View Single Post
too's Avatar
Posts: 122 | Thanked: 135 times | Joined on Dec 2009 @ Helsinki
#32
Originally Posted by imagomundi View Post
Thx for the flowers



I don't have an Android device at hand for a few weeks. Maybe it is possible you have a look at it yourself? The user in the IPPhone-Forum said that he used a vpnc client downloaded from android market which he altered in the way I described before.

Unfortunately my local time is 7,5 hrs. behind Helsinki - so I can only answer when it is midnight or even later in Helsinki and it will always take two full days to post and answer. I try to speed this up a little answering from my office's PC.
Well, If you're not in hurry this speed is OK to me -- and I think we
don't need too many iterations to solve this...

Originally Posted by imagomundi View Post
I would guess one or the other problem and therefore ask:

1. What is the IPSec ID? I never saw such a data in none of my working NOKIA (Symbian) vpn clients and I do not see it in the vpn server's (FRITZBox) configuration either.
It might be that is server is not interested on any id then this
can be empty...

Originally Posted by imagomundi View Post
2. Is "IKE DH Group dh2" identical with "GROUP_DESCRIPTION_II: MODP_1024" or/and "GROUP_DESCRIPTION: MODP_1024" as in the working Nokia vpn client's configuration?
I will post the 701's vpn client config later
I'm lazy to check out atm. If everything else fails then let's look this
option further...

Originally Posted by imagomundi View Post

3. "Domain" is the DDNS domain of the gateway? If my gateway is "My.dyndns.org" the domain is "dyndns.org"?
Frankly I don't know what this is. Maybe some microsoft thing :O -- In
my config that is empty.

Originally Posted by imagomundi View Post

Finally: I read somewhere that the use of @ is not allowed in a vpnc user name? False or true?
No idea. My vpn[c] user name is just plain login name.

---

Anyway, I'll compile a vpnc binary where

IKE_ATTRIB_LIFE_DURATION = 3600 (instead of 2147483)

and draft-ietf-ipsec-nat-t-ike-03 code is patched in place
of draft-ietf-ipsec-nat-t-ike-02. Whenever I get it done
I put it avalable somewhere -- let's hope that is enough
to solve this issue.
 

The Following User Says Thank You to too For This Useful Post: