12-13-2004 08:19 AM - edited 02-20-2020 11:48 PM
It is not possible get the tunnel up and running between the VPN Concentrator 3020 and Hardware Client 3002. It seems to be a problem with the network extension mode.
Following is an extract from the Reporting:
53251 12/13/2004 16:45:39.530 SEV=4 IKE/49 RPT=2793 xx.xx.xx.xx
Group [VPN_yyy_yyy] User [yyy_yyy]
Security negotiation complete for User (yyy_yyy)
Responder, Inbound SPI = 0x1132a684, Outbound SPI = 0x4c889fd2
53254 12/13/2004 16:45:39.530 SEV=4 IKE/125 RPT=795 xx.xx.xx.xx
Group [VPN_yyy_yyy] User [yyy_yyy]
Failed to validate remote network for network extension mode
53256 12/13/2004 16:45:39.530 SEV=4 AUTH/60 RPT=795
Remote Network Address (10.67.234.0) does not matched
framed IP address (194.40.160.128)
53258 12/13/2004 16:45:39.530 SEV=4 IKEDBG/97 RPT=806 xx.xx.xx.xx
Group [VPN_yyy_yyy] User [yyy_yyy]
QM FSM error (P2 struct &0xb178854, mess id 0x85142b95)!
53260 12/13/2004 16:45:39.550 SEV=4 AUTH/28 RPT=795 xx.xx.xx.xx
User [yyy_yyy] Group [VPN_yyy_yyy] disconnected:
Session Type: IPSec
Duration: 0:00:02
Bytes xmt: 0
Bytes rcv: 0
Reason: User Requested
Thanks very much for your help.
Markus
12-13-2004 03:05 PM
This usually occurs when you're doing Radius authentication on the 30xx for the 3002 user, and the Radius user profile is returning an IP address (Framed IP address) to the 3020. With the 3002 in NEM you can't have the Radius server return an IP address, so check the user profile on the Radius server and make sure it is not sending an IP address back in its return attributes.
To verify set up a test account on the Radius server without any attributes, just a username and password, then configure that username on the 3002 and see what happens.
12-14-2004 12:44 AM
Thanks very much.
But we don't use RADIUS for authentication, instead we use internal Authentication on both sides.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide