So I'm trying to get a couple 5620's hooked up to a 318v3 netgear. I have tried to follow some of the users that have done it on this forum but not having luck.
From what I can tell the fvs318v3 does not support 'users' so you can only use the PSK methods which is fine for me.
But, I have my 5620 upgraded to the VPN firmware and using the "Generic PSK" profile. Everytime I try and connect it is complaining about the "ID" being incorrect:
Log from FVS318:
[2010-12-01 23:59:07][==== IKE PHASE 1(from 69.11.11.11) START (responder) ====]
[2010-12-01 23:59:07]**** RECEIVED FIRST MESSAGE OF AGGR MODE ****
[2010-12-01 23:59:07]<POLICY: > PAYLOADS: SA,PROP,TRANS,KE,NONCE,ID,VID,VID,VID,VID,VID,VID
[2010-12-01 23:59:07]SENDING NOTIFY MSG:
[2010-12-01 23:59:07]INVALID_ID_INFORMATION
[2010-12-01 23:59:07]**** SENT OUT INFORMATIONAL EXCHANGE MESSAGE ****
[2010-12-01 23:59:07]<POLICY: > PAYLOADS: NOTIFY
[2010-12-01 23:59:09][==== IKE PHASE 1(from 69.11.11.11) START (responder) ====]
[2010-12-01 23:59:09]**** RECEIVED FIRST MESSAGE OF AGGR MODE ****
[2010-12-01 23:59:09]<POLICY: > PAYLOADS: SA,PROP,TRANS,KE,NONCE,ID,VID,VID,VID,VID,VID,VID
[2010-12-01 23:59:09]SENDING NOTIFY MSG:
[2010-12-01 23:59:09]INVALID_ID_INFORMATION
[2010-12-01 23:59:09]**** SENT OUT INFORMATIONAL EXCHANGE MESSAGE ****
[2010-12-01 23:59:09]<POLICY: > PAYLOADS: NOTIFY
The phone is saying the same thing. I setup the syslog server on the phone and I see this coming from the phone:
<175>192.168.0.55 isakmp_start_session-374: Loading oakley prefrences 192.168.0.55 03/12 10:05:27.974
<175>192.168.0.55 construct_isakmp_sa-246: Building phase 1 SA payload for 72.11.11.11 192.168.0.55 03/12 10:05:27.976
<175>192.168.0.55 construct_ke-191: Constructing key exchange payload for 72.11.11.11 192.168.0.55 03/12 10:05:28.949
<175>192.168.0.55 construct_id-251: Constructing id payload 192.168.0.55 03/12 10:05:28.973
<175>192.168.0.55 got_info_xchg-137: rcv'd phase 1 notify, Invalid id info 192.168.0.55 03/12 10:05:29.065
<175>192.168.0.55 timed_out-138: Retransmission timeout, count = 0 192.168.0.55 03/12 10:05:31.083
<175>192.168.0.55 got_info_xchg-137: rcv'd phase 1 notify, Invalid id info 192.168.0.55 03/12 10:05:31.212
<175>192.168.0.55 timed_out-138: Retransmission timeout, count = 1 192.168.0.55 03/12 10:05:33.211
<175>192.168.0.55 got_info_xchg-137: rcv'd phase 1 notify, Invalid id info 192.168.0.55 03/12 10:05:33.335
<175>192.168.0.55 timed_out-138: Retransmission timeout, count = 2 192.168.0.55 03/12 10:05:34.331
<175>192.168.0.55 got_info_xchg-137: rcv'd phase 1 notify, Invalid id info 192.168.0.55 03/12 10:05:34.441
<175>192.168.0.55 timed_out-138: Retransmission timeout, count = 3 192.168.0.55 03/12 10:05:36.441
<175>192.168.0.55 got_info_xchg-137: rcv'd phase 1 notify, Invalid id info 192.168.0.55 03/12 10:05:36.552
<175>192.168.0.55 timed_out-138: Retransmission timeout, count = 4 192.168.0.55 03/12 10:05:38.551
<171>192.168.0.55 vpnSetLastError-587: Error Encountered at 142 in IKMPD 192.168.0.55 03/12 10:05:38.553
<171>192.168.0.55 timed_out-143: IKE Phase1 no response 4 192.168.0.55 03/12 10:05:38.555
<171>192.168.0.55 vpnSetLastError-587: Error Encountered at 459 in IKECFG 192.168.0.55 03/12 10:05:38.557
<175>192.168.0.55 RestoreRealIP-98: DeInit of Virtual if not required 192.168.0.55 03/12 10:05:40.552
<174>192.168.0.55 SetupVPNTunnel-983: SetupIKEAndIPsecSAs Returned -2 192.168.0.55 03/12 10:05:40.581
<174>192.168.0.55 ike_msg_task-909: Exiting from ike_msg_task 192.168.0.55 03/12 10:05:40.627
<175>192.168.0.55 UpdateIkeConfig-1706: Adding member tunnel ID type 0x3 mem ID type 0x4 192.168.0.55 03/12 10:07:40.879
<175>192.168.0.55 UpdateIkeConfig-1706: Adding member tunnel ID type 0x1 mem ID type 0x4 192.168.0.55 03/12 10:07:40.881
<175>192.168.0.55 ResetSpiIgnoreList-267: Reset the spi recent list 192.168.0.55 03/12 10:07:40.904
<175>192.168.0.55 start_ike_msg_task-927: IKE MSG Queue Created 192.168.0.55 03/12 10:07:40.905
<175>192.168.0.55 vpn_fill_conn_info-527: Remote mem mask = 0xffffff00 bits = 24 192.168.0.55 03/12 10:07:40.937
<175>192.168.0.55 vpn_fill_conn_info-537: Initializing with default tunnel for phase1 192.168.0.55:32 ===> 192.168.19.0:24 192.168.0.55 03/12 10:07:40.939
<175>192.168.0.55 get_default_remote_port-269: Default remote ike port is 500 192.168.0.55 03/12 10:07:40.942
<174>192.168.0.55 isakmp_start_xauth-636: Phase1 negotiation started with 72.11.11.11 192.168.0.55 03/12 10:07:40.944
<175>192.168.0.55 isakmp_start_session-374: Loading oakley prefrences 192.168.0.55 03/12 10:07:40.946
<175>192.168.0.55 construct_isakmp_sa-246: Building phase 1 SA payload for 72.11.11.11 192.168.0.55 03/12 10:07:40.946
<175>192.168.0.55 construct_ke-191: Constructing key exchange payload for 72.11.11.11 192.168.0.55 03/12 10:07:41.935
<175>192.168.0.55 construct_id-251: Constructing id payload 192.168.0.55 03/12 10:07:41.937
<175>192.168.0.55 got_info_xchg-137: rcv'd phase 1 notify, Invalid id info 192.168.0.55 03/12 10:07:42.042
<175>192.168.0.55 timed_out-138: Retransmission timeout, count = 0 192.168.0.55 03/12 10:07:44.062
<175>192.168.0.55 got_info_xchg-137: rcv'd phase 1 notify, Invalid id info 192.168.0.55 03/12 10:07:44.165
<175>192.168.0.55 timed_out-138: Retransmission timeout, count = 1 192.168.0.55 03/12 10:07:46.161
<175>192.168.0.55 got_info_xchg-137: rcv'd phase 1 notify, Invalid id info 192.168.0.55 03/12 10:07:46.272
<175>192.168.0.55 timed_out-138: Retransmission timeout, count = 2 192.168.0.55 03/12 10:07:48.271
<175>192.168.0.55 got_info_xchg-137: rcv'd phase 1 notify, Invalid id info 192.168.0.55 03/12 10:07:48.374
<175>192.168.0.55 timed_out-138: Retransmission timeout, count = 3 192.168.0.55 03/12 10:07:49.371
<175>192.168.0.55 got_info_xchg-137: rcv'd phase 1 notify, Invalid id info 192.168.0.55 03/12 10:07:49.474
<175>192.168.0.55 timed_out-138: Retransmission timeout, count = 4 192.168.0.55 03/12 10:07:51.470
<171>192.168.0.55 vpnSetLastError-587: Error Encountered at 142 in IKMPD 192.168.0.55 03/12 10:07:51.472
<171>192.168.0.55 timed_out-143: IKE Phase1 no response 4 192.168.0.55 03/12 10:07:51.513
<171>192.168.0.55 vpnSetLastError-587: Error Encountered at 459 in IKECFG 192.168.0.55 03/12 10:07:51.514
<175>192.168.0.55 RestoreRealIP-98: DeInit of Virtual if not required 192.168.0.55 03/12 10:07:53.470
<174>192.168.0.55 SetupVPNTunnel-983: SetupIKEAndIPsecSAs Returned -2 192.168.0.55 03/12 10:07:53.474
<174>192.168.0.55 ike_msg_task-909: Exiting from ike_msg_task 192.168.0.55 03/12 10:07:53.546
Anyone have any ideas... On phone the phone and router I have the IKE ID set to "remote" and "USER-Fqdn" however it is not working. I know the FVS318 is not a 'supported' router but many people seem to have gotten it working. I'm trying to do this install on the cheap for these guys..
thanks
From what I can tell the fvs318v3 does not support 'users' so you can only use the PSK methods which is fine for me.
But, I have my 5620 upgraded to the VPN firmware and using the "Generic PSK" profile. Everytime I try and connect it is complaining about the "ID" being incorrect:
Log from FVS318:
[2010-12-01 23:59:07][==== IKE PHASE 1(from 69.11.11.11) START (responder) ====]
[2010-12-01 23:59:07]**** RECEIVED FIRST MESSAGE OF AGGR MODE ****
[2010-12-01 23:59:07]<POLICY: > PAYLOADS: SA,PROP,TRANS,KE,NONCE,ID,VID,VID,VID,VID,VID,VID
[2010-12-01 23:59:07]SENDING NOTIFY MSG:
[2010-12-01 23:59:07]INVALID_ID_INFORMATION
[2010-12-01 23:59:07]**** SENT OUT INFORMATIONAL EXCHANGE MESSAGE ****
[2010-12-01 23:59:07]<POLICY: > PAYLOADS: NOTIFY
[2010-12-01 23:59:09][==== IKE PHASE 1(from 69.11.11.11) START (responder) ====]
[2010-12-01 23:59:09]**** RECEIVED FIRST MESSAGE OF AGGR MODE ****
[2010-12-01 23:59:09]<POLICY: > PAYLOADS: SA,PROP,TRANS,KE,NONCE,ID,VID,VID,VID,VID,VID,VID
[2010-12-01 23:59:09]SENDING NOTIFY MSG:
[2010-12-01 23:59:09]INVALID_ID_INFORMATION
[2010-12-01 23:59:09]**** SENT OUT INFORMATIONAL EXCHANGE MESSAGE ****
[2010-12-01 23:59:09]<POLICY: > PAYLOADS: NOTIFY
The phone is saying the same thing. I setup the syslog server on the phone and I see this coming from the phone:
<175>192.168.0.55 isakmp_start_session-374: Loading oakley prefrences 192.168.0.55 03/12 10:05:27.974
<175>192.168.0.55 construct_isakmp_sa-246: Building phase 1 SA payload for 72.11.11.11 192.168.0.55 03/12 10:05:27.976
<175>192.168.0.55 construct_ke-191: Constructing key exchange payload for 72.11.11.11 192.168.0.55 03/12 10:05:28.949
<175>192.168.0.55 construct_id-251: Constructing id payload 192.168.0.55 03/12 10:05:28.973
<175>192.168.0.55 got_info_xchg-137: rcv'd phase 1 notify, Invalid id info 192.168.0.55 03/12 10:05:29.065
<175>192.168.0.55 timed_out-138: Retransmission timeout, count = 0 192.168.0.55 03/12 10:05:31.083
<175>192.168.0.55 got_info_xchg-137: rcv'd phase 1 notify, Invalid id info 192.168.0.55 03/12 10:05:31.212
<175>192.168.0.55 timed_out-138: Retransmission timeout, count = 1 192.168.0.55 03/12 10:05:33.211
<175>192.168.0.55 got_info_xchg-137: rcv'd phase 1 notify, Invalid id info 192.168.0.55 03/12 10:05:33.335
<175>192.168.0.55 timed_out-138: Retransmission timeout, count = 2 192.168.0.55 03/12 10:05:34.331
<175>192.168.0.55 got_info_xchg-137: rcv'd phase 1 notify, Invalid id info 192.168.0.55 03/12 10:05:34.441
<175>192.168.0.55 timed_out-138: Retransmission timeout, count = 3 192.168.0.55 03/12 10:05:36.441
<175>192.168.0.55 got_info_xchg-137: rcv'd phase 1 notify, Invalid id info 192.168.0.55 03/12 10:05:36.552
<175>192.168.0.55 timed_out-138: Retransmission timeout, count = 4 192.168.0.55 03/12 10:05:38.551
<171>192.168.0.55 vpnSetLastError-587: Error Encountered at 142 in IKMPD 192.168.0.55 03/12 10:05:38.553
<171>192.168.0.55 timed_out-143: IKE Phase1 no response 4 192.168.0.55 03/12 10:05:38.555
<171>192.168.0.55 vpnSetLastError-587: Error Encountered at 459 in IKECFG 192.168.0.55 03/12 10:05:38.557
<175>192.168.0.55 RestoreRealIP-98: DeInit of Virtual if not required 192.168.0.55 03/12 10:05:40.552
<174>192.168.0.55 SetupVPNTunnel-983: SetupIKEAndIPsecSAs Returned -2 192.168.0.55 03/12 10:05:40.581
<174>192.168.0.55 ike_msg_task-909: Exiting from ike_msg_task 192.168.0.55 03/12 10:05:40.627
<175>192.168.0.55 UpdateIkeConfig-1706: Adding member tunnel ID type 0x3 mem ID type 0x4 192.168.0.55 03/12 10:07:40.879
<175>192.168.0.55 UpdateIkeConfig-1706: Adding member tunnel ID type 0x1 mem ID type 0x4 192.168.0.55 03/12 10:07:40.881
<175>192.168.0.55 ResetSpiIgnoreList-267: Reset the spi recent list 192.168.0.55 03/12 10:07:40.904
<175>192.168.0.55 start_ike_msg_task-927: IKE MSG Queue Created 192.168.0.55 03/12 10:07:40.905
<175>192.168.0.55 vpn_fill_conn_info-527: Remote mem mask = 0xffffff00 bits = 24 192.168.0.55 03/12 10:07:40.937
<175>192.168.0.55 vpn_fill_conn_info-537: Initializing with default tunnel for phase1 192.168.0.55:32 ===> 192.168.19.0:24 192.168.0.55 03/12 10:07:40.939
<175>192.168.0.55 get_default_remote_port-269: Default remote ike port is 500 192.168.0.55 03/12 10:07:40.942
<174>192.168.0.55 isakmp_start_xauth-636: Phase1 negotiation started with 72.11.11.11 192.168.0.55 03/12 10:07:40.944
<175>192.168.0.55 isakmp_start_session-374: Loading oakley prefrences 192.168.0.55 03/12 10:07:40.946
<175>192.168.0.55 construct_isakmp_sa-246: Building phase 1 SA payload for 72.11.11.11 192.168.0.55 03/12 10:07:40.946
<175>192.168.0.55 construct_ke-191: Constructing key exchange payload for 72.11.11.11 192.168.0.55 03/12 10:07:41.935
<175>192.168.0.55 construct_id-251: Constructing id payload 192.168.0.55 03/12 10:07:41.937
<175>192.168.0.55 got_info_xchg-137: rcv'd phase 1 notify, Invalid id info 192.168.0.55 03/12 10:07:42.042
<175>192.168.0.55 timed_out-138: Retransmission timeout, count = 0 192.168.0.55 03/12 10:07:44.062
<175>192.168.0.55 got_info_xchg-137: rcv'd phase 1 notify, Invalid id info 192.168.0.55 03/12 10:07:44.165
<175>192.168.0.55 timed_out-138: Retransmission timeout, count = 1 192.168.0.55 03/12 10:07:46.161
<175>192.168.0.55 got_info_xchg-137: rcv'd phase 1 notify, Invalid id info 192.168.0.55 03/12 10:07:46.272
<175>192.168.0.55 timed_out-138: Retransmission timeout, count = 2 192.168.0.55 03/12 10:07:48.271
<175>192.168.0.55 got_info_xchg-137: rcv'd phase 1 notify, Invalid id info 192.168.0.55 03/12 10:07:48.374
<175>192.168.0.55 timed_out-138: Retransmission timeout, count = 3 192.168.0.55 03/12 10:07:49.371
<175>192.168.0.55 got_info_xchg-137: rcv'd phase 1 notify, Invalid id info 192.168.0.55 03/12 10:07:49.474
<175>192.168.0.55 timed_out-138: Retransmission timeout, count = 4 192.168.0.55 03/12 10:07:51.470
<171>192.168.0.55 vpnSetLastError-587: Error Encountered at 142 in IKMPD 192.168.0.55 03/12 10:07:51.472
<171>192.168.0.55 timed_out-143: IKE Phase1 no response 4 192.168.0.55 03/12 10:07:51.513
<171>192.168.0.55 vpnSetLastError-587: Error Encountered at 459 in IKECFG 192.168.0.55 03/12 10:07:51.514
<175>192.168.0.55 RestoreRealIP-98: DeInit of Virtual if not required 192.168.0.55 03/12 10:07:53.470
<174>192.168.0.55 SetupVPNTunnel-983: SetupIKEAndIPsecSAs Returned -2 192.168.0.55 03/12 10:07:53.474
<174>192.168.0.55 ike_msg_task-909: Exiting from ike_msg_task 192.168.0.55 03/12 10:07:53.546
Anyone have any ideas... On phone the phone and router I have the IKE ID set to "remote" and "USER-Fqdn" however it is not working. I know the FVS318 is not a 'supported' router but many people seem to have gotten it working. I'm trying to do this install on the cheap for these guys..
thanks