Advertisement

08.01.2007 at 11:35AM PDT, ID: 22735478
[x]
Attachment Details

FVG318 No matching SPD policy for the selectors received in IKE phase-II message

Asked by techsolutionusa in IPSec Security Protocol, Virtual Private Networking (VPN), Internet Protocols

Tags: matching, spd, policy, selectors, ike

I have a FVG318 netgear and trying to connect using the prosafe client but im getting the following from the VPN Router Log:

 Init Cookie: 0x62a0c5fc2a589b53 & Resp Cookie: 0x9c37221c2157c0cf INFO :: Started phase-I negotiation
 Init Cookie: 0x62a0c5fc2a589b53 & Resp Cookie: 0x9c37221c2157c0cf INFO :: received NOTIFY PAYLOAD of notify type INITIAL_CONTACT
 Init Cookie: 0x62a0c5fc2a589b53 & Resp Cookie: 0x9c37221c2157c0cf INFO :: IKE phase-I started
 Init Cookie: 0x62a0c5fc2a589b53 & Resp Cookie: 0x9c37221c2157c0cf INFO :: Initiator SPD selectors received: IPADDR, 192.168.1.101, proto 0, port 0
 Init Cookie: 0x62a0c5fc2a589b53 & Resp Cookie: 0x9c37221c2157c0cf INFO :: Responder SPD selectors received: IP SUBNET, 192.168.0.0, mask 32 proto 0, port 0
 Init Cookie: 0x62a0c5fc2a589b53 & Resp Cookie: 0x9c37221c2157c0cf INFO :: No matching SPD policy for the selectors received in IKE phase-II message
 Init Cookie: 0x62a0c5fc2a589b53 & Resp Cookie: 0x9c37221c2157c0cf INFO :: IKE phase-II with message ID f0bc50e4 failed

and the Log file of the prosafe is:

 8-01: 13:45:16.437 No Interfaces detected.
 8-01: 13:45:17.750 Filter table loaded.
 8-01: 13:45:40.265 Interface added: 192.168.1.101/255.255.255.0 on LAN "Intel(R) PRO/Wireless 2200BG Network Connection".
 8-01: 14:27:02.578 Filter table loaded.
 8-01: 14:27:33.593 Filter table loaded.
 8-01: 14:27:49.187
 8-01: 14:27:49.328 My Connections\New Connection - Initiating IKE Phase 1 (IP ADDR=xx.xx.xxx.xx) (staict address of the site)
 8-01: 14:27:49.468 My Connections\New Connection - SENDING>>>> ISAKMP OAK AG (SA, KE, NON, ID, VID 5x)
 8-01: 14:27:50.421 My Connections\New Connection - RECEIVED<<< ISAKMP OAK AG (SA, KE, NON, ID, HASH, VID, NAT-D 2x, VID 2x)
 8-01: 14:27:50.421 My Connections\New Connection - Peer is NAT-T draft-02 capable
 8-01: 14:27:50.421 My Connections\New Connection - NAT is detected for Client
 8-01: 14:27:50.421 My Connections\New Connection - Floating to IKE non-500 port
 8-01: 14:27:50.671 My Connections\New Connection - SENDING>>>> ISAKMP OAK AG *(HASH, NAT-D 2x, NOTIFY:STATUS_INITIAL_CONTACT)
 8-01: 14:27:50.671 My Connections\New Connection - Established IKE SA
 8-01: 14:27:50.671    MY COOKIE 62 a0 c5 fc 2a 58 9b 53
 8-01: 14:27:50.671    HIS COOKIE 9c 37 22 1c 21 57 c0 cf
 8-01: 14:27:50.703 My Connections\New Connection - Initiating IKE Phase 2 with Client IDs (message id: F0BC50E4)
 8-01: 14:27:50.703   Initiator = IP ADDR=192.168.1.101, prot = 0 port = 0
 8-01: 14:27:50.703   Responder = IP SUBNET/MASK=192.168.0.0/255.255.255.255, prot = 0 port = 0
 8-01: 14:27:50.703 My Connections\New Connection - SENDING>>>> ISAKMP OAK QM *(HASH, SA, NON, ID 2x)
 8-01: 14:28:36.031 My Connections\New Connection - QM re-keying timed out (message id: F0BC50E4). Retry count: 1
 8-01: 14:28:36.031 My Connections\New Connection - SENDING>>>> ISAKMP OAK QM *(Retransmission)
 8-01: 14:29:21.046 My Connections\New Connection - Exceeded 1 re-keying attempts (message id: F0BC50E4)
 8-01: 14:29:21.046 My Connections\New Connection - Disconnecting IKE SA negotiation
 8-01: 14:29:21.046 My Connections\New Connection - Deleting IKE SA (IP ADDR=xx.xx.xxx.xx)
 8-01: 14:29:21.046    MY COOKIE 62 a0 c5 fc 2a 58 9b 53
 8-01: 14:29:21.046    HIS COOKIE 9c 37 22 1c 21 57 c0 cf
 8-01: 14:29:21.046 My Connections\New Connection - SENDING>>>> ISAKMP OAK INFO *(HASH, DEL)

its looks like it failes in phase2

I have sent the client software to the following
New Connection:
Secure
Remote Party Identity and addresesing
IP Subnet
192.168.0.0
255.255.255.0
protocal all
connect using Secure Gateway Tunnel
Domain name. fvg_local.com
and Gateway ip address (my static IP)Start Free Trial
[+][-]08.01.2007 at 11:50AM PDT, ID: 19611710

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: IPSec Security Protocol, Virtual Private Networking (VPN), Internet Protocols
Tags: matching, spd, policy, selectors, ike
Sign Up Now!
Solution Provided By: RobWill
Participating Experts: 2
Solution Grade: A
 
 
[+][-]08.01.2007 at 12:25PM PDT, ID: 19612029

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]08.01.2007 at 12:29PM PDT, ID: 19612057

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08.02.2007 at 05:12AM PDT, ID: 19616092

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08.02.2007 at 05:59AM PDT, ID: 19616417

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]08.02.2007 at 06:13AM PDT, ID: 19616507

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32