Re: problem with IPSec between OpenBSD 5.5 and Cisco 2901

2014-06-18 Thread Sebastian Reitenbach
On Wednesday, June 18, 2014 15:27 CEST, Stuart Henderson wrote: > On 2014-06-18, Sebastian Reitenbach wrote: > > The only difference I see, but I'm unsure if this is OK or not, is that > > the OpenBSD box sends ENCAPSULATION_MODE = TUNNEL, and the > > Cisco box sends ENCAPSULATION_MODE = UDP_

Re: problem with IPSec between OpenBSD 5.5 and Cisco 2901

2014-06-18 Thread Stuart Henderson
On 2014-06-18, Sebastian Reitenbach wrote: > The only difference I see, but I'm unsure if this is OK or not, is that > the OpenBSD box sends ENCAPSULATION_MODE = TUNNEL, and the > Cisco box sends ENCAPSULATION_MODE = UDP_ENCAP_TUNNEL. > I'm not sure if that is expected, since the Cisco is behind a

Re: problem with IPSec between OpenBSD 5.5 and Cisco 2901

2014-06-18 Thread Sebastian Reitenbach
On Wednesday, June 18, 2014 08:49 CEST, Remi Locherer wrote: > On Tue, Jun 17, 2014 at 05:34:27PM +0200, Sebastian Reitenbach wrote: > > Hi, > > > > I'm trying to establish an IPSec tunnel between an OpenBSD 5.5 (amd64) > > box and a Cisco 2901, the whole day, but doesn't seem to > > get it t

Re: problem with IPSec between OpenBSD 5.5 and Cisco 2901

2014-06-17 Thread Remi Locherer
On Tue, Jun 17, 2014 at 05:34:27PM +0200, Sebastian Reitenbach wrote: > Hi, > > I'm trying to establish an IPSec tunnel between an OpenBSD 5.5 (amd64) > box and a Cisco 2901, the whole day, but doesn't seem to > get it to work. I think I have something wrong with the > crypto transforms for phase

problem with IPSec between OpenBSD 5.5 and Cisco 2901

2014-06-17 Thread Sebastian Reitenbach
Hi, I'm trying to establish an IPSec tunnel between an OpenBSD 5.5 (amd64) box and a Cisco 2901, the whole day, but doesn't seem to get it to work. I think I have something wrong with the crypto transforms for phase two, since this NO_PROPOSAL_CHOSEN I get in the logs, which I think is in phase t