ā07-22-2011 07:58 AM
Hello there
I was using NETGEAR FVS338 as a main router but it is discontinued now and I found the CISCO RV082 as a good replacement option. I am trying to set up a VPN the same way I used to do it with the netgear one but seems like something is being missed up
I am trying to connect the VPN to a SonicWall 100 device using gateway to gateway, 3DES/MD5, agresive mode and IKE with preshared key.
I already have the local id, remote ID and subnet configured in the SonicWall device as well as the remote IP address. I used to enter these information in the IKE and VPN configuration screens in the Netgear FVS338 we used to work with. I also have the PreShared Key code I entered in the configuration.
Error: INVALID_HASH_INFORMATION
Does someone has an idea why is this happening?
Ivan
ā07-22-2011 08:45 AM
Hi Ivan,
Have you updated the firmware of the RV082 to the current version of code;
RV082-v2.0.2.01-tm-20110308.rmt
Release Date: 15/JUN/2011
RV082 firmware 2.0.2.01-tm
Size: 5291.17 KB (5418154 bytes)
It also sounds like you are using MD5 for hashing at IKE negototiation.
May have to experiment a wee bit with IKE after hours, and alter MD5 to something like SHA1 or above on both units.
Check to see if it works. may have to play with these IKE settings a wee bit.
But the easiest and first thing to do is initially upgrade the firmware , if you are at the old version of code.
regards dave
ā07-22-2011 11:13 AM
Hi Dave
Thank you for replying back.
The firmware I am actually using is below because I am using version 3 hardware.:
RV0XX-v4.0.3.03-tm-20110513-code.bin
Release Date: 15/JUN/2011
RV042, RV082, RV016 firmware 4.0.3.03-tm (V3 hardware required)
Size: 26588.00 KB (27226112 bytes) RV0XX-v4.0.3.03-tm-20110513-code.bin
Release Date: 15/JUN/2011
RV042, RV082, RV016 firmware 4.0.3.03-tm (V3 hardware required)
Size: 26588.00 KB (27226112 bytes)
I will try with the IKE configuration and will let you know
Thank you
ā07-22-2011 11:36 AM
Thanks Ivan,
Ok you have the newer revamped RV082 hardware..cool...I still have to play with Version 1 gear
If we didn't complete IKE negotiation, there is no way IPSec will come up. Thanks for your patience.
Let us know the result.
Regards Dave
ā07-22-2011 11:54 AM
Ok, successful!
The problem was that I was not doing well the IKE configuration as you said (great point btw)
Using 3DES and MD5 got well done for phase 1 and phase 2; the confusing part was on Phase 1 DH group, Phase 1 SA Life Time and the same for Phase 2, so i put everything the way is was on the Netgear (Phase 1 for IKE and Phase 2 for VPN) and got to work with Perfect Forward Secrecy disabled.
Thank you very much
Regards
IvƔn
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide