troubleshooting Question

Connection fails VPN

Avatar of whatisthesolution
whatisthesolution asked on
Networking Hardware-OtherWindows NetworkingNetwork Security
39 Comments1 Solution10318 ViewsLast Modified:
Treing to setup a romaing user client to test with D-link DS-601 VPN software agianst their SMB/enterprise firewall DFL-700 I recieve an error saying: "Invalid payload type"

Log from ds-601 as follows:
23-02-2007 00:46:14  Found adapter: SiS NIC SISNIC (Microsoft's Packet Scheduler)  with MTU 1500 bytes
23-02-2007 00:46:14  Found adapter: Broadcom 802.11g Netværkskort (Microsoft's Packet Scheduler)  with MTU 1500 bytes
23-02-2007 00:46:14  Found adapter: NdisWan Adapter (Microsoft's Packet Scheduler)  with MTU 1400 bytes
23-02-2007 00:46:14  Installed as a full license.
23-02-2007 00:46:45  Protecting RAS adapter - 0
23-02-2007 01:01:38  Protecting RAS adapter - 0
23-02-2007 01:01:41  IPSDIALCHAN::start building connection
23-02-2007 01:01:41  NCPIKE-phase1:name(XX VPN) - outgoing connect request - main mode.
23-02-2007 01:01:41  XMIT_MSG1_MAIN - xx VPN
23-02-2007 01:01:41  Extended Firewall: adapter SiS NIC SISNIC (Microsoft's Packet Scheduler)  is outside the friendly net
23-02-2007 01:01:41  RECV_MSG2_MAIN - xx VPN
23-02-2007 01:01:41  IPSDIAL->FINAL_TUNNEL_ENDPOINT:192.168.001.001
23-02-2007 01:01:41  IKE phase I: Setting LifeTime to 28800 seconds
23-02-2007 01:01:41  xx VPN ->Support for NAT-T version - 3
23-02-2007 01:01:41  XMIT_MSG3_MAIN - xx VPN
23-02-2007 01:01:41  RECV_MSG4_MAIN - xx VPN
23-02-2007 01:01:42  XMIT_MSG5_MAIN - xx VPN
23-02-2007 01:01:42  NOTIFY : xx VPN : RECEIVED : INVALID_PAYLOAD_TYPE
23-02-2007 01:02:20  NCPIKE-phase2:name(xx VPN) - error - cleared by phase1
23-02-2007 01:02:20  IPSDIAL  - disconnected from xx VPN on channel 1.
23-02-2007 01:02:27  IPSDIALCHAN::start building connection
23-02-2007 01:02:27  NCPIKE-phase1:name(xx VPN) - outgoing connect request - main mode.
23-02-2007 01:02:27  XMIT_MSG1_MAIN - xx VPN
23-02-2007 01:02:27  RECV_MSG2_MAIN - xx VPN
23-02-2007 01:02:27  IKE phase I: Setting LifeTime to 28800 seconds
23-02-2007 01:02:27  xx VPN ->Support for NAT-T version - 3
23-02-2007 01:02:27  XMIT_MSG3_MAIN - xx VPN
23-02-2007 01:02:27  IPSDIAL->FINAL_TUNNEL_ENDPOINT:192.168.001.001
23-02-2007 01:02:27  RECV_MSG4_MAIN - xx VPN
23-02-2007 01:02:27  XMIT_MSG5_MAIN - xx VPN
23-02-2007 01:02:27  NOTIFY : xx VPN : RECEIVED : INVALID_PAYLOAD_TYPE
23-02-2007 01:03:06  NCPIKE-phase2:name(xx VPN) - error - cleared by phase1
23-02-2007 01:03:06  IPSDIAL  - disconnected from xx VPN on channel 1.
23-02-2007 01:04:02  Protecting RAS adapter - 0
23-02-2007 01:04:02  Protecting RAS adapter - 0
23-02-2007 01:04:02  Protecting RAS adapter - 2
23-02-2007 01:08:02  Protecting RAS adapter - 0
23-02-2007 01:08:02  Protecting RAS adapter - 0
23-02-2007 01:08:02  Protecting RAS adapter - 2
23-02-2007 01:09:56  Protecting RAS adapter - 0
23-02-2007 01:09:56  Protecting RAS adapter - 0
23-02-2007 01:09:57  Protecting RAS adapter - 0
23-02-2007 01:09:57  Protecting RAS adapter - 0
23-02-2007 01:09:57  Protecting RAS adapter - 0
23-02-2007 01:09:57  Protecting RAS adapter - 0
23-02-2007 01:09:58  Protecting RAS adapter - 0
23-02-2007 01:12:13  EAPOL:send EAPOL_LOGOFF
23-02-2007 01:12:13  EAP:SiS NIC SISNIC (Microsoft's Packet Scheduler)  authentication failure ! - EAPOL - admin close
23-02-2007 01:12:18  IPSDIALCHAN::start building connection
23-02-2007 01:12:18  NCPIKE-phase1:name(xx VPN) - outgoing connect request - main mode.
23-02-2007 01:12:18  XMIT_MSG1_MAIN - xx VPN
23-02-2007 01:12:36  NCPIKE-phase1:name(xx VPN) - error - retry timeout - max retries
23-02-2007 01:12:36  NCPIKE-phase2:name(xx VPN) - error - cleared by phase1
23-02-2007 01:12:36  IPSDIAL  - disconnected from xx VPN on channel 1.
23-02-2007 01:12:46  IPSDIALCHAN::start building connection
23-02-2007 01:12:46  NCPIKE-phase1:name(xx VPN) - outgoing connect request - main mode.
23-02-2007 01:12:46  XMIT_MSG1_MAIN - xx VPN
23-02-2007 01:12:56  IPSDIAL  - disconnecting from xx VPN on channel 1.
23-02-2007 01:12:56  NCPIKE-phase2:name(xx VPN) - error - cleared by phase1
23-02-2007 01:12:56  IPSDIAL  - disconnected from xx VPN on channel 1.
23-02-2007 01:13:02  IPSDIALCHAN::start building connection
23-02-2007 01:13:02  NCPIKE-phase1:name(xx VPN) - outgoing connect request - main mode.
23-02-2007 01:13:02  XMIT_MSG1_MAIN - xx VPN
23-02-2007 01:13:19  NCPIKE-phase1:name(xx VPN) - error - retry timeout - max retries
23-02-2007 01:13:19  NCPIKE-phase2:name(xx VPN) - error - cleared by phase1
23-02-2007 01:13:19  IPSDIAL  - disconnected from xx VPN on channel 1.
23-02-2007 01:14:12  Protecting RAS adapter - 0
23-02-2007 01:14:25  Found adapter: SiS NIC SISNIC (Microsoft's Packet Scheduler)  with MTU 1500 bytes
23-02-2007 01:14:36  IPSDIALCHAN::start building connection
23-02-2007 01:14:36  NCPIKE-phase1:name(xx VPN) - outgoing connect request - main mode.
23-02-2007 01:14:36  XMIT_MSG1_MAIN - xx VPN
23-02-2007 01:14:36  Extended Firewall: adapter SiS NIC SISNIC (Microsoft's Packet Scheduler)  is outside the friendly net
23-02-2007 01:14:36  RECV_MSG2_MAIN - xx VPN
23-02-2007 01:14:36  IKE phase I: Setting LifeTime to 28800 seconds
23-02-2007 01:14:36  x VPN ->Support for NAT-T version - 3
23-02-2007 01:14:36  XMIT_MSG3_MAIN - xx VPN
23-02-2007 01:14:36  IPSDIAL->FINAL_TUNNEL_ENDPOINT:192.168.001.001
23-02-2007 01:14:36  RECV_MSG4_MAIN - xx VPN
23-02-2007 01:14:36  XMIT_MSG5_MAIN - xx VPN
23-02-2007 01:14:36  NOTIFY : xx VPN : RECEIVED : INVALID_PAYLOAD_TYPE
23-02-2007 01:15:16  NCPIKE-phase2:name(xx VPN) - error - cleared

Log from DFL-700 as follows:

2007-02-23 00:14:39] <6>EFW: IPSEC: prio=1 Phase-1 [responder] between ipv4(any:0,[0..3]=192.168.1.1) and ipv4(any:0,[0..3]=192.168.1.3) failed; Invalid payload type

2007-02-23 00:14:38] <5>EFW: CONN: rule=IPsecBeforeRules conn=open connipproto=UDP connrecvif=LAN connsrcip=192.168.1.3 connsrcport=500 conndestif=core conndestip=192.168.1.1 conndestport=500

        [2007-02-23 00:14:38] <5>EFW: CONN: rule=IPsecBeforeRules conn=open connipproto=UDP connrecvif=LAN connsrcip=192.168.1.3 connsrcport=500 conndestif=core conndestip=XXX.XXX.XX.XXX conndestport=500

Any ideas guys?

Thanks
whatisthesolution
ASKER CERTIFIED SOLUTION
hancke

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Log in to continue reading
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform for $9.99/mo
View membership options
Unlock 1 Answer and 39 Comments.
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
See how we're fighting big data
The Value of Experts Exchange in My Daily IT Life

Experts Exchange (EE) has become my company's go-to resource to get answers. I've used EE to make decisions, solve problems and even save customers. OutagesIO has been a challenging project and... Keep reading >>

Mike

Owner of Outages.IO
Phoenix, Arizona, United States
Member Since 2016
Join a full scale community that combines the best parts of other tools into one platform.
Unlock 1 Answer and 39 Comments.
View membership options
“All of life is about relationships, and EE has made a virtual community a real community. It lifts everyone's boat.”
William Peck

Member since 2004