isa_user
Posts: 11
Joined: 15.May2007
Status: offline
|
hi justmee, i'm very happy that you spend time on answering my problems :o) first some generaly things: -router i've tested with: some bintec's / some artem / and siemens router -now at this time it is a netgear FWG114P (netgear say's there are 4 vpn passtrough clients at one time possible, see: http://kbserver.netgear.com/kb_web_files/n101222.asp) -(i tried it with AND without the vpn-pathrough option enabled in the netgear router-same thing) however things are making me crazy.. because sometimes the second connection is WORKING !? this would be a long post :o) .... first i have some trace about the 2 clients (first is OK, second FAILS): No. Time Source Destination Protocol Info 1 0.000000 *.*.0.73 *.*.0.71 ISAKMP Identity Protection (Main Mode) Frame 1 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: isakmp (500), Dst Port: isakmp (500) Source port: isakmp (500) Destination port: isakmp (500) Length: 320 Checksum: 0x5073 [correct] Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 2 0.002296 *.*.0.71 *.*.0.73 ISAKMP Identity Protection (Main Mode) Frame 2 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) User Datagram Protocol, Src Port: isakmp (500), Dst Port: isakmp (500) Source port: isakmp (500) Destination port: isakmp (500) Length: 156 Checksum: 0x6c59 [correct] Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 3 0.032866 *.*.0.73 *.*.0.71 ISAKMP Identity Protection (Main Mode) Frame 3 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: isakmp (500), Dst Port: isakmp (500) Source port: isakmp (500) Destination port: isakmp (500) Length: 240 Checksum: 0x572e [correct] Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 4 0.078146 *.*.0.71 *.*.0.73 ISAKMP Identity Protection (Main Mode) Frame 4 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) User Datagram Protocol, Src Port: isakmp (500), Dst Port: isakmp (500) Source port: isakmp (500) Destination port: isakmp (500) Length: 343 Checksum: 0xaa9b [correct] Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 5 0.096661 *.*.0.73 *.*.0.71 IP Fragmented IP protocol (proto=UDP 0x11, off=0) [Reassembled in #7] Frame 5 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) Data (1480 bytes) No. Time Source Destination Protocol Info 6 0.097888 *.*.0.73 *.*.0.71 IP Fragmented IP protocol (proto=UDP 0x11, off=1480) [Reassembled in #7] Frame 6 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) Data (1480 bytes) No. Time Source Destination Protocol Info 7 0.098517 *.*.0.73 *.*.0.71 ISAKMP Identity Protection (Main Mode) Frame 7 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 4500 (4500), Dst Port: 4500 (4500) Source port: 4500 (4500) Destination port: 4500 (4500) Length: 3688 (bogus, should be 728) Checksum: 0x54cd [correct] UDP Encapsulation of IPsec Packets Non-ESP Marker Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 8 0.113545 *.*.0.71 *.*.0.73 IP Fragmented IP protocol (proto=UDP 0x11, off=0) [Reassembled in #10] Frame 8 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) Data (1480 bytes) No. Time Source Destination Protocol Info 9 0.114773 *.*.0.71 *.*.0.73 IP Fragmented IP protocol (proto=UDP 0x11, off=1480) [Reassembled in #10] Frame 9 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) Data (1480 bytes) No. Time Source Destination Protocol Info 10 0.115318 *.*.0.71 *.*.0.73 ISAKMP Identity Protection (Main Mode) Frame 10 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) User Datagram Protocol, Src Port: 4500 (4500), Dst Port: 4500 (4500) Source port: 4500 (4500) Destination port: 4500 (4500) Length: 3584 (bogus, should be 624) Checksum: 0xa3af [correct] UDP Encapsulation of IPsec Packets Non-ESP Marker Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 11 0.120052 *.*.0.73 *.*.0.71 ISAKMP Quick Mode Frame 11 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 4500 (4500), Dst Port: 4500 (4500) Source port: 4500 (4500) Destination port: 4500 (4500) Length: 328 Checksum: 0x2ee6 [correct] UDP Encapsulation of IPsec Packets Non-ESP Marker Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 12 0.122585 *.*.0.71 *.*.0.73 ISAKMP Quick Mode Frame 12 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) User Datagram Protocol, Src Port: 4500 (4500), Dst Port: 4500 (4500) Source port: 4500 (4500) Destination port: 4500 (4500) Length: 200 Checksum: 0x3965 [correct] UDP Encapsulation of IPsec Packets Non-ESP Marker Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 13 0.124878 *.*.0.73 *.*.0.71 ISAKMP Quick Mode Frame 13 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 4500 (4500), Dst Port: 4500 (4500) Source port: 4500 (4500) Destination port: 4500 (4500) Length: 64 Checksum: 0xf47f [correct] UDP Encapsulation of IPsec Packets Non-ESP Marker Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 14 0.126100 *.*.0.71 *.*.0.73 ISAKMP Quick Mode Frame 14 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) User Datagram Protocol, Src Port: 4500 (4500), Dst Port: 4500 (4500) Source port: 4500 (4500) Destination port: 4500 (4500) Length: 96 Checksum: 0xd501 [correct] UDP Encapsulation of IPsec Packets Non-ESP Marker Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 15 0.128921 *.*.0.73 *.*.0.71 ESP ESP (SPI=0x2664cce3) Frame 15 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 4500 (4500), Dst Port: 4500 (4500) Source port: 4500 (4500) Destination port: 4500 (4500) Length: 164 Checksum: 0x0000 (none) UDP Encapsulation of IPsec Packets Encapsulating Security Payload No. Time Source Destination Protocol Info 16 0.129229 *.*.0.71 *.*.0.73 ESP ESP (SPI=0x97b03f7f) Frame 16 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) User Datagram Protocol, Src Port: 4500 (4500), Dst Port: 4500 (4500) Source port: 4500 (4500) Destination port: 4500 (4500) Length: 164 Checksum: 0x0000 (none) UDP Encapsulation of IPsec Packets Encapsulating Security Payload No. Time Source Destination Protocol Info 17 0.130976 *.*.0.73 *.*.0.71 ESP ESP (SPI=0x2664cce3) Frame 17 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 4500 (4500), Dst Port: 4500 (4500) Source port: 4500 (4500) Destination port: 4500 (4500) Length: 68 Checksum: 0x0000 (none) UDP Encapsulation of IPsec Packets Encapsulating Security Payload No. Time Source Destination Protocol Info 18 0.131346 *.*.0.73 *.*.0.71 ESP ESP (SPI=0x2664cce3) Frame 18 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 4500 (4500), Dst Port: 4500 (4500) Source port: 4500 (4500) Destination port: 4500 (4500) Length: 100 Checksum: 0x0000 (none) UDP Encapsulation of IPsec Packets Encapsulating Security Payload No. Time Source Destination Protocol Info 19 0.131448 *.*.0.71 *.*.0.73 ESP ESP (SPI=0x97b03f7f) Frame 19 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) User Datagram Protocol, Src Port: 4500 (4500), Dst Port: 4500 (4500) Source port: 4500 (4500) Destination port: 4500 (4500) Length: 60 Checksum: 0x0000 (none) UDP Encapsulation of IPsec Packets Encapsulating Security Payload ------------now here comes the second (did not work)--------------------------- No. Time Source Destination Protocol Info 20 31.019896 *.*.0.73 *.*.0.71 ISAKMP Identity Protection (Main Mode) Frame 20 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 32767 (32767), Dst Port: isakmp (500) Source port: 32767 (32767) Destination port: isakmp (500) Length: 320 Checksum: 0x130d [correct] Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 21 31.022680 *.*.0.71 *.*.0.73 ISAKMP Identity Protection (Main Mode) Frame 21 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) User Datagram Protocol, Src Port: isakmp (500), Dst Port: 32767 (32767) Source port: isakmp (500) Destination port: 32767 (32767) Length: 156 Checksum: 0xc200 [correct] Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 22 31.087600 *.*.0.73 *.*.0.71 ISAKMP Identity Protection (Main Mode) Frame 22 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 32767 (32767), Dst Port: isakmp (500) Source port: 32767 (32767) Destination port: isakmp (500) Length: 240 Checksum: 0x7102 [correct] Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 23 31.132930 *.*.0.71 *.*.0.73 ISAKMP Identity Protection (Main Mode) Frame 23 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) User Datagram Protocol, Src Port: isakmp (500), Dst Port: 32767 (32767) Source port: isakmp (500) Destination port: 32767 (32767) Length: 343 Checksum: 0x74d1 [correct] Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 24 31.209178 *.*.0.73 *.*.0.71 IP Fragmented IP protocol (proto=UDP 0x11, off=0) [Reassembled in #26] Frame 24 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) Data (1480 bytes) No. Time Source Destination Protocol Info 25 31.210406 *.*.0.73 *.*.0.71 IP Fragmented IP protocol (proto=UDP 0x11, off=1480) [Reassembled in #26] Frame 25 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) Data (1480 bytes) No. Time Source Destination Protocol Info 26 31.211026 *.*.0.73 *.*.0.71 ISAKMP Identity Protection (Main Mode) Frame 26 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 32768 (32768), Dst Port: 4500 (4500) Source port: 32768 (32768) Destination port: 4500 (4500) Length: 3680 (bogus, should be 720) Checksum: 0x5b02 [correct] UDP Encapsulation of IPsec Packets Non-ESP Marker Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 27 31.227118 *.*.0.71 *.*.0.73 IP Fragmented IP protocol (proto=UDP 0x11, off=0) [Reassembled in #29] Frame 27 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) Data (1480 bytes) No. Time Source Destination Protocol Info 28 31.228348 *.*.0.71 *.*.0.73 IP Fragmented IP protocol (proto=UDP 0x11, off=1480) [Reassembled in #29] Frame 28 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) Data (1480 bytes) No. Time Source Destination Protocol Info 29 31.228891 *.*.0.71 *.*.0.73 ISAKMP Identity Protection (Main Mode) Frame 29 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) User Datagram Protocol, Src Port: 4500 (4500), Dst Port: 32768 (32768) Source port: 4500 (4500) Destination port: 32768 (32768) Length: 3584 (bogus, should be 624) Checksum: 0x3333 [correct] UDP Encapsulation of IPsec Packets Non-ESP Marker Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 30 31.246417 *.*.0.73 *.*.0.71 ISAKMP Quick Mode Frame 30 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 32768 (32768), Dst Port: 4500 (4500) Source port: 32768 (32768) Destination port: 4500 (4500) Length: 328 Checksum: 0x08ae [correct] UDP Encapsulation of IPsec Packets Non-ESP Marker Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 31 31.248919 *.*.0.71 *.*.0.73 ISAKMP Quick Mode Frame 31 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) User Datagram Protocol, Src Port: 4500 (4500), Dst Port: 32768 (32768) Source port: 4500 (4500) Destination port: 32768 (32768) Length: 200 Checksum: 0x364e [correct] UDP Encapsulation of IPsec Packets Non-ESP Marker Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 32 31.253539 *.*.0.73 *.*.0.71 ISAKMP Quick Mode Frame 32 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 32768 (32768), Dst Port: 4500 (4500) Source port: 32768 (32768) Destination port: 4500 (4500) Length: 64 Checksum: 0x5b41 [correct] UDP Encapsulation of IPsec Packets Non-ESP Marker Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 33 31.254671 *.*.0.71 *.*.0.73 ISAKMP Quick Mode Frame 33 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) User Datagram Protocol, Src Port: 4500 (4500), Dst Port: 32768 (32768) Source port: 4500 (4500) Destination port: 32768 (32768) Length: 96 Checksum: 0x748d [correct] UDP Encapsulation of IPsec Packets Non-ESP Marker Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 34 31.267397 *.*.0.73 *.*.0.71 ESP ESP (SPI=0x91283f52) Frame 34 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 32768 (32768), Dst Port: 4500 (4500) Source port: 32768 (32768) Destination port: 4500 (4500) Length: 164 Checksum: 0x0000 (none) UDP Encapsulation of IPsec Packets Encapsulating Security Payload No. Time Source Destination Protocol Info 35 32.262500 *.*.0.73 *.*.0.71 ESP ESP (SPI=0x91283f52) Frame 35 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 32768 (32768), Dst Port: 4500 (4500) Source port: 32768 (32768) Destination port: 4500 (4500) Length: 164 Checksum: 0x0000 (none) UDP Encapsulation of IPsec Packets Encapsulating Security Payload No. Time Source Destination Protocol Info 36 34.265703 *.*.0.73 *.*.0.71 ESP ESP (SPI=0x91283f52) Frame 36 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 32768 (32768), Dst Port: 4500 (4500) Source port: 32768 (32768) Destination port: 4500 (4500) Length: 164 Checksum: 0x0000 (none) UDP Encapsulation of IPsec Packets Encapsulating Security Payload No. Time Source Destination Protocol Info 37 38.272099 *.*.0.73 *.*.0.71 ESP ESP (SPI=0x91283f52) Frame 37 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 32768 (32768), Dst Port: 4500 (4500) Source port: 32768 (32768) Destination port: 4500 (4500) Length: 164 Checksum: 0x0000 (none) UDP Encapsulation of IPsec Packets Encapsulating Security Payload No. Time Source Destination Protocol Info 38 46.274810 *.*.0.73 *.*.0.71 ESP ESP (SPI=0x91283f52) Frame 38 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 32768 (32768), Dst Port: 4500 (4500) Source port: 32768 (32768) Destination port: 4500 (4500) Length: 164 Checksum: 0x0000 (none) UDP Encapsulation of IPsec Packets Encapsulating Security Payload No. Time Source Destination Protocol Info 39 56.280850 *.*.0.73 *.*.0.71 ESP ESP (SPI=0x91283f52) Frame 39 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 32768 (32768), Dst Port: 4500 (4500) Source port: 32768 (32768) Destination port: 4500 (4500) Length: 164 Checksum: 0x0000 (none) UDP Encapsulation of IPsec Packets Encapsulating Security Payload No. Time Source Destination Protocol Info 40 66.298372 *.*.0.73 *.*.0.71 ISAKMP Informational Frame 40 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 32768 (32768), Dst Port: 4500 (4500) Source port: 32768 (32768) Destination port: 4500 (4500) Length: 104 Checksum: 0x5e31 [correct] UDP Encapsulation of IPsec Packets Non-ESP Marker Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 41 66.299283 *.*.0.71 *.*.0.73 ISAKMP Informational Frame 41 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) User Datagram Protocol, Src Port: 4500 (4500), Dst Port: 32768 (32768) Source port: 4500 (4500) Destination port: 32768 (32768) Length: 104 Checksum: 0x7bc3 [correct] UDP Encapsulation of IPsec Packets Non-ESP Marker Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 42 66.312821 *.*.0.73 *.*.0.71 ISAKMP Informational Frame 42 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 32768 (32768), Dst Port: 4500 (4500) Source port: 32768 (32768) Destination port: 4500 (4500) Length: 120 Checksum: 0x546c [correct] UDP Encapsulation of IPsec Packets Non-ESP Marker Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 43 66.314134 *.*.0.71 *.*.0.73 ISAKMP Informational Frame 43 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) User Datagram Protocol, Src Port: 4500 (4500), Dst Port: 32768 (32768) Source port: 4500 (4500) Destination port: 32768 (32768) Length: 120 Checksum: 0xa054 [correct] UDP Encapsulation of IPsec Packets Non-ESP Marker Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 44 71.053954 *.*.0.73 *.*.0.71 UDPENCAP Frame 44 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 32768 (32768), Dst Port: 4500 (4500) Source port: 32768 (32768) Destination port: 4500 (4500) Length: 9 Checksum: 0xf24e [correct] UDP Encapsulation of IPsec Packets NAT-keepalive packet ------------------------------------------------- and now a trace round about 10 min later, the first client works fine, AND the second too ... the trace from the second: No. Time Source Destination Protocol Info 334 23.832558 *.*.0.73 *.*.0.71 ISAKMP Identity Protection (Main Mode) Frame 334 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 32769 (32769), Dst Port: isakmp (500) Source port: 32769 (32769) Destination port: isakmp (500) Length: 320 Checksum: 0x50f9 [correct] Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 335 23.835370 *.*.0.71 *.*.0.73 ISAKMP Identity Protection (Main Mode) Frame 335 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) User Datagram Protocol, Src Port: isakmp (500), Dst Port: 32769 (32769) Source port: isakmp (500) Destination port: 32769 (32769) Length: 156 Checksum: 0xf847 [correct] Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 336 23.889566 *.*.0.73 *.*.0.71 ISAKMP Identity Protection (Main Mode) Frame 336 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 32769 (32769), Dst Port: isakmp (500) Source port: 32769 (32769) Destination port: isakmp (500) Length: 240 Checksum: 0xe2ef [correct] Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 337 23.935096 *.*.0.71 *.*.0.73 ISAKMP Identity Protection (Main Mode) Frame 337 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) User Datagram Protocol, Src Port: isakmp (500), Dst Port: 32769 (32769) Source port: isakmp (500) Destination port: 32769 (32769) Length: 343 Checksum: 0x8a30 [correct] Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 338 23.981642 *.*.0.73 *.*.0.71 IP Fragmented IP protocol (proto=UDP 0x11, off=0) [Reassembled in #340] Frame 338 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) Data (1480 bytes) No. Time Source Destination Protocol Info 339 23.982869 *.*.0.73 *.*.0.71 IP Fragmented IP protocol (proto=UDP 0x11, off=1480) [Reassembled in #340] Frame 339 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) Data (1480 bytes) No. Time Source Destination Protocol Info 340 23.983490 *.*.0.73 *.*.0.71 ISAKMP Identity Protection (Main Mode) Frame 340 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 32768 (32768), Dst Port: 4500 (4500) Source port: 32768 (32768) Destination port: 4500 (4500) Length: 3680 (bogus, should be 720) Checksum: 0x5963 [correct] UDP Encapsulation of IPsec Packets Non-ESP Marker Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 341 23.999215 *.*.0.71 *.*.0.73 IP Fragmented IP protocol (proto=UDP 0x11, off=0) [Reassembled in #343] Frame 341 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) Data (1480 bytes) No. Time Source Destination Protocol Info 342 24.000444 *.*.0.71 *.*.0.73 IP Fragmented IP protocol (proto=UDP 0x11, off=1480) [Reassembled in #343] Frame 342 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) Data (1480 bytes) No. Time Source Destination Protocol Info 343 24.000991 *.*.0.71 *.*.0.73 ISAKMP Identity Protection (Main Mode) Frame 343 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) User Datagram Protocol, Src Port: 4500 (4500), Dst Port: 32768 (32768) Source port: 4500 (4500) Destination port: 32768 (32768) Length: 3584 (bogus, should be 624) Checksum: 0xd28c [correct] UDP Encapsulation of IPsec Packets Non-ESP Marker Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 344 24.019281 *.*.0.73 *.*.0.71 ISAKMP Quick Mode Frame 344 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 32768 (32768), Dst Port: 4500 (4500) Source port: 32768 (32768) Destination port: 4500 (4500) Length: 328 Checksum: 0xe123 [correct] UDP Encapsulation of IPsec Packets Non-ESP Marker Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 345 24.021782 *.*.0.71 *.*.0.73 ISAKMP Quick Mode Frame 345 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) User Datagram Protocol, Src Port: 4500 (4500), Dst Port: 32768 (32768) Source port: 4500 (4500) Destination port: 32768 (32768) Length: 200 Checksum: 0xbafd [correct] UDP Encapsulation of IPsec Packets Non-ESP Marker Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 346 24.026589 *.*.0.73 *.*.0.71 ISAKMP Quick Mode Frame 346 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 32768 (32768), Dst Port: 4500 (4500) Source port: 32768 (32768) Destination port: 4500 (4500) Length: 64 Checksum: 0x79e6 [correct] UDP Encapsulation of IPsec Packets Non-ESP Marker Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 347 24.031828 *.*.0.71 *.*.0.73 ISAKMP Quick Mode Frame 347 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) User Datagram Protocol, Src Port: 4500 (4500), Dst Port: 32768 (32768) Source port: 4500 (4500) Destination port: 32768 (32768) Length: 96 Checksum: 0xd73a [correct] UDP Encapsulation of IPsec Packets Non-ESP Marker Internet Security Association and Key Management Protocol No. Time Source Destination Protocol Info 348 24.038039 *.*.0.73 *.*.0.71 ESP ESP (SPI=0xd49be094) Frame 348 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 32768 (32768), Dst Port: 4500 (4500) Source port: 32768 (32768) Destination port: 4500 (4500) Length: 164 Checksum: 0x0000 (none) UDP Encapsulation of IPsec Packets Encapsulating Security Payload SPI: 0xd49be094 Sequence: 1 No. Time Source Destination Protocol Info 349 24.038370 *.*.0.71 *.*.0.73 ESP ESP (SPI=0xd06530f8) Frame 349 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) User Datagram Protocol, Src Port: 4500 (4500), Dst Port: 32768 (32768) Source port: 4500 (4500) Destination port: 32768 (32768) Length: 164 Checksum: 0x0000 (none) UDP Encapsulation of IPsec Packets Encapsulating Security Payload SPI: 0xd06530f8 Sequence: 1 No. Time Source Destination Protocol Info 350 24.043240 *.*.0.73 *.*.0.71 ESP ESP (SPI=0xd49be094) Frame 350 ( Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 32768 (32768), Dst Port: 4500 (4500) Source port: 32768 (32768) Destination port: 4500 (4500) Length: 68 Checksum: 0x0000 (none) UDP Encapsulation of IPsec Packets Encapsulating Security Payload SPI: 0xd49be094 Sequence: 2 No. Time Source Destination Protocol Info 351 24.043510 *.*.0.71 *.*.0.73 ESP ESP (SPI=0xd06530f8) Frame 351 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) User Datagram Protocol, Src Port: 4500 (4500), Dst Port: 32768 (32768) Source port: 4500 (4500) Destination port: 32768 (32768) Length: 60 Checksum: 0x0000 (none) UDP Encapsulation of IPsec Packets Encapsulating Security Payload SPI: 0xd06530f8 Sequence: 2 No. Time Source Destination Protocol Info 352 24.043884 *.*.0.73 *.*.0.71 ESP ESP (SPI=0xd49be094) Frame 352 Internet Protocol, Src: *.*.0.73 (*.*.0.73), Dst: *.*.0.71 (*.*.0.71) User Datagram Protocol, Src Port: 32768 (32768), Dst Port: 4500 (4500) Source port: 32768 (32768) Destination port: 4500 (4500) Length: 100 Checksum: 0x0000 (none) UDP Encapsulation of IPsec Packets Encapsulating Security Payload SPI: 0xd49be094 Sequence: 3 No. Time Source Destination Protocol Info 353 24.044109 *.*.0.71 *.*.0.73 ESP ESP (SPI=0xd06530f8) Frame 353 Internet Protocol, Src: *.*.0.71 (*.*.0.71), Dst: *.*.0.73 (*.*.0.73) User Datagram Protocol, Src Port: 4500 (4500), Dst Port: 32768 (32768) Source port: 4500 (4500) Destination port: 32768 (32768) Length: 60 Checksum: 0x0000 (none) UDP Encapsulation of IPsec Packets Encapsulating Security Payload SPI: 0xd06530f8 Sequence: 3 ---------------- - in isa log is not much to see, only IKE-Client (disconnected) and IPSec-NAT-T-Client(diconnected) then nothing more - i've tried combinations with many other clients - every time the same thing -what i absolutely not understand is, that sometime 2 ore more clients can connect and sometimes only 1 - not logical for a newbie like me :o) -the only error on the client is the: Error 678 The remote computer did not respond.. i hope you have some more ideas ? thank you for reading the long traces :o) greets an nica weekend! isa_user
|