Hi , ik zie hier volop tweakers met Azure site to site verbindingen die ook bij velen werkt.
Mij lukt het statisch en dynamisch niet.
Wat doe ik verkeerd?
Firewall uitgezet op de Zyxel. Alle combinaties aan encryptie geprobeerd.
Van alles gelezen
https://documentation.mer...2Ffailed_to_get_sainfo.22
https://azure.microsoft.c...ateway-about-vpn-devices/
[Config]
Azure :
10.10.0.0 /16
Thuis
192.168.1.0/24
Zyxel Firmware V1.00(AAKL.14)C0
Remote IPSec Gateway Address (IP or Domain Name)
13.94.153.163
Tunnel access from local IP addresses
subnet
IP Address for VPN
192.168.1.0
IP Subnetmask
255.255.255.0
Tunnel access from remote IP addresses
subnet
IP Address for VPN
10.10.0.0
IP Subnetmask
255.255.0.0
Protocol
ESP
Key Exchange Method
AutoIKE
Authentication Method
preshared-key
presharedkey xxxxxxxxxx
Local ID leeg
Local ID leeg
Remote ID leeg
Remote ID leeg
Phase 1
Mode
Main
Encryption Algorithm
AES-256
Integrity Algorithm
SHA1
Perfect Forward Secrecy(PFS)
(DH Group 1) 1024bit'
keylifetime
3600
Phase 2
Mode
Main
Encryption Algorithm
AES-256
Integrity Algorithm
SHA1
Perfect Forward Secrecy(PFS)
(DH Group 1) 1024bit
keylifetime
3600
Log Zyxel
1 2016 May 26 23:48:51 IPSec err invalid flag 0x08.
2 2016 May 26 23:48:48 IPSec err phase1 negotiation failed due to time up. 70ac81f15e9ad857:0000000000000000
3 2016 May 26 23:48:47 IPSec err last message repeated 2 times in 2 seconds
4 2016 May 26 23:48:45 IPSec err invalid flag 0x08.
5 2016 May 26 23:48:40 IPSec err invalid flag 0x08.
6 2016 May 26 23:48:39 IPSec err invalid flag 0x08.
7 2016 May 26 23:48:38 IPSec err notification NO-PROPOSAL-CHOSEN received in unencrypted informational exchange.
8 2016 May 26 23:48:38 IPSec err invalid flag 0x08.
9 2016 May 26 23:48:29 IPSec info delete phase 2 handler.
10 2016 May 26 23:48:29 IPSec err phase2 negotiation failed due to time up waiting for phase1. ESP 13.94.153.163[0]->84.245.xx.xx0]
11 2016 May 26 23:48:28 IPSec err notification NO-PROPOSAL-CHOSEN received in unencrypted informational exchange.
12 2016 May 26 23:48:18 IPSec err notification NO-PROPOSAL-CHOSEN received in unencrypted informational exchange.
13 2016 May 26 23:48:16 IPSec err last message repeated 4 times in 7 seconds
14 2016 May 26 23:48:09 IPSec err invalid flag 0x08.
15 2016 May 26 23:48:08 IPSec err notification NO-PROPOSAL-CHOSEN received in unencrypted informational exchange.
16 2016 May 26 23:48:08 IPSec err last message repeated 3 times in 7 seconds
17 2016 May 26 23:48:01 IPSec err invalid flag 0x08.
18 2016 May 26 23:47:58 IPSec err notification NO-PROPOSAL-CHOSEN received in unencrypted informational exchange.
19 2016 May 26 23:47:58 IPSec info begin Identity Protection mode.
20 2016 May 26 23:47:58 IPSec info initiate new phase 1 negotiation: 84.245.xx.xx[500]<=>13.94.153.163[500]
21 2016 May 26 23:47:58 IPSec info IPsec-SA request for 13.94.153.163 queued due to no phase1 found.
22 2016 May 26 23:47:48 IPSec err phase1 negotiation failed due to time up. b15c4c63815b2afb:0000000000000000
23 2016 May 26 23:47:48 IPSec err last message repeated 5 times in 9 seconds
24 2016 May 26 23:47:39 IPSec err invalid flag 0x08.
25 2016 May 26 23:47:38 IPSec err notification NO-PROPOSAL-CHOSEN received in unencrypted informational exchange.
26 2016 May 26 23:47:34 IPSec err last message repeated 2 times in 2 seconds
27 2016 May 26 23:47:32 IPSec err invalid flag 0x08.
28 2016 May 26 23:47:29 IPSec info delete phase 2 handler.
29 2016 May 26 23:47:29 IPSec err phase2 negotiation failed due to time up waiting for phase1. ESP 13.94.153.163[0]->84.245.xx.xx[0]
Alvast reuze bedankt! Trek al mijn haren al uit mijn hoofd.
Lifetime key ook al verhoogd. Maar niets lijkt zomaar te werken.....
Aangepast :
van dynamic naar STATIC Switch
Phase 2 :
AES-128
SHA1
Perfect Forward secrecy (PFS)
NONE
Keyliftetime 3600
Nieuwe logs :
2016 May 27 10:42:30 IPSec info delete phase 2 handler.
3 2016 May 27 10:42:30 IPSec err phase2 negotiation failed due to time up waiting for phase1. ESP 40.68.231.44[0]->84.245.xx.xx[0]
6 2016 May 27 10:42:29 IPSec notice last message repeated 2 times in 4 seconds
7 2016 May 27 10:42:25 IPSec notice the packet is retransmitted by 40.68.231.44[500] (1).
8 2016 May 27 10:42:24 IPSec info an acceptable phase 1 proposal found.
9 2016 May 27 10:42:24 IPSec info dh_group = 1024-bit MODP group
10 2016 May 27 10:42:24 IPSec info authmethod = pre-shared key
11 2016 May 27 10:42:24 IPSec info hashtype = SHA
12 2016 May 27 10:42:24 IPSec info encklen = 256
13 2016 May 27 10:42:24 IPSec info enctype = AES-CBC
14 2016 May 27 10:42:24 IPSec info lifebyte = 0
15 2016 May 27 10:42:24 IPSec info lifetime = 28800
16 2016 May 27 10:42:24 IPSec info trns#=2, trns-id=IKE
17 2016 May 27 10:42:24 IPSec info prop#=1, prot-id=ISAKMP, spi-size=0, #trns=4
18 2016 May 27 10:42:24 IPSec err invalied hash algorithm=4.
19 2016 May 27 10:42:24 IPSec info received Vendor ID: FRAGMENTATION
20 2016 May 27 10:42:24 IPSec info received Vendor ID: draft-ietf-ipsec-nat-t-ike-02
21 2016 May 27 10:42:24 IPSec info received Vendor ID: RFC 3947
22 2016 May 27 10:42:24 IPSec info received broken Microsoft ID: MS NT5 ISAKMPOAKLEY
23 2016 May 27 10:42:24 IPSec info begin Identity Protection mode.
24 2016 May 27 10:42:24 IPSec info respond new phase 1 negotiation: 84.245.xx.xx[500]<=>40.68.231.44[500]
25 2016 May 27 10:42:09 Account warn last message repeated 7 times in 5 seconds
26 2016 May 27 10:42:04 Account warn User admin login from 192.168.1.5 successful
27 2016 May 27 10:41:59 IPSec info request for establishing IPsec-SA was queued due to no phase1 found.
28 2016 May 27 10:41:46 IPSec info an acceptable phase 1 proposal found.
29 2016 May 27 10:41:46 IPSec info dh_group = 1024-bit MODP group
30 2016 May 27 10:41:46 IPSec info authmethod = pre-shared key
2 2016 May 27 10:36:13 IPSec err phase1 negotiation failed due to time up. 70856747a8c65d00:4378cd538df533d4
5 2016 May 27 10:35:59 IPSec info request for establishing IPsec-SA was queued due to no phase1 found.
[
Voor 23% gewijzigd door
hives op 27-05-2016 10:48
]
AMD XP 3000+ , Asus A7v333 Raid , 3 x maxtor 40 gb 7200 rpm , asus nvidia geforce FX 5950 Ultra 256 MB, 1024 Kingston DDR PC-2700, Creative Audigy 2 ZS , Pioneer 106s 16 x 40 x , Lite-on 52 x 32 x , 52 x, Sony DVD Writer 4x Extern , Ilyama HM204DT 22 Inch