[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: isakmpd problems



Colin Harford wrote:
> Did a few tests, upgraded one machine from 3.5 to 3.6, and found that my
> isakmpd users can no longer get in.  (Clients Netscreen Remote 8 aka
> Safenet 8).  
> 

snip

>         payload: NOTIFICATION len: 12
>             notification: UNEQUAL PAYLOAD LENGTHS [ttl 0] (id 1)
> 12:15:03.887383 XXX.XXX.XXX.214.500 > ZZZ.ZZZ.108.231.500:  [udp sum ok]
> isakmp v1.0 exchange INFO
>         cookie: c6db916e25ba46a8->0000000000000000 msgid: 00000000 len:
> 40
>         payload: NOTIFICATION len: 12
>             notification: UNEQUAL PAYLOAD LENGTHS [ttl 0] (id 1)
> 

obfuscating the IPs in your logs makes it impossible to debug. Resend 
with real IPs so we can read it. Use private addresses if that makes you 
feel better...