Buongiorno a tutti, scusate ma ho avuto un po di difficoltà con le prove.
Ora sono riuscito grazie a varie guide a configurare PF Sense per il tunnel VPN, ma quando mi provo a connettere tramite IPAD il log mi restituisce questo
May 13 17:26:01 charon: 10[ENC] <6> parsed AGGRESSIVE request 0 [ SA KE No ID V V V V V V V V V V V V V V ]
May 13 17:26:01 charon: 10[IKE] <6> received FRAGMENTATION vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received FRAGMENTATION vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received NAT-T (RFC 3947) vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received NAT-T (RFC 3947) vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received draft-ietf-ipsec-nat-t-ike vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received draft-ietf-ipsec-nat-t-ike vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received draft-ietf-ipsec-nat-t-ike-08 vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received draft-ietf-ipsec-nat-t-ike-08 vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received draft-ietf-ipsec-nat-t-ike-07 vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received draft-ietf-ipsec-nat-t-ike-07 vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received draft-ietf-ipsec-nat-t-ike-06 vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received draft-ietf-ipsec-nat-t-ike-06 vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received draft-ietf-ipsec-nat-t-ike-05 vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received draft-ietf-ipsec-nat-t-ike-05 vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received draft-ietf-ipsec-nat-t-ike-04 vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received draft-ietf-ipsec-nat-t-ike-04 vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received draft-ietf-ipsec-nat-t-ike-03 vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received draft-ietf-ipsec-nat-t-ike-03 vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received draft-ietf-ipsec-nat-t-ike-02 vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received draft-ietf-ipsec-nat-t-ike-02 vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received draft-ietf-ipsec-nat-t-ike-02\n vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received draft-ietf-ipsec-nat-t-ike-02\n vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received XAuth vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received XAuth vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received Cisco Unity vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received Cisco Unity vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received DPD vendor ID
May 13 17:26:01 charon: 10[IKE] <6> received DPD vendor ID
May 13 17:26:01 charon: 10[IKE] <6> 5.170.213.123 is initiating a Aggressive Mode IKE_SA
May 13 17:26:01 charon: 10[IKE] <6> 5.170.213.123 is initiating a Aggressive Mode IKE_SA
May 13 17:26:01 charon: 10[CFG] <6> looking for XAuthInitPSK peer configs matching 192.168.0.115...5.170.213.123[
[email protected]]
May 13 17:26:01 charon: 10[CFG] <6> selected peer config "con1"
May 13 17:26:01 charon: 10[ENC] <con1|6> generating AGGRESSIVE response 0 [ SA KE No ID NAT-D NAT-D HASH V V V V V ]
May 13 17:26:01 charon: 10[NET] <con1|6> sending packet: from 192.168.0.115[500] to 5.170.213.123[19234] (432 bytes)
May 13 17:26:01 charon: 10[NET] <con1|6> received packet: from 5.170.213.123[19911] to 192.168.0.115[4500] (140 bytes)
May 13 17:26:01 charon: 10[ENC] <con1|6> parsed AGGRESSIVE request 0 [ HASH NAT-D NAT-D N(INITIAL_CONTACT) ]
May 13 17:26:01 charon: 10[IKE] <con1|6> local host is behind NAT, sending keep alives
May 13 17:26:01 charon: 10[IKE] <con1|6> local host is behind NAT, sending keep alives
May 13 17:26:01 charon: 10[IKE] <con1|6> remote host is behind NAT
May 13 17:26:01 charon: 10[IKE] <con1|6> remote host is behind NAT
May 13 17:26:01 charon: 10[ENC] <con1|6> generating TRANSACTION request 3076709618 [ HASH CPRQ(X_USER X_PWD) ]
May 13 17:26:01 charon: 10[NET] <con1|6> sending packet: from 192.168.0.115[4500] to 5.170.213.123[19911] (76 bytes)
May 13 17:26:05 charon: 10[IKE] <con1|6> sending retransmit 1 of request message ID 3076709618, seq 1
May 13 17:26:05 charon: 10[IKE] <con1|6> sending retransmit 1 of request message ID 3076709618, seq 1
May 13 17:26:05 charon: 10[NET] <con1|6> sending packet: from 192.168.0.115[4500] to 5.170.213.123[19911] (76 bytes)
May 13 17:26:12 charon: 10[IKE] <con1|6> sending retransmit 2 of request message ID 3076709618, seq 1
May 13 17:26:12 charon: 10[IKE] <con1|6> sending retransmit 2 of request message ID 3076709618, seq 1
May 13 17:26:12 charon: 10[NET] <con1|6> sending packet: from 192.168.0.115[4500] to 5.170.213.123[19911] (76 bytes)
e mi viene restituito l'errore "Autenticazione utente non riuscita".
Mentre se mi connetto tramite cellulare android mi restituisce questo
May 13 17:27:33 charon: 08[CFG] <7> looking for XAuthInitPSK peer configs matching 192.168.0.115...217.200.200.249[
[email protected]]
May 13 17:27:33 charon: 08[CFG] <7> selected peer config "con1"
May 13 17:27:33 charon: 08[ENC] <con1|7> generating AGGRESSIVE response 0 [ SA KE No ID NAT-D NAT-D HASH V V V V V ]
May 13 17:27:33 charon: 08[NET] <con1|7> sending packet: from 192.168.0.115[500] to 217.200.200.249[53507] (432 bytes)
May 13 17:27:35 charon: 08[NET] <con1|7> received packet: from 217.200.200.249[53507] to 192.168.0.115[500] (657 bytes)
May 13 17:27:35 charon: 08[IKE] <con1|7> received retransmit of request with ID 0, retransmitting response
May 13 17:27:35 charon: 08[IKE] <con1|7> received retransmit of request with ID 0, retransmitting response
May 13 17:27:35 charon: 08[NET] <con1|7> sending packet: from 192.168.0.115[500] to 217.200.200.249[53507] (432 bytes)
May 13 17:27:37 charon: 08[IKE] <con1|7> sending retransmit 1 of response message ID 0, seq 1
May 13 17:27:37 charon: 08[IKE] <con1|7> sending retransmit 1 of response message ID 0, seq 1
May 13 17:27:37 charon: 08[NET] <con1|7> sending packet: from 192.168.0.115[500] to 217.200.200.249[53507] (432 bytes)
May 13 17:27:44 charon: 08[IKE] <con1|7> sending retransmit 2 of response message ID 0, seq 1
May 13 17:27:44 charon: 08[IKE] <con1|7> sending retransmit 2 of response message ID 0, seq 1
May 13 17:27:44 charon: 08[NET] <con1|7> sending packet: from 192.168.0.115[500] to 217.200.200.249[53507] (432 bytes)
May 13 17:27:46 charon: 08[NET] <con1|7> received packet: from 217.200.200.249[53507] to 192.168.0.115[500] (657 bytes)
May 13 17:27:46 charon: 08[IKE] <con1|7> received retransmit of request with ID 0, retransmitting response
May 13 17:27:46 charon: 08[IKE] <con1|7> received retransmit of request with ID 0, retransmitting response
May 13 17:27:46 charon: 08[NET] <con1|7> sending packet: from 192.168.0.115[500] to 217.200.200.249[53507] (432 bytes)
May 13 17:27:46 charon: 08[NET] <con1|7> received packet: from 217.200.200.249[53507] to 192.168.0.115[500] (657 bytes)
May 13 17:27:46 charon: 08[IKE] <con1|7> received retransmit of request with ID 0, retransmitting response
May 13 17:27:46 charon: 08[IKE] <con1|7> received retransmit of request with ID 0, retransmitting response
May 13 17:27:46 charon: 08[NET] <con1|7> sending packet: from 192.168.0.115[500] to 217.200.200.249[53507] (432 bytes)
May 13 17:27:46 charon: 08[NET] <con1|7> received packet: from 217.200.200.249[53507] to 192.168.0.115[500] (657 bytes)
May 13 17:27:46 charon: 08[IKE] <con1|7> received retransmit of request with ID 0, retransmitting response
May 13 17:27:46 charon: 08[IKE] <con1|7> received retransmit of request with ID 0, retransmitting response
May 13 17:27:46 charon: 08[NET] <con1|7> sending packet: from 192.168.0.115[500] to 217.200.200.249[53507] (432 bytes)
May 13 17:27:46 charon: 08[NET] <con1|7> received packet: from 217.200.200.249[53507] to 192.168.0.115[500] (657 bytes)
May 13 17:27:46 charon: 08[IKE] <con1|7> received retransmit of request with ID 0, retransmitting response
May 13 17:27:46 charon: 08[IKE] <con1|7> received retransmit of request with ID 0, retransmitting response
May 13 17:27:46 charon: 08[NET] <con1|7> sending packet: from 192.168.0.115[500] to 217.200.200.249[53507] (432 bytes)
May 13 17:27:50 charon: 08[NET] <con1|7> received packet: from 217.200.200.249[53507] to 192.168.0.115[500] (657 bytes)
May 13 17:27:50 charon: 08[IKE] <con1|7> received retransmit of request with ID 0, retransmitting response
May 13 17:27:50 charon: 08[IKE] <con1|7> received retransmit of request with ID 0, retransmitting response
May 13 17:27:50 charon: 08[NET] <con1|7> sending packet: from 192.168.0.115[500] to 217.200.200.249[53507] (432 bytes)
May 13 17:27:54 charon: 08[NET] <con1|7> received packet: from 217.200.200.249[53507] to 192.168.0.115[500] (657 bytes)
May 13 17:27:54 charon: 08[IKE] <con1|7> received retransmit of request with ID 0, retransmitting response
May 13 17:27:54 charon: 08[IKE] <con1|7> received retransmit of request with ID 0, retransmitting response
May 13 17:27:54 charon: 08[NET] <con1|7> sending packet: from 192.168.0.115[500] to 217.200.200.249[53507] (432 bytes)
May 13 17:27:55 charon: 08[NET] <con1|7> received packet: from 217.200.200.249[53507] to 192.168.0.115[500] (657 bytes)
May 13 17:27:55 charon: 08[IKE] <con1|7> received retransmit of request with ID 0, retransmitting response
May 13 17:27:55 charon: 08[IKE] <con1|7> received retransmit of request with ID 0, retransmitting response
May 13 17:27:55 charon: 08[NET] <con1|7> sending packet: from 192.168.0.115[500] to 217.200.200.249[53507] (432 bytes)
May 13 17:27:57 charon: 06[IKE] <con1|7> sending retransmit 3 of response message ID 0, seq 1
May 13 17:27:57 charon: 06[IKE] <con1|7> sending retransmit 3 of response message ID 0, seq 1
May 13 17:27:57 charon: 06[NET] <con1|7> sending packet: from 192.168.0.115[500] to 217.200.200.249[53507] (432 bytes)
May 13 17:27:59 charon: 06[NET] <con1|7> received packet: from 217.200.200.249[53507] to 192.168.0.115[500] (657 bytes)
May 13 17:27:59 charon: 06[IKE] <con1|7> received retransmit of request with ID 0, retransmitting response
May 13 17:27:59 charon: 06[IKE] <con1|7> received retransmit of request with ID 0, retransmitting response
May 13 17:27:59 charon: 06[NET] <con1|7> sending packet: from 192.168.0.115[500] to 217.200.200.249[53507] (432 bytes)
May 13 17:28:03 charon: 06[JOB] <con1|7> deleting half open IKE_SA after timeout
Le impostazioni dei dispositivi sono le seguenti :
IPAD :
Server : il mio ip
Account : lo username creato in pfsense dal menu system > user manager
Password: la password impostata per lo username
Nome gruppo:
[email protected] (quello impostato nella creazione del tunner)
Segreto: la preshared key
PROXY : NO
CELLULARE ANDROID
Tipo : IPSec Xauth PSK
Indirizzo Server : il mio indirizzo ip statico
Identificatore IPSec
[email protected]
Chiave pre-condivisa IPSec: la chiave impostata nella configurazione del tunnel
Nome utente: lo username creato in pfsense dal menu system > user manager
Password: la password impostata per lo username
Mi sapete dire che cosa sbaglio ?
Sul firewall di PFSense ho creato la regola per permettere tutto nella rete IPSEC, nel router ADSL che mi fornisce la connessione ho impostato una DMZ verso il server che riesco a raggiungere dall'esterno...
Non so più che cosa provare....
Per la configurazione ho seguito questi passaggi
https://www.youtube.com/watch?v=_twNJHahAJU