDISC
9-13: 15:11:28:750:1590 Processing NatHash
9-13: 15:11:28:750:1590 Nat hash 42740d56cd00754e102bc9679b98f344
9-13: 15:11:28:750:1590 16c2e82b
9-13: 15:11:28:750:1590 SA StateMask2 f
9-13: 15:11:28:750:1590 PTID 129 PKTYPE 130
9-13: 15:11:28:750:1590 PTID 130 PKTYPE 130
9-13: 15:11:28:750:1590 processing payload NATDISC
9-13: 15:11:28:750:1590 Processing NatHash
9-13: 15:11:28:750:1590 Nat hash a1304c4ac1fca7da2aa03ebfdad4a971
9-13: 15:11:28:750:1590 47638853
9-13: 15:11:28:750:1590 SA StateMask2 8f
9-13: 15:11:28:750:1590 ClearFragList
9-13: 15:11:28:750:1590 In state OAK_MM_Key_EXCH
9-13: 15:11:28:750:1590 skeyid generated; crypto enabled (initiator)
9-13: 15:11:28:750:1590 constructing ISAKMP Header
9-13: 15:11:28:750:1590 constructing ID
9-13: 15:11:28:750:1590 MM ID Type 1
9-13: 15:11:28:750:1590 MM ID 425c5b82
9-13: 15:11:28:750:1590 constructing HASH
9-13: 15:11:28:750:1590 send_request SA 050BF718 centry 00000000 RetryType
2 Context 05B293A0
9-13: 15:11:28:750:1590 TotalActiveTimers--2 0
9-13: 15:11:28:750:1590 TotalActiveTimers++ 1
9-13: 15:11:28:750:1590 Inserting entry 05B743A0 in slot 33 CurWheelIndex
33 delta 1000
9-13: 15:11:28:750:1590
9-13: 15:11:28:750:1590 Sending: SA = 0x050BF718 to YY.YY.YY.YY:Type 2.500
9-13: 15:11:28:750:1590 ISAKMP Header: (V1.0), len = 68
9-13: 15:11:28:750:1590 I-COOKIE 813695f686840e34
9-13: 15:11:28:750:1590 R-COOKIE 087b6e34e9c768b7
9-13: 15:11:28:750:1590 exchange: Oakley Main Mode
9-13: 15:11:28:750:1590 flags: 1 ( encrypted )
9-13: 15:11:28:750:1590 next payload: ID
9-13: 15:11:28:750:1590 message ID: 00000000
9-13: 15:11:28:750:1590 Ports S:f401 D:f401
9-13: 15:11:28:750:1590 Worker exiting
9-13: 15:11:28:843:10e0 Queuing work item, packetsize 68
9-13: 15:11:28:843:1590
9-13: 15:11:28:843:1590 Receive: (get) SA = 0x050bf718 from YY.YY.YY.YY.500
9-13: 15:11:28:843:1590 ISAKMP Header: (V1.0), len = 68
9-13: 15:11:28:843:1590 I-COOKIE 813695f686840e34
9-13: 15:11:28:843:1590 R-COOKIE 087b6e34e9c768b7
9-13: 15:11:28:843:1590 exchange: Oakley Main Mode
9-13: 15:11:28:843:1590 flags: 1 ( encrypted )
9-13: 15:11:28:843:1590 next payload: ID
9-13: 15:11:28:843:1590 message ID: 00000000
9-13: 15:11:28:843:1590 processing payload ID
9-13: 15:11:28:843:1590 processing payload HASH
9-13: 15:11:28:843:1590 AUTH: Phase I authentication accepted
9-13: 15:11:28:843:1590 ClearFragList
9-13: 15:11:28:843:1590 Setting SA timeout: 25860
9-13: 15:11:28:843:1590 In state OAK_MM_KEY_AUTH
9-13: 15:11:28:843:1590 MM established. SA: 050BF718
9-13: 15:11:28:843:1590 Created new conn entry 5bbcec8
9-13: 15:11:28:843:1590 Starting QM with mess ID 4f444448
9-13: 15:11:28:843:1590 QM PolicyName: ISA Server London QM Policy dwFlags
0
9-13: 15:11:28:843:1590 QMOffer[0] LifetimeKBytes 0 LifetimeSec 28800
9-13: 15:11:28:843:1590 QMOffer[0] dwFlags 0 dwPFSGroup 0
9-13: 15:11:28:843:1590 Algo[0] Operation: ESP Algo: Triple DES CBC HMAC:
SHA
9-13: 15:11:28:843:1590 GetSpi: src = 192.168.YY.0.0000, dst =
XX.XX.XX.XX.0000, proto = 00, context = 00000019, srcMask = 255.255.255.0,
destMask = 255.255.255.255, TunnelFilter 1
9-13: 15:11:28:843:1590 Setting SPI 2336555781
9-13: 15:11:28:843:1590 Stopping RetransTimer sa:050BF718 centry:00000000
handle:05B743A0
9-13: 15:11:28:843:1590 TotalActiveTimers--2 0
9-13: 15:11:28:843:1590 constructing ISAKMP Header
9-13: 15:11:28:843:1590 constructing HASH (null)
9-13: 15:11:28:843:1590 constructing SA (IPSEC)
9-13: 15:11:28:843:1590 constructing NONCE (IPSEC)
9-13: 15:11:28:843:1590 constructing ID (proxy)
9-13: 15:11:28:843:1590 constructing ID (proxy)
9-13: 15:11:28:843:1590 constructing HASH (QM)
9-13: 15:11:28:843:1590 Construct QM Hash mess ID = 1212433487
9-13: 15:11:28:843:1590 send_request SA 050BF718 centry 05BBCEC8 RetryType
2 Context 00000000
9-13: 15:11:28:843:1590 TotalActiveTimers++ 1
9-13: 15:11:28:843:1590 Inserting entry 05B74198 in slot 33 CurWheelIndex
33 delta 1000
9-13: 15:11:28:843:1590 Setting Retransmit: sa 50bf718 centry 5bbcec8
handle 5b74198 context 5b669d0
9-13: 15:11:28:843:1590
9-13: 15:11:28:843:1590 Sending: SA = 0x050BF718 to YY.YY.YY.YY:Type 2.500
9-13: 15:11:28:843:1590 ISAKMP Header: (V1.0), len = 156
9-13: 15:11:28:843:1590 I-COOKIE 813695f686840e34
9-13: 15:11:28:843:1590 R-COOKIE 087b6e34e9c768b7
9-13: 15:11:28:843:1590 exchange: Oakley Quick Mode
9-13: 15:11:28:843:1590 flags: 1 ( encrypted )
9-13: 15:11:28:843:1590 next payload: HASH
9-13: 15:11:28:843:1590 message ID: 4f444448
9-13: 15:11:28:843:1590 Ports S:f401 D:f401
9-13: 15:11:28:843:1590 Entered isadb_delete_old_main_modes
9-13: 15:11:28:843:1590 Worker exiting
9-13: 15:11:28:953:10e0 Queuing work item, packetsize 84
9-13: 15:11:28:953:1590
9-13: 15:11:28:953:1590 Receive: (get) SA = 0x050bf718 from YY.YY.YY.YY.500
9-13: 15:11:28:953:1590 ISAKMP Header: (V1.0), len = 84
9-13: 15:11:28:953:1590 I-COOKIE 813695f686840e34
9-13: 15:11:28:953:1590 R-COOKIE 087b6e34e9c768b7
9-13: 15:11:28:953:1590 exchange: ISAKMP Informational Exchange
9-13: 15:11:28:953:1590 flags: 1 ( encrypted )
9-13: 15:11:28:953:1590 next payload: HASH
9-13: 15:11:28:953:1590 message ID: 03ef36ae
9-13: 15:11:28:953:1590 processing HASH (Notify/Delete)
9-13: 15:11:28:953:1590 Bad N/D Hash
9-13: 15:11:28:953:1590 ProcessFailure: sa:050BF718 centry:00000000
status:360d
9-13: 15:11:28:953:1590 unable to process info-only exchange
9-13: 15:11:28:953:1590 Worker exiting
9-13: 15:11:29:609:152c TotalActiveTimers--3 0
9-13: 15:11:29:609:152c TotalActiveTimers++ 1
9-13: 15:11:29:609:152c Inserting entry 05B74198 in slot 34 CurWheelIndex
34 delta 1000
9-13: 15:11:29:609:152c Handling Retransmit: sa 050BF718 centry 05BBCEC8
handle 05B74198 type 2
9-13: 15:11:29:609:152c retransmit: sa = 050BF718 centry 05BBCEC8 , count =
1
9-13: 15:11:29:609:152c send_request SA 050BF718 centry 05BBCEC8 RetryType
2 Context 05B669D0
9-13: 15:11:29:609:152c TotalActiveTimers--2 0
9-13: 15:11:29:609:152c TotalActiveTimers++ 1
9-13: 15:11:29:609:152c Inserting entry 05B74198 in slot 35 CurWheelIndex
34 delta 2000
9-13: 15:11:29:609:152c
9-13: 15:11:29:609:152c Sending: SA = 0x050BF718 to YY.YY.YY.YY:Type 2.500
9-13: 15:11:29:609:152c ISAKMP Header: (V1.0), len = 156
9-13: 15:11:29:609:152c I-COOKIE 813695f686840e34
9-13: 15:11:29:609:152c R-COOKIE 087b6e34e9c768b7
9-13: 15:11:29:609:152c exchange: Oakley Quick Mode
9-13: 15:11:29:609:152c flags: 1 ( encrypted )
9-13: 15:11:29:609:152c next payload: HASH
9-13: 15:11:29:609:152c message ID: 4f444448
9-13: 15:11:29:609:152c Ports S:f401 D:f401
9-13: 15:11:29:703:10e0 Queuing work item, packetsize 84
9-13: 15:11:29:703:1590
9-13: 15:11:29:703:1590 Receive: (get) SA = 0x050bf718 from YY.YY.YY.YY.500
9-13: 15:11:29:703:1590 ISAKMP Header: (V1.0), len = 84
9-13: 15:11:29:703:1590 I-COOKIE 813695f686840e34
9-13: 15:11:29:703:1590 R-COOKIE 087b6e34e9c768b7
9-13: 15:11:29:703:1590 exchange: ISAKMP Informational Exchange
9-13: 15:11:29:703:1590 flags: 1 ( encrypted )
9-13: 15:11:29:703:1590 next payload: HASH
9-13: 15:11:29:703:1590 message ID: 19f0a03e
9-13: 15:11:29:703:1590 processing HASH (Notify/Delete)
9-13: 15:11:29:703:1590 Bad N/D Hash
9-13: 15:11:29:703:1590 ProcessFailure: sa:050BF718 centry:00000000
status:360d
9-13: 15:11:29:703:1590 unable to process info-only exchange
9-13: 15:11:29:703:1590 Worker exiting
9-13: 15:11:31:609:152c TotalActiveTimers--3 0
9-13: 15:11:31:609:152c TotalActiveTimers++ 1
9-13: 15:11:31:609:152c Inserting entry 05B74198 in slot 37 CurWheelIndex
36 delta 2000
9-13: 15:11:31:609:152c Handling Retransmit: sa 050BF718 centry 05BBCEC8
handle 05B74198 type 2
9-13: 15:11:31:609:152c retransmit: sa = 050BF718 centry 05BBCEC8 , count =
2
9-13: 15:11:31:609:152c send_request SA 050BF718 centry 05BBCEC8 RetryType
2 Context 05B669D0
9-13: 15:11:31:609:152c TotalActiveTimers--2 0
9-13: 15:11:31:609:152c TotalActiveTimers++ 1
9-13: 15:11:31:609:152c Inserting entry 05B74198 in slot 39 CurWheelIndex
36 delta 4000
9-13: 15:11:31:609:152c
9-13: 15:11:31:609:152c Sending: SA = 0x050BF718 to YY.YY.YY.YY:Type 2.500
9-13: 15:11:31:609:152c ISAKMP Header: (V1.0), len = 156
9-13: 15:11:31:609:152c I-COOKIE 813695f686840e34
9-13: 15:11:31:609:152c R-COOKIE 087b6e34e9c768b7
9-13: 15:11:31:609:152c exchange: Oakley Quick Mode
9-13: 15:11:31:609:152c flags: 1 ( encrypted )
9-13: 15:11:31:609:152c next payload: HASH
9-13: 15:11:31:609:152c message ID: 4f444448
9-13: 15:11:31:609:152c Ports S:f401 D:f401
9-13: 15:11:31:703:10e0 Queuing work item, packetsize 84
9-13: 15:11:31:703:1590
9-13: 15:11:31:703:1590 Receive: (get) SA = 0x050bf718 from YY.YY.YY.YY.500
9-13: 15:11:31:703:1590 ISAKMP Header: (V1.0), len = 84
9-13: 15:11:31:703:1590 I-COOKIE 813695f686840e34
9-13: 15:11:31:703:1590 R-COOKIE 087b6e34e9c768b7
9-13: 15:11:31:703:1590 exchange: ISAKMP Informational Exchange
9-13: 15:11:31:703:1590 flags: 1 ( encrypted )
9-13: 15:11:31:703:1590 next payload: HASH
9-13: 15:11:31:703:1590 message ID: 67c60c40
9-13: 15:11:31:703:1590 processing HASH (Notify/Delete)
9-13: 15:11:31:703:1590 Bad N/D Hash
9-13: 15:11:31:703:1590 ProcessFailure: sa:050BF718 centry:00000000
status:360d
9-13: 15:11:31:703:1590 unable to process info-only exchange
9-13: 15:11:31:703:1590 Worker exiting
9-13: 15:11:35:609:152c TotalActiveTimers--3 0
9-13: 15:11:35:609:152c TotalActiveTimers++ 1
9-13: 15:11:35:609:152c Inserting entry 05B74198 in slot 43 CurWheelIndex
40 delta 4000
9-13: 15:11:35:609:152c Handling Retransmit: sa 050BF718 centry 05BBCEC8
handle 05B74198 type 2
9-13: 15:11:35:609:152c retransmit: sa = 050BF718 centry 05BBCEC8 , count =
3
9-13: 15:11:35:609:152c send_request SA 050BF718 centry 05BBCEC8 RetryType
2 Context 05B669D0
9-13: 15:11:35:609:152c TotalActiveTimers--2 0
9-13: 15:11:35:609:152c TotalActiveTimers++ 1
9-13: 15:11:35:609:152c Inserting entry 05B74198 in slot 47 CurWheelIndex
40 delta 8000
9-13: 15:11:35:609:152c
9-13: 15:11:35:609:152c Sending: SA = 0x050BF718 to YY.YY.YY.YY:Type 2.500
9-13: 15:11:35:609:152c ISAKMP Header: (V1.0), len = 156
9-13: 15:11:35:609:152c I-COOKIE 813695f686840e34
9-13: 15:11:35:609:152c R-COOKIE 087b6e34e9c768b7
9-13: 15:11:35:609:152c exchange: Oakley Quick Mode
9-13: 15:11:35:609:152c flags: 1 ( encrypted )
9-13: 15:11:35:609:152c next payload: HASH
9-13: 15:11:35:609:152c message ID: 4f444448
9-13: 15:11:35:609:152c Ports S:f401 D:f401
9-13: 15:11:35:703:10e0 Queuing work item, packetsize 84
9-13: 15:11:35:703:1590
9-13: 15:11:35:703:1590 Receive: (get) SA = 0x050bf718 from YY.YY.YY.YY.500
9-13: 15:11:35:703:1590 ISAKMP Header: (V1.0), len = 84
9-13: 15:11:35:703:1590 I-COOKIE 813695f686840e34
9-13: 15:11:35:703:1590 R-COOKIE 087b6e34e9c768b7
9-13: 15:11:35:703:1590 exchange: ISAKMP Informational Exchange
9-13: 15:11:35:703:1590 flags: 1 ( encrypted )
9-13: 15:11:35:703:1590 next payload: HASH
9-13: 15:11:35:703:1590 message ID: 13b8d534
9-13: 15:11:35:703:1590 processing HASH (Notify/Delete)
9-13: 15:11:35:703:1590 Bad N/D Hash
9-13: 15:11:35:703:1590 ProcessFailure: sa:050BF718 centry:00000000
status:360d
9-13: 15:11:35:703:1590 unable to process info-only exchange
9-13: 15:11:35:703:1590 Worker exiting
|