Advertisement

07.10.2007 at 06:53PM PDT, ID: 22687740
[x]
Attachment Details

VPN to SonicWall Pro 4100 to Windows network from OS 10.4.?

Asked by Indy_IT_Admin in Apple Networking

Tags: handle, vpn, phase2, sonicwall

First off, please pardon my ignorance on the Mac side of the house.  I am a PC/Windows Server admin through and through, however with the introduction of the Mactel boxes my interest peaks.

The issue I am having is:
When I connect using the built in VPN connection to my SonicWall ALL of my network connections go dead (no internet, no network browsing (IP or DNS), nothing.  I cannot ping servers on the inside of the network or outside.  I know the shared key, usernames, and IP are all correct.

I also tried with VPN Tracker software and it asks me for my Pre-Shared Key, requires the correct one or it thows an error, and then fails to connect with the following log.  I would rather use the built in VPN software but at this point I would do whatever to get the connection.  

The end result I need is for my media and design teams to be able to access their network files (saved on a windows server) on their machines at home.  BTW using the same connection information on the SonicWall Global VPN Client (PC side) works like  charm.

Resolving connection "Untitled 1":
Router:          192.168.1.1 (00:18:4d:92:24:d2)
Local Endpoint:  192.168.1.5
Remote Endpoint: 207.67.113.158
Local Network:   none
Remote Network:  0.0.0.0/0
Starting IKE daemon...
2007-07-10 21:47:50: INFO: main.c:177:main(): @(#)package version VPN-Tracker-4.9.3(1311)
2007-07-10 21:47:50: INFO: main.c:179:main(): @(#)internal version 20001216 sakane@kame.net
2007-07-10 21:47:50: INFO: main.c:180:main(): @(#)This product linked OpenSSL 0.9.7l 28 Sep 2006 (http://www.openssl.org/)
2007-07-10 21:47:50: INFO: licensing: Unlicensed demo valid for 25 days.
2007-07-10 21:47:51: INFO: isakmp.c:2083:isakmp_post_acquire(): IPsec-SA request for 207.67.113.158 queued due to no phase1 found. Starting phase1...
2007-07-10 21:47:51: INFO: isakmp.c:1038:isakmp_ph1begin_i(): initiate new phase 1 negotiation: 192.168.1.5[500]<=>207.67.113.158[500]
2007-07-10 21:47:51: INFO: isakmp.c:1043:isakmp_ph1begin_i(): begin Aggressive mode.
2007-07-10 21:47:51: NOTIFY: oakley.c:2380:oakley_skeyid(): getting pre-shared key by peer's address instead of identifier.
2007-07-10 21:47:55: INFO: isakmp_agg.c:536:agg_i2recv(): detected NAT, switching to port 4500 for 207.67.113.158[500]
2007-07-10 21:47:55: INFO: isakmp.c:2884:log_ph1established(): ISAKMP-SA established 192.168.1.5[4500]-207.67.113.158[4500] spi:713648687bb04924:bf1c90207b702ca7
2007-07-10 21:47:55: INFO: isakmp.c:1207:isakmp_ph2begin_i(): initiate new phase 2 negotiation: 192.168.1.5[0]<=>207.67.113.158[0] (sequence: 1050329672) (sainfo: 192.168.1.5/32 0.0.0.0/0)
2007-07-10 21:47:55: ERROR: isakmp_inf.c:947:isakmp_info_recv_n(): unknown notify message: NO-PROPOSAL-CHOSEN, no phase2 handle found.
2007-07-10 21:48:10: ERROR: pfkey.c:795:pfkey_timeover(): 207.67.113.158 (192.168.1.5/32 0.0.0.0/0) give up to get IPsec-SA due to time up to wait.
2007-07-10 21:48:12: INFO: isakmp.c:1207:isakmp_ph2begin_i(): initiate new phase 2 negotiation: 192.168.1.5[0]<=>207.67.113.158[0] (sequence: 5) (sainfo: 192.168.1.5/32 0.0.0.0/0)
2007-07-10 21:48:12: ERROR: isakmp_inf.c:947:isakmp_info_recv_n(): unknown notify message: NO-PROPOSAL-CHOSEN, no phase2 handle found.
2007-07-10 21:48:27: ERROR: pfkey.c:795:pfkey_timeover(): 207.67.113.158 (192.168.1.5/32 0.0.0.0/0) give up to get IPsec-SA due to time up to wait.Start Free Trial
[+][-]07.10.2007 at 07:17PM PDT, ID: 19459405

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.13.2007 at 12:06PM PDT, ID: 19483577

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zone: Apple Networking
Tags: handle, vpn, phase2, sonicwall
Sign Up Now!
Solution Provided By: abenage
Participating Experts: 1
Solution Grade: B
 
 
 
Loading Advertisement...
20080716-EE-VQP-32