У меня есть VPN с ноутбука с Windows 7 на MikroTik с использованием L2TP/IPSEC с NAT-T. Работает без NAT-T, но при использовании NAT-T появляется странная ошибка:
14:59:28 ipsec respond new phase 1 negotiation: 68.183.xxx.xxx[500]<=>67.169.xxx.xxx[500]
14:59:28 ipsec begin Identity Protection mode.
14:59:28 ipsec received broken Microsoft ID: MS NT5 ISAKMPOAKLEY
14:59:28 ipsec received Vendor ID: RFC 3947
14:59:28 ipsec received Vendor ID: draft-ietf-ipsec-nat-t-ike-02
14:59:28 ipsec
14:59:28 ipsec received Vendor ID: FRAGMENTATION
14:59:28 ipsec Selected NAT-T version: RFC 3947
14:59:28 ipsec invalid DH group 20.
14:59:28 ipsec invalid DH group 19.
14:59:28 ipsec Hashing 68.183.xxx.xxx[500] with algo #2
14:59:28 ipsec NAT-D payload #0 verified
14:59:28 ipsec Hashing 67.169.xxx.xxx[500] with algo #2
14:59:28 ipsec NAT-D payload #1 doesn't match
14:59:28 ipsec NAT detected: PEER
14:59:28 ipsec Hashing 67.169.xxx.xxx[500] with algo #2
14:59:28 ipsec Hashing 68.183.xxx.xxx[500] with algo #2
14:59:28 ipsec Adding remote and local NAT-D payloads.
14:59:28 ipsec NAT-T: ports changed to: 67.169.xxx.xxx[4500]<->68.183.xxx.xxx[4500]
14:59:28 ipsec KA list add: 68.183.xxx.xxx[4500]->67.169.xxx.xxx[4500]
14:59:28 ipsec ISAKMP-SA established 68.183.xxx.xxx[4500]-67.169.xxx.xxx[4500] spi:4ad7f89178310abd:5ca6f63efdbf1
b79
14:59:28 ipsec respond new phase 2 negotiation: 68.183.xxx.xxx[4500]<=>67.169.xxx.xxx[4500]
14:59:28 ipsec Update the generated policy : 192.168.1.101/32[1701] 68.183.xxx.xxx/32[1701] proto=udp dir=in
14:59:28 ipsec Adjusting my encmode UDP-Transport->Transport
14:59:28 ipsec Adjusting peer's encmode UDP-Transport(4)->Transport(2)
14:59:28 ipsec IPsec-SA established: ESP/Transport 67.169.xxx.xxx[4500]->68.183.xxx.xxx[4500] spi=76079680(0x488e
240)
14:59:28 ipsec IPsec-SA established: ESP/Transport 68.183.xxx.xxx[4500]->67.169.xxx.xxx[4500] spi=4062236856(0xf2
20d0b8)
14:59:28 ipsec the length in the isakmp header is too big.
14:59:29 ipsec the length in the isakmp header is too big.
14:59:31 ipsec the length in the isakmp header is too big.
14:59:35 ipsec the length in the isakmp header is too big. Есть какие-нибудь идеи, что делать с ошибкой "the length in the isakmp header is too big" ???
14:59:28 ipsec respond new phase 1 negotiation: 68.183.xxx.xxx[500]<=>67.169.xxx.xxx[500]
14:59:28 ipsec begin Identity Protection mode.
14:59:28 ipsec received broken Microsoft ID: MS NT5 ISAKMPOAKLEY
14:59:28 ipsec received Vendor ID: RFC 3947
14:59:28 ipsec received Vendor ID: draft-ietf-ipsec-nat-t-ike-02
14:59:28 ipsec
14:59:28 ipsec received Vendor ID: FRAGMENTATION
14:59:28 ipsec Selected NAT-T version: RFC 3947
14:59:28 ipsec invalid DH group 20.
14:59:28 ipsec invalid DH group 19.
14:59:28 ipsec Hashing 68.183.xxx.xxx[500] with algo #2
14:59:28 ipsec NAT-D payload #0 verified
14:59:28 ipsec Hashing 67.169.xxx.xxx[500] with algo #2
14:59:28 ipsec NAT-D payload #1 doesn't match
14:59:28 ipsec NAT detected: PEER
14:59:28 ipsec Hashing 67.169.xxx.xxx[500] with algo #2
14:59:28 ipsec Hashing 68.183.xxx.xxx[500] with algo #2
14:59:28 ipsec Adding remote and local NAT-D payloads.
14:59:28 ipsec NAT-T: ports changed to: 67.169.xxx.xxx[4500]<->68.183.xxx.xxx[4500]
14:59:28 ipsec KA list add: 68.183.xxx.xxx[4500]->67.169.xxx.xxx[4500]
14:59:28 ipsec ISAKMP-SA established 68.183.xxx.xxx[4500]-67.169.xxx.xxx[4500] spi:4ad7f89178310abd:5ca6f63efdbf1
b79
14:59:28 ipsec respond new phase 2 negotiation: 68.183.xxx.xxx[4500]<=>67.169.xxx.xxx[4500]
14:59:28 ipsec Update the generated policy : 192.168.1.101/32[1701] 68.183.xxx.xxx/32[1701] proto=udp dir=in
14:59:28 ipsec Adjusting my encmode UDP-Transport->Transport
14:59:28 ipsec Adjusting peer's encmode UDP-Transport(4)->Transport(2)
14:59:28 ipsec IPsec-SA established: ESP/Transport 67.169.xxx.xxx[4500]->68.183.xxx.xxx[4500] spi=76079680(0x488e
240)
14:59:28 ipsec IPsec-SA established: ESP/Transport 68.183.xxx.xxx[4500]->67.169.xxx.xxx[4500] spi=4062236856(0xf2
20d0b8)
14:59:28 ipsec the length in the isakmp header is too big.
14:59:29 ipsec the length in the isakmp header is too big.
14:59:31 ipsec the length in the isakmp header is too big.
14:59:35 ipsec the length in the isakmp header is too big. Есть какие-нибудь идеи, что делать с ошибкой "the length in the isakmp header is too big" ???
