Issue IKEV1 for Libreswan 3.27 : no connection has been authorized with policy PSK+IKEV1_ALLOWMoving VPN configuration from Juniper SSG5 to serverRV082 Gateway-Gateway VPN Won't ConnectpfSense IPsec VPN setup (Log error: racoon: INFO: unsupported PF_KEY message REGISTER)OpenVPN link to Cisco 3954Pfsense 2.02 unstable ipsec vpn.Tunnels will come up upon restarting racconSonicOS Enhanced 5.8.1.2 L2TP VPN Authentication FailedHow can I connect to a Cisco ASA5540 from Windows Server 2012 over IPSEC?Can't establish site to site vpn connection between Cisco 3900 and strongSwan clientSite to Site IPSec between pfSense and Cisco ASAHow to configure strongswan peer-to-peer vpn tunnel using public IP as encryption domain?

Where to refill my bottle in India?

When blogging recipes, how can I support both readers who want the narrative/journey and ones who want the printer-friendly recipe?

What is the command to reset a PC without deleting any files

Was there ever an axiom rendered a theorem?

Re-submission of rejected manuscript without informing co-authors

Is this food a bread or a loaf?

How is it possible for user's password to be changed after storage was encrypted? (on OS X, Android)

Calculate Levenshtein distance between two strings in Python

Why doesn't a const reference extend the life of a temporary object passed via a function?

Is it wise to hold on to stock that has plummeted and then stabilized?

Why do UK politicians seemingly ignore opinion polls on Brexit?

Is domain driven design an anti-SQL pattern?

Manga about a female worker who got dragged into another world together with this high school girl and she was just told she's not needed anymore

Is there any use for defining additional entity types in a SOQL FROM clause?

How would photo IDs work for shapeshifters?

Why was the "bread communication" in the arena of Catching Fire left out in the movie?

Why did the Germans forbid the possession of pet pigeons in Rostov-on-Don in 1941?

What do you call something that goes against the spirit of the law, but is legal when interpreting the law to the letter?

aging parents with no investments

Does the average primeness of natural numbers tend to zero?

Denied boarding due to overcrowding, Sparpreis ticket. What are my rights?

What to wear for invited talk in Canada

extract characters between two commas?

I’m planning on buying a laser printer but concerned about the life cycle of toner in the machine



Issue IKEV1 for Libreswan 3.27 : no connection has been authorized with policy PSK+IKEV1_ALLOW


Moving VPN configuration from Juniper SSG5 to serverRV082 Gateway-Gateway VPN Won't ConnectpfSense IPsec VPN setup (Log error: racoon: INFO: unsupported PF_KEY message REGISTER)OpenVPN link to Cisco 3954Pfsense 2.02 unstable ipsec vpn.Tunnels will come up upon restarting racconSonicOS Enhanced 5.8.1.2 L2TP VPN Authentication FailedHow can I connect to a Cisco ASA5540 from Windows Server 2012 over IPSEC?Can't establish site to site vpn connection between Cisco 3900 and strongSwan clientSite to Site IPSec between pfSense and Cisco ASAHow to configure strongswan peer-to-peer vpn tunnel using public IP as encryption domain?






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








1















I'm trying to connect to a Cisco ASA 5520. I have been provided credentials :



Phase1
VPN IP address (Public IP) | XXX.XXX.XXX.XXX
Authentication Method | Pre-Shared Secret
Encryption Schema | IKE
Perfect Forward Secrecy- IKE | DH Group-2
Encryption Algorithm | 3DES
Hashing Algorithm | SHA-1
Renegotiate IKE SA every | 86400 Sec

Phase2
IPSec | ESP
Perfect Forward Secrecy-IPSEC | NO PFS
Encryption Algorithm IPSec | 3DES
Hashing Algorithm IPSec | SHA-1
Renegotiate IPSec SA every | 3600 Sec  
Private Network | 192.168.XXX.XXX/32


On my side, I compiled and installed Libreswan (3.27) on a DigitalOcean droplet, with the public IP : YYY.YYY.YYY.YYY and a private IP: 10.YYY.YYY.YYY/32. I tried to implement the IPSec VPN with this config:



conn the_vpn
ike=3des-sha1;modp1024,aes128-sha1;modp1024
auto=start
authby=secret
keyexchange=ike
phase2=esp
phase2alg=3des-sha1
left=XXX.XXX.XXX.XXX
leftsubnet=192.168.XXX.XXX/32
right=YYY.YYY.YYY.YYY
rightsubnet=10.YYY.YYY.YYY/32
ikelifetime=3600
type=tunnel
ikev2=never


And I did allow udp on port 500 and 4500 in my server (Ubuntu 16.04). I also wrote down the secrekey in /etc/ipsec.secrets. But through the logs; it seems that the handshake is initialized by the CISCO, but my side has this error:



packet from XXX.XXX.XXX.XXX:500 : initial Main Mode message received on YYY.YYY.YYY.YYY:500 but no connection has been authorized with policy PSK+IKEV1_ALLOW



My question are these:



1) does Libreswan still allow IKEV1 with shared PSK and DH 2 group or it has been deprecated and removed ?



2) does my configurations reflect the other side ? Because, as usual, It's me who has to conform to their setup, they can't change anything.



Thank you.










share|improve this question









New contributor




iMitwe is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.


























    1















    I'm trying to connect to a Cisco ASA 5520. I have been provided credentials :



    Phase1
    VPN IP address (Public IP) | XXX.XXX.XXX.XXX
    Authentication Method | Pre-Shared Secret
    Encryption Schema | IKE
    Perfect Forward Secrecy- IKE | DH Group-2
    Encryption Algorithm | 3DES
    Hashing Algorithm | SHA-1
    Renegotiate IKE SA every | 86400 Sec

    Phase2
    IPSec | ESP
    Perfect Forward Secrecy-IPSEC | NO PFS
    Encryption Algorithm IPSec | 3DES
    Hashing Algorithm IPSec | SHA-1
    Renegotiate IPSec SA every | 3600 Sec  
    Private Network | 192.168.XXX.XXX/32


    On my side, I compiled and installed Libreswan (3.27) on a DigitalOcean droplet, with the public IP : YYY.YYY.YYY.YYY and a private IP: 10.YYY.YYY.YYY/32. I tried to implement the IPSec VPN with this config:



    conn the_vpn
    ike=3des-sha1;modp1024,aes128-sha1;modp1024
    auto=start
    authby=secret
    keyexchange=ike
    phase2=esp
    phase2alg=3des-sha1
    left=XXX.XXX.XXX.XXX
    leftsubnet=192.168.XXX.XXX/32
    right=YYY.YYY.YYY.YYY
    rightsubnet=10.YYY.YYY.YYY/32
    ikelifetime=3600
    type=tunnel
    ikev2=never


    And I did allow udp on port 500 and 4500 in my server (Ubuntu 16.04). I also wrote down the secrekey in /etc/ipsec.secrets. But through the logs; it seems that the handshake is initialized by the CISCO, but my side has this error:



    packet from XXX.XXX.XXX.XXX:500 : initial Main Mode message received on YYY.YYY.YYY.YYY:500 but no connection has been authorized with policy PSK+IKEV1_ALLOW



    My question are these:



    1) does Libreswan still allow IKEV1 with shared PSK and DH 2 group or it has been deprecated and removed ?



    2) does my configurations reflect the other side ? Because, as usual, It's me who has to conform to their setup, they can't change anything.



    Thank you.










    share|improve this question









    New contributor




    iMitwe is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
    Check out our Code of Conduct.






















      1












      1








      1


      1






      I'm trying to connect to a Cisco ASA 5520. I have been provided credentials :



      Phase1
      VPN IP address (Public IP) | XXX.XXX.XXX.XXX
      Authentication Method | Pre-Shared Secret
      Encryption Schema | IKE
      Perfect Forward Secrecy- IKE | DH Group-2
      Encryption Algorithm | 3DES
      Hashing Algorithm | SHA-1
      Renegotiate IKE SA every | 86400 Sec

      Phase2
      IPSec | ESP
      Perfect Forward Secrecy-IPSEC | NO PFS
      Encryption Algorithm IPSec | 3DES
      Hashing Algorithm IPSec | SHA-1
      Renegotiate IPSec SA every | 3600 Sec  
      Private Network | 192.168.XXX.XXX/32


      On my side, I compiled and installed Libreswan (3.27) on a DigitalOcean droplet, with the public IP : YYY.YYY.YYY.YYY and a private IP: 10.YYY.YYY.YYY/32. I tried to implement the IPSec VPN with this config:



      conn the_vpn
      ike=3des-sha1;modp1024,aes128-sha1;modp1024
      auto=start
      authby=secret
      keyexchange=ike
      phase2=esp
      phase2alg=3des-sha1
      left=XXX.XXX.XXX.XXX
      leftsubnet=192.168.XXX.XXX/32
      right=YYY.YYY.YYY.YYY
      rightsubnet=10.YYY.YYY.YYY/32
      ikelifetime=3600
      type=tunnel
      ikev2=never


      And I did allow udp on port 500 and 4500 in my server (Ubuntu 16.04). I also wrote down the secrekey in /etc/ipsec.secrets. But through the logs; it seems that the handshake is initialized by the CISCO, but my side has this error:



      packet from XXX.XXX.XXX.XXX:500 : initial Main Mode message received on YYY.YYY.YYY.YYY:500 but no connection has been authorized with policy PSK+IKEV1_ALLOW



      My question are these:



      1) does Libreswan still allow IKEV1 with shared PSK and DH 2 group or it has been deprecated and removed ?



      2) does my configurations reflect the other side ? Because, as usual, It's me who has to conform to their setup, they can't change anything.



      Thank you.










      share|improve this question









      New contributor




      iMitwe is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.












      I'm trying to connect to a Cisco ASA 5520. I have been provided credentials :



      Phase1
      VPN IP address (Public IP) | XXX.XXX.XXX.XXX
      Authentication Method | Pre-Shared Secret
      Encryption Schema | IKE
      Perfect Forward Secrecy- IKE | DH Group-2
      Encryption Algorithm | 3DES
      Hashing Algorithm | SHA-1
      Renegotiate IKE SA every | 86400 Sec

      Phase2
      IPSec | ESP
      Perfect Forward Secrecy-IPSEC | NO PFS
      Encryption Algorithm IPSec | 3DES
      Hashing Algorithm IPSec | SHA-1
      Renegotiate IPSec SA every | 3600 Sec  
      Private Network | 192.168.XXX.XXX/32


      On my side, I compiled and installed Libreswan (3.27) on a DigitalOcean droplet, with the public IP : YYY.YYY.YYY.YYY and a private IP: 10.YYY.YYY.YYY/32. I tried to implement the IPSec VPN with this config:



      conn the_vpn
      ike=3des-sha1;modp1024,aes128-sha1;modp1024
      auto=start
      authby=secret
      keyexchange=ike
      phase2=esp
      phase2alg=3des-sha1
      left=XXX.XXX.XXX.XXX
      leftsubnet=192.168.XXX.XXX/32
      right=YYY.YYY.YYY.YYY
      rightsubnet=10.YYY.YYY.YYY/32
      ikelifetime=3600
      type=tunnel
      ikev2=never


      And I did allow udp on port 500 and 4500 in my server (Ubuntu 16.04). I also wrote down the secrekey in /etc/ipsec.secrets. But through the logs; it seems that the handshake is initialized by the CISCO, but my side has this error:



      packet from XXX.XXX.XXX.XXX:500 : initial Main Mode message received on YYY.YYY.YYY.YYY:500 but no connection has been authorized with policy PSK+IKEV1_ALLOW



      My question are these:



      1) does Libreswan still allow IKEV1 with shared PSK and DH 2 group or it has been deprecated and removed ?



      2) does my configurations reflect the other side ? Because, as usual, It's me who has to conform to their setup, they can't change anything.



      Thank you.







      vpn ipsec libreswan






      share|improve this question









      New contributor




      iMitwe is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.











      share|improve this question









      New contributor




      iMitwe is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.









      share|improve this question




      share|improve this question








      edited Apr 5 at 7:55







      iMitwe













      New contributor




      iMitwe is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.









      asked Apr 5 at 7:30









      iMitweiMitwe

      1064




      1064




      New contributor




      iMitwe is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.





      New contributor





      iMitwe is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.






      iMitwe is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.




















          0






          active

          oldest

          votes












          Your Answer








          StackExchange.ready(function()
          var channelOptions =
          tags: "".split(" "),
          id: "2"
          ;
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function()
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled)
          StackExchange.using("snippets", function()
          createEditor();
          );

          else
          createEditor();

          );

          function createEditor()
          StackExchange.prepareEditor(
          heartbeatType: 'answer',
          autoActivateHeartbeat: false,
          convertImagesToLinks: true,
          noModals: true,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: 10,
          bindNavPrevention: true,
          postfix: "",
          imageUploader:
          brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
          contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
          allowUrls: true
          ,
          onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          );



          );






          iMitwe is a new contributor. Be nice, and check out our Code of Conduct.









          draft saved

          draft discarded


















          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f961635%2fissue-ikev1-for-libreswan-3-27-no-connection-has-been-authorized-with-policy-p%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown

























          0






          active

          oldest

          votes








          0






          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes








          iMitwe is a new contributor. Be nice, and check out our Code of Conduct.









          draft saved

          draft discarded


















          iMitwe is a new contributor. Be nice, and check out our Code of Conduct.












          iMitwe is a new contributor. Be nice, and check out our Code of Conduct.











          iMitwe is a new contributor. Be nice, and check out our Code of Conduct.














          Thanks for contributing an answer to Server Fault!


          • Please be sure to answer the question. Provide details and share your research!

          But avoid


          • Asking for help, clarification, or responding to other answers.

          • Making statements based on opinion; back them up with references or personal experience.

          To learn more, see our tips on writing great answers.




          draft saved


          draft discarded














          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f961635%2fissue-ikev1-for-libreswan-3-27-no-connection-has-been-authorized-with-policy-p%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown





















































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown

































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown







          Popular posts from this blog

          Wikipedia:Vital articles Мазмуну Biography - Өмүр баян Philosophy and psychology - Философия жана психология Religion - Дин Social sciences - Коомдук илимдер Language and literature - Тил жана адабият Science - Илим Technology - Технология Arts and recreation - Искусство жана эс алуу History and geography - Тарых жана география Навигация менюсу

          Bruxelas-Capital Índice Historia | Composición | Situación lingüística | Clima | Cidades irmandadas | Notas | Véxase tamén | Menú de navegacióneO uso das linguas en Bruxelas e a situación do neerlandés"Rexión de Bruxelas Capital"o orixinalSitio da rexiónPáxina de Bruselas no sitio da Oficina de Promoción Turística de Valonia e BruxelasMapa Interactivo da Rexión de Bruxelas-CapitaleeWorldCat332144929079854441105155190212ID28008674080552-90000 0001 0666 3698n94104302ID540940339365017018237

          What should I write in an apology letter, since I have decided not to join a company after accepting an offer letterShould I keep looking after accepting a job offer?What should I do when I've been verbally told I would get an offer letter, but still haven't gotten one after 4 weeks?Do I accept an offer from a company that I am not likely to join?New job hasn't confirmed starting date and I want to give current employer as much notice as possibleHow should I address my manager in my resignation letter?HR delayed background verification, now jobless as resignedNo email communication after accepting a formal written offer. How should I phrase the call?What should I do if after receiving a verbal offer letter I am informed that my written job offer is put on hold due to some internal issues?Should I inform the current employer that I am about to resign within 1-2 weeks since I have signed the offer letter and waiting for visa?What company will do, if I send their offer letter to another company