Re: IPSec trouble - Phase 2 negotiations with Cisco PIX and NAT-T

2005-05-06 Thread Erik Carlseen
Ok, I think I solved my own problem and there appears to be a bug in isakmpd. Apparently isakmpd was having trouble matching the SAs when key lifes were specified by both time (seconds) and traffic quantity (kilobytes). The relevant log information is included post signature. The configuration info

IPSec trouble - Phase 2 negotiations with Cisco PIX and NAT-T

2005-05-05 Thread Erik Carlseen
I've been banging my head against this problem for a few days and was wondering (hoping) someone around here has an answer. I'm trying to set up a VPN with OpenBSD on my end, and a Cisco PIX on the other. The PIX is hiding behind a NAT firewall (God only knows why - I asked nicely and I'm not i