[Vpn-help] Problem connecting to Cisco VPN Concentrator

Brian Guild bguild at gmail.com
Fri Aug 7 10:09:30 CDT 2009


Problem:

The VPN client fails to connect to my gateway. When I click on connect,
the client application seems to connect briefly, but then immediately
reports "session terminated by gateway" (full console log below)

To Reproduce:

Connect to Cisco VPN.

VPN Client Version = 2.1.5 RC2
Windows OS Version = Windows 7 RTM
Gateway Make/Model = Cisco VPN Concentrator (not ASA)
Gateway OS Version = ?

debug.zip [attachment]
I could not get the decrypted ike dump to work on this OS and/or version of
Shrew.

What I see on the console is the following:

config loaded for site 'Houston'
configuring client settings ...
attached to key daemon ...
peer configured
iskamp proposal configured
esp proposal configured
client configured
local id configured
pre-shared key configured
bringing up tunnel ...
network device configured
tunnel enabled
session terminated by gateway
tunnel disabled
detached from key daemon ...

I have another PCF file over here to a different VPN Concentrator at my
organization that works.  I have inspected the 2 PCFs and the only real
difference I can see is that in sample1.pcf, the group name has an
underscore character.  sample2.pcf does not, and seems to connect fine. So,
this could either 1) be a problem with the import process or 2) my two VPN
concentrators are configured differently.

Any thoughts on how to make this work?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.shrew.net/pipermail/vpn-help/attachments/20090807/c35bd18c/attachment-0001.html>
-------------- next part --------------
[main]
Description=Houston, TX - USA
Host=vpn.somecompany.com
AuthType=1
GroupName=2307_20040728
GroupPwd=
enc_GroupPwd=41C0362E12D0F3469E57B0695101295B9B91E150BB77C11AB18C844977E22628B4E7D7450DA77810EFE4336D878FBAA43A42B9536EA00D3217DB9A1C758E569C
EnableISPConnect=0
ISPConnectType=0
ISPConnect=iPassConnect
ISPCommand=
Username=user1
SaveUserPassword=0
UserPassword=
enc_UserPassword=
NTDomain=BESURE
EnableBackup=1
BackupServer=vpn2.somecompany.com
EnableMSLogon=1
MSLogonType=0
EnableNat=1
TunnelingMode=0
TcpTunnelingPort=10000
CertStore=0
CertName=
CertPath=
CertSubjectName=
CertSerialHash=00000000000000000000000000000000
SendCertChain=0
DHGroup=2
ForceKeepAlives=1
PeerTimeout=90
EnableLocalLAN=0
ISPPhonebook=
-------------- next part --------------
A non-text attachment was scrubbed...
Name: debug.zip
Type: application/zip
Size: 6385 bytes
Desc: not available
URL: <https://lists.shrew.net/pipermail/vpn-help/attachments/20090807/c35bd18c/attachment-0001.zip>
-------------- next part --------------
[main]
Description=Seattle, WA - USA
Host=navpn.company.com
AuthType=1
GroupName=navpn
GroupPwd=
enc_GroupPwd=4F05AB650080433D16041D6938DF378A2CF8517BBA4B83B492535E531745519E773715C6F5778DF9DE10DC7E157426D377560BE06BB738C1
EnableISPConnect=0
ISPConnectType=0
ISPConnect=iPassConnect
ISPPhonebook=
ISPCommand=
Username=domain\username
SaveUserPassword=0
UserPassword=
enc_UserPassword=
NTDomain=COMPANY
EnableBackup=1
BackupServer=vpn2.companyname.com
EnableMSLogon=1
MSLogonType=0
EnableNat=1
TunnelingMode=0
TcpTunnelingPort=10000
CertStore=0
CertName=
CertPath=
CertSubjectName=
CertSerialHash=00000000000000000000000000000000
SendCertChain=0
PeerTimeout=90
EnableLocalLAN=0
ForceKeepAlives=1


More information about the vpn-help mailing list