Hello:
I am following AN21 and am attempting to connect from a Windows 7 Pro client.
Here are my client settings:
C:\Windows\system32>netsh advfirewall show global mainmode
Global Settings:
KeyLifetime 480min,0sess
SecMethods DHGroup2-3DES-SHA1,DHGroup2-AES128-SHA1
ForceDH Yes
Ok.
C:\Windows\system32>netsh advfirewall show global ipsec
Global Settings:
StrongCRLCheck 0:Disabled
SAIdleTimeMin 5min
DefaultExemptions NeighborDiscovery,DHCP
IPsecThroughNAT Server and client behind NAT
AuthzUserGrp None
AuthzComputerGrp None
Ok.
So, as you can see, my client is setup for both itself and the WR44 to be behind a NAT wall.
Following the app note and settig the client up to be the admin user it never gets to the ppp negotiation as IPSec fails, this form the event log:
16:56:47, 26 Jul 2016,(74) IKE SA Removed. Peer: ,Negotiation Failure
16:56:47, 26 Jul 2016,(74) IKE Negotiation Failed. Peer: ,Bad Packet
16:56:47, 26 Jul 2016,(74) IKE Keys Negotiated. Peer:
16:56:47, 26 Jul 2016,(74) New Phase 1 IKE Session 119.75.44.126,Responder
16:56:34, 26 Jul 2016,Clear Event Log
Usually this means a mismatched password and username. But my username for user14 is set to “*” and the psk is set to “mynameisjim” Exactly the same osk is used in my connection profile in windows.
ss398837>user 14 ?
Parameters are…
name: *
password:
epassword: .05;yeJFbeoxGAWA/bmI9CLCFgCL6gHEIitGCn54zlBKgZs=
newpwd:
enewpwd:
access: 4
fieldip:
IPaddr:
mask:
phonenum:
keyfile:
dun_en: OFF
webmode: 1
defpage:
Current user:mskroot
OK
ss398837>eroute 1 ?
Parameters are…
descr: L2TPServer
peerip:
bakpeerip:
peerid: *
ourid:
ouridtype: 0
neglocip:
neglocmsk:
locip:
locmsk:
locipifent: PPP
locipifadd: 1
remip:
remmsk:
remnetid:
mode: Transport
AHauth: Off
ESPauth: SHA1
ESPenc: AES
IPCOMPalg: Off
proto: Off
locport: 0
remport: 1701
ltime: 3600
lkbytes: 0
authmeth: PRESHARED
nosa: DROP
nosadeactcnt: 0
nattkaint: 20
autosa: 0
nosaoos: OFF
ikever: 1
ikecfg: 0
locfirstport: 0
loclastport: 65535
remfirstport: 0
remlastport: 65535
dhgroup: 0
ifent:
ifadd: 0
enckeybits: 128
privkey:
check_apnbu: OFF
apnbu: 0
usesecip: OFF
ipent:
ipadd: 0
oosdelsa: ON
intunnel: OFF
ripip:
vip: 0
xauthid:
inhibitno:
requireno:
ifvrrpmaster: OFF
vrrpinstance: -1
inact_to: 0
toslist:
debug: OFF
injectroute: OFF
metric: 1
replaywin: 0
OK
Looking for some pointers on how to trouble shoot this.
Cheers,
John