troubleshooting Question

Connection fails VPN

Avatar of whatisthesolution
whatisthesolution asked on
Windows NetworkingNetworking Hardware-OtherNetwork Security
39 Comments1 Solution10318 ViewsLast Modified:
Treing to setup a romaing user client to test with D-link DS-601 VPN software agianst their SMB/enterprise firewall DFL-700 I recieve an error saying: "Invalid payload type"

Log from ds-601 as follows:
23-02-2007 00:46:14  Found adapter: SiS NIC SISNIC (Microsoft's Packet Scheduler)  with MTU 1500 bytes
23-02-2007 00:46:14  Found adapter: Broadcom 802.11g Netværkskort (Microsoft's Packet Scheduler)  with MTU 1500 bytes
23-02-2007 00:46:14  Found adapter: NdisWan Adapter (Microsoft's Packet Scheduler)  with MTU 1400 bytes
23-02-2007 00:46:14  Installed as a full license.
23-02-2007 00:46:45  Protecting RAS adapter - 0
23-02-2007 01:01:38  Protecting RAS adapter - 0
23-02-2007 01:01:41  IPSDIALCHAN::start building connection
23-02-2007 01:01:41  NCPIKE-phase1:name(XX VPN) - outgoing connect request - main mode.
23-02-2007 01:01:41  XMIT_MSG1_MAIN - xx VPN
23-02-2007 01:01:41  Extended Firewall: adapter SiS NIC SISNIC (Microsoft's Packet Scheduler)  is outside the friendly net
23-02-2007 01:01:41  RECV_MSG2_MAIN - xx VPN
23-02-2007 01:01:41  IPSDIAL->FINAL_TUNNEL_ENDPOINT:192.168.001.001
23-02-2007 01:01:41  IKE phase I: Setting LifeTime to 28800 seconds
23-02-2007 01:01:41  xx VPN ->Support for NAT-T version - 3
23-02-2007 01:01:41  XMIT_MSG3_MAIN - xx VPN
23-02-2007 01:01:41  RECV_MSG4_MAIN - xx VPN
23-02-2007 01:01:42  XMIT_MSG5_MAIN - xx VPN
23-02-2007 01:01:42  NOTIFY : xx VPN : RECEIVED : INVALID_PAYLOAD_TYPE
23-02-2007 01:02:20  NCPIKE-phase2:name(xx VPN) - error - cleared by phase1
23-02-2007 01:02:20  IPSDIAL  - disconnected from xx VPN on channel 1.
23-02-2007 01:02:27  IPSDIALCHAN::start building connection
23-02-2007 01:02:27  NCPIKE-phase1:name(xx VPN) - outgoing connect request - main mode.
23-02-2007 01:02:27  XMIT_MSG1_MAIN - xx VPN
23-02-2007 01:02:27  RECV_MSG2_MAIN - xx VPN
23-02-2007 01:02:27  IKE phase I: Setting LifeTime to 28800 seconds
23-02-2007 01:02:27  xx VPN ->Support for NAT-T version - 3
23-02-2007 01:02:27  XMIT_MSG3_MAIN - xx VPN
23-02-2007 01:02:27  IPSDIAL->FINAL_TUNNEL_ENDPOINT:192.168.001.001
23-02-2007 01:02:27  RECV_MSG4_MAIN - xx VPN
23-02-2007 01:02:27  XMIT_MSG5_MAIN - xx VPN
23-02-2007 01:02:27  NOTIFY : xx VPN : RECEIVED : INVALID_PAYLOAD_TYPE
23-02-2007 01:03:06  NCPIKE-phase2:name(xx VPN) - error - cleared by phase1
23-02-2007 01:03:06  IPSDIAL  - disconnected from xx VPN on channel 1.
23-02-2007 01:04:02  Protecting RAS adapter - 0
23-02-2007 01:04:02  Protecting RAS adapter - 0
23-02-2007 01:04:02  Protecting RAS adapter - 2
23-02-2007 01:08:02  Protecting RAS adapter - 0
23-02-2007 01:08:02  Protecting RAS adapter - 0
23-02-2007 01:08:02  Protecting RAS adapter - 2
23-02-2007 01:09:56  Protecting RAS adapter - 0
23-02-2007 01:09:56  Protecting RAS adapter - 0
23-02-2007 01:09:57  Protecting RAS adapter - 0
23-02-2007 01:09:57  Protecting RAS adapter - 0
23-02-2007 01:09:57  Protecting RAS adapter - 0
23-02-2007 01:09:57  Protecting RAS adapter - 0
23-02-2007 01:09:58  Protecting RAS adapter - 0
23-02-2007 01:12:13  EAPOL:send EAPOL_LOGOFF
23-02-2007 01:12:13  EAP:SiS NIC SISNIC (Microsoft's Packet Scheduler)  authentication failure ! - EAPOL - admin close
23-02-2007 01:12:18  IPSDIALCHAN::start building connection
23-02-2007 01:12:18  NCPIKE-phase1:name(xx VPN) - outgoing connect request - main mode.
23-02-2007 01:12:18  XMIT_MSG1_MAIN - xx VPN
23-02-2007 01:12:36  NCPIKE-phase1:name(xx VPN) - error - retry timeout - max retries
23-02-2007 01:12:36  NCPIKE-phase2:name(xx VPN) - error - cleared by phase1
23-02-2007 01:12:36  IPSDIAL  - disconnected from xx VPN on channel 1.
23-02-2007 01:12:46  IPSDIALCHAN::start building connection
23-02-2007 01:12:46  NCPIKE-phase1:name(xx VPN) - outgoing connect request - main mode.
23-02-2007 01:12:46  XMIT_MSG1_MAIN - xx VPN
23-02-2007 01:12:56  IPSDIAL  - disconnecting from xx VPN on channel 1.
23-02-2007 01:12:56  NCPIKE-phase2:name(xx VPN) - error - cleared by phase1
23-02-2007 01:12:56  IPSDIAL  - disconnected from xx VPN on channel 1.
23-02-2007 01:13:02  IPSDIALCHAN::start building connection
23-02-2007 01:13:02  NCPIKE-phase1:name(xx VPN) - outgoing connect request - main mode.
23-02-2007 01:13:02  XMIT_MSG1_MAIN - xx VPN
23-02-2007 01:13:19  NCPIKE-phase1:name(xx VPN) - error - retry timeout - max retries
23-02-2007 01:13:19  NCPIKE-phase2:name(xx VPN) - error - cleared by phase1
23-02-2007 01:13:19  IPSDIAL  - disconnected from xx VPN on channel 1.
23-02-2007 01:14:12  Protecting RAS adapter - 0
23-02-2007 01:14:25  Found adapter: SiS NIC SISNIC (Microsoft's Packet Scheduler)  with MTU 1500 bytes
23-02-2007 01:14:36  IPSDIALCHAN::start building connection
23-02-2007 01:14:36  NCPIKE-phase1:name(xx VPN) - outgoing connect request - main mode.
23-02-2007 01:14:36  XMIT_MSG1_MAIN - xx VPN
23-02-2007 01:14:36  Extended Firewall: adapter SiS NIC SISNIC (Microsoft's Packet Scheduler)  is outside the friendly net
23-02-2007 01:14:36  RECV_MSG2_MAIN - xx VPN
23-02-2007 01:14:36  IKE phase I: Setting LifeTime to 28800 seconds
23-02-2007 01:14:36  x VPN ->Support for NAT-T version - 3
23-02-2007 01:14:36  XMIT_MSG3_MAIN - xx VPN
23-02-2007 01:14:36  IPSDIAL->FINAL_TUNNEL_ENDPOINT:192.168.001.001
23-02-2007 01:14:36  RECV_MSG4_MAIN - xx VPN
23-02-2007 01:14:36  XMIT_MSG5_MAIN - xx VPN
23-02-2007 01:14:36  NOTIFY : xx VPN : RECEIVED : INVALID_PAYLOAD_TYPE
23-02-2007 01:15:16  NCPIKE-phase2:name(xx VPN) - error - cleared

Log from DFL-700 as follows:

2007-02-23 00:14:39] <6>EFW: IPSEC: prio=1 Phase-1 [responder] between ipv4(any:0,[0..3]=192.168.1.1) and ipv4(any:0,[0..3]=192.168.1.3) failed; Invalid payload type

2007-02-23 00:14:38] <5>EFW: CONN: rule=IPsecBeforeRules conn=open connipproto=UDP connrecvif=LAN connsrcip=192.168.1.3 connsrcport=500 conndestif=core conndestip=192.168.1.1 conndestport=500

        [2007-02-23 00:14:38] <5>EFW: CONN: rule=IPsecBeforeRules conn=open connipproto=UDP connrecvif=LAN connsrcip=192.168.1.3 connsrcport=500 conndestif=core conndestip=XXX.XXX.XX.XXX conndestport=500

Any ideas guys?

Thanks
whatisthesolution
Join the community to see this answer!
Join our exclusive community to see this answer & millions of others.
Unlock 1 Answer and 39 Comments.
Join the Community
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 39 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros