Re: isakmpd, greenbow vpn client and NO PROPOSAL CHOSEN

2005-10-19 Thread Kim Nielsen
Hans-Joerg Hoexer wrote: [AES-SHA-GRP2] ENCRYPTION_ALGORITHM= AES_CBC HASH_ALGORITHM= SHA AUTHENTICATION_METHOD= PRE_SHARED GROUP_DESCRIPTION= MODP_1024 Life= LIFE_1_DAY LIFE_1_DAY is not defined Hi :) I added [LIFE_1_DAY] LIFE_TYPE= SECONDS LIFE_DURATIO

Re: isakmpd, greenbow vpn client and NO PROPOSAL CHOSEN

2005-10-19 Thread Hans-Joerg Hoexer
Hi, On Wed, Oct 19, 2005 at 01:34:45PM +0200, Kim Nielsen wrote: > [greenbow-main-mode] > DOI=IPSEC > EXCHANGE_TYPE= ID_PROT > Transforms= AES-SHA-GRP2 > > [greenbow-quick-mode] > DOI=IPSEC > EXCHANGE_TYPE= QUICK_MODE > Suites= QM-ESP-AES-SHA-PFS-GR2-SUITE >

Re: isakmpd, greenbow vpn client and NO PROPOSAL CHOSEN

2005-10-19 Thread Kim Nielsen
Rogier Krieger wrote: Last time I dealt with the NO_PROPOSAL_CHOSEN issue, it was due to an error in my keynote(4) policy. After re-creating it from scratch using the example files, things worked like a charm for me. Hope this helps, I wish that was it .. I even tried to wget http://www.a

Re: isakmpd, greenbow vpn client and NO PROPOSAL CHOSEN

2005-10-19 Thread Kim Nielsen
Hans-Joerg Hoexer wrote: On Wed, Oct 19, 2005 at 01:34:45PM +0200, Kim Nielsen wrote: [greenbow-quick-mode] DOI=IPSEC EXCHANGE_TYPE= QUICK_MODE Suites= QM-ESP-AES-SHA-PFS-GR2-SUITE it's GRP2, not GR2 [AES-SHA-GRP2] ENCRYPTION_ALGORITHM= AES_CBC HASH_ALGORITHM=

Re: isakmpd, greenbow vpn client and NO PROPOSAL CHOSEN

2005-10-19 Thread Hans-Joerg Hoexer
On Wed, Oct 19, 2005 at 01:34:45PM +0200, Kim Nielsen wrote: > [greenbow-quick-mode] > DOI=IPSEC > EXCHANGE_TYPE= QUICK_MODE > Suites= QM-ESP-AES-SHA-PFS-GR2-SUITE it's GRP2, not GR2 > > [AES-SHA-GRP2] > ENCRYPTION_ALGORITHM= AES_CBC > HASH_ALGORITHM= SHA > AUTHENT