Go Back   PCMech Forums > Help & Discussion > Networking & Online Security

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 08-16-2002, 05:57 AM   #1
Member (9 bit)
 
Join Date: Aug 2000
Location: Honolulu, Hawaii
Posts: 367
VPN setup w/ router and SSH sentinel

Need some help configuring a router for a home-office VPN. The error is "Cannot establish a security association for the virtual IP protocol. Cannot run the diagnostics. The remote end cannot find suitable IPSec proposal(phase-2)parameters. Verify the IPSec proposal parameters.

Sentinel proposol parameters:
IKE proposal
Encryption - 3DES
Integrity function - MD5
IKE mode - main mode
IKE group - MODP 768 (group 1)

IPSec proposal
Encryption - 3DES
Integrity function - HMAC-SHA-1
IPSec mode - tunnel
PFS group - MODP 768 (group 1)



Router settings:

Encryption 3DES
Authentication MD5

Advanced settings

Phase 1 - main mode

Proposal 1
encryption - DES
authentication SHA
group - 768-bit
key lifetime - 3600 seconds

proposal 2
encryption - 3DES
authentication - MD5
PFS - ON
group - 768-bit
key lifetime - 3600 seconds

other settings
Anti-replay is enabled


Any suggestions?
Boneless is offline   Reply With Quote
Old 08-16-2002, 08:36 AM   #2
Member (9 bit)
 
Great_One's Avatar
 
Join Date: May 2000
Location: Lexington, Michigan
Posts: 353
who is the router manufacturer?
__________________
Certifiable
===========================================

Cisco CCNA,CCDA
CompTIA A+, Network+,Inet+,Security+
CIW Associate
IBM AIX certified
IBM Certified Specialist - p5 and pSeries Administration and Support for AIX 5L V5.3
IBM Certified Systems Expert - p5 and pSeries Enterprise Technical Support AIX 5L V5.3
Great_One is offline   Reply With Quote
Old 08-16-2002, 03:08 PM   #3
Member (9 bit)
 
Join Date: Aug 2000
Location: Honolulu, Hawaii
Posts: 367
oops, that would be important wouldn't it. It is the BEFX41 by Linksys. Exactly the same documentation as the BEVP41 except mine supports 2 tunnels while the other supports 70 tunnels, and minor upgrades in menus, but 99% identical user guides.

BTW, if anyone is curious, The BEVP41 has a second co-processor to decrypt IPSec to support the tunnels, while mine does not. So the BEFX41 would be more processor intensive. That is the main difference between the two.
Boneless is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 08:46 AM.
Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.6.0