<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec between HP - SUN servers in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481985#M562178</link>
    <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I have one question do you need to configure&lt;BR /&gt;all trafic between HP and SUN ?&lt;BR /&gt;I always configure only selected services (telnet, ssh etc..).</description>
    <pubDate>Thu, 10 Feb 2005 05:51:11 GMT</pubDate>
    <dc:creator>Slawomir Gora</dc:creator>
    <dc:date>2005-02-10T05:51:11Z</dc:date>
    <item>
      <title>IPSec between HP - SUN servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481974#M562167</link>
      <description>Hi,&lt;BR /&gt;have any one successfully configured IPSec for a HP-UX 11.00 and a Solaris 9 server? Will use this for backup thru a firewall. The test do not include the FW, that is the next step.&lt;BR /&gt;&lt;BR /&gt;The problem seems to be on the Sun box since I have successfully configured and connected to a W2K server from the HP box. There are no GUI for the IPSec on Solaris. I have followed an example from the "IPsec and IKE Administration Guide" from Sun (&lt;A href="http://docs-pdf.sun.com/817-2694/817-2694.pdf)." target="_blank"&gt;http://docs-pdf.sun.com/817-2694/817-2694.pdf).&lt;/A&gt; &lt;BR /&gt;When starting up the in.iked process in debug mode, I see that there are problem in Phase 1 (Phase 1 negotiation error: No proposal chosen)&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;BR /&gt;&lt;BR /&gt;//Fredric</description>
      <pubDate>Wed, 09 Feb 2005 07:30:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481974#M562167</guid>
      <dc:creator>Fredric Vådegård</dc:creator>
      <dc:date>2005-02-09T07:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec between HP - SUN servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481975#M562168</link>
      <description>Hi,&lt;BR /&gt;could you double-check your IKE policies.&lt;BR /&gt;That message would appear if policies have a security or encryption mismatch.&lt;BR /&gt;Are there any other messages before or after?&lt;BR /&gt;Regards</description>
      <pubDate>Wed, 09 Feb 2005 08:26:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481975#M562168</guid>
      <dc:creator>Peter Godron</dc:creator>
      <dc:date>2005-02-09T08:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec between HP - SUN servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481976#M562169</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;now I havn't the same problem, but it still donÂ´t work.&lt;BR /&gt;&lt;BR /&gt;I can see "ESP SPI=0x323 Replay=1" when snooping (Replay is counting up by one every) and running a telnet against the remote IP-address.&lt;BR /&gt;&lt;BR /&gt;Currently I use the following files&lt;BR /&gt;/etc/inet/ipsecinit.conf&lt;BR /&gt;/etc/inet/ike/config&lt;BR /&gt;/etc/inet/ipseckey&lt;BR /&gt;removed the /etc/inet/secret/ike.preshared, because it was not in the new example of setup I saw on &lt;A href="http://builder.com.com/5100-6372-1044095.html" target="_blank"&gt;http://builder.com.com/5100-6372-1044095.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;//Fredri</description>
      <pubDate>Wed, 09 Feb 2005 09:00:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481976#M562169</guid>
      <dc:creator>Fredric Vådegård</dc:creator>
      <dc:date>2005-02-09T09:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec between HP - SUN servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481977#M562170</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I'am using IPSEC between Solaris 9 and HPUX 11.0 and 11.11 but only in transport mode.&lt;BR /&gt;Maby you have problem with your preshared password - on Solaris it must be hex. &lt;BR /&gt;&lt;BR /&gt;Can you attach yours configs ?&lt;BR /&gt;HPUX: /var/adm/ipsec/polices.txt&lt;BR /&gt;Sol9: /etc/inet/ike/config&lt;BR /&gt;      /etc/inet/ipsecinit.conf&lt;BR /&gt;</description>
      <pubDate>Wed, 09 Feb 2005 09:14:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481977#M562170</guid>
      <dc:creator>Slawomir Gora</dc:creator>
      <dc:date>2005-02-09T09:14:54Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec between HP - SUN servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481978#M562171</link>
      <description>I have attached the requested files.&lt;BR /&gt;&lt;BR /&gt;HP: &lt;BR /&gt;server name - hpbup&lt;BR /&gt;Below I have listed what is used for the setup of HP/SUN in the policies.txt&lt;BR /&gt;begin filter hpbup_setest02&lt;BR /&gt;begin oakley isakmp_hpbup2&lt;BR /&gt;begin transform ESP-3DES-HMAC-SHA1&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;BR /&gt;&lt;BR /&gt;//Fredric</description>
      <pubDate>Wed, 09 Feb 2005 09:47:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481978#M562171</guid>
      <dc:creator>Fredric Vådegård</dc:creator>
      <dc:date>2005-02-09T09:47:03Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec between HP - SUN servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481979#M562172</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I think that your problem is in oakley group for in.iked daemon.&lt;BR /&gt;On HPUX you have oakley group 2&lt;BR /&gt;On Solaris you have oakley group 5&lt;BR /&gt;Your solaris polices are in old style try use my config:&lt;BR /&gt;&lt;BR /&gt;#########################&lt;BR /&gt;/etc/inet/ipsecinit.conf&lt;BR /&gt;&lt;BR /&gt;{ saddr 192.36.176.142&lt;BR /&gt;  daddr 192.36.176.216&lt;BR /&gt;} ipsec {&lt;BR /&gt;    encr_auth_algs md5&lt;BR /&gt;    encr_algs 3des&lt;BR /&gt;    sa shared&lt;BR /&gt;}&lt;BR /&gt;&lt;BR /&gt;#########################&lt;BR /&gt;/etc/inet/iked/config&lt;BR /&gt;p1_lifetime_secs 28800&lt;BR /&gt;p2_lifetime_secs 28800&lt;BR /&gt;&lt;BR /&gt;{&lt;BR /&gt;  label "hpbup_setest02"&lt;BR /&gt;  local_id_type ip&lt;BR /&gt;  local_addr   192.36.176.142&lt;BR /&gt;  remote_addr  192.36.176.216&lt;BR /&gt;&lt;BR /&gt;  p1_xform {&lt;BR /&gt;        auth_method preshared&lt;BR /&gt;        oakley_group 2&lt;BR /&gt;        auth_alg md5&lt;BR /&gt;#        encr_alg 3des-cbc - YOU CAN TRY THIS&lt;BR /&gt;        encr_alg 3des&lt;BR /&gt;        p1_lifetime_secs 28800&lt;BR /&gt;  }&lt;BR /&gt;  p2_lifetime_secs 28800&lt;BR /&gt;}&lt;BR /&gt;&lt;BR /&gt;#####################&lt;BR /&gt;If you want convert key from text to hex use my script:&lt;BR /&gt;&lt;BR /&gt;#!/bin/sh&lt;BR /&gt;&lt;BR /&gt;if [ "$1" = "" ]&lt;BR /&gt;then&lt;BR /&gt;   echo "usage `basename $0` keyfile"&lt;BR /&gt;   exit&lt;BR /&gt;fi&lt;BR /&gt;&lt;BR /&gt;OUTFILE="$1.hex"&lt;BR /&gt;&lt;BR /&gt;if [ -f $1 ]&lt;BR /&gt;then&lt;BR /&gt;  cat $1 | od -X | \&lt;BR /&gt;  awk '{printf "%s%s%s%s",$2,$3,$4,$5} END {printf "\n"}' |\&lt;BR /&gt;  sed -e 's/0a000000//g' &amp;gt; ${OUTFILE}&lt;BR /&gt;&lt;BR /&gt;  echo "Key is stored in ${OUTFILE}"&lt;BR /&gt;else&lt;BR /&gt;  echo "No such file $1"&lt;BR /&gt;fi&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;#end of file&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 09 Feb 2005 13:40:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481979#M562172</guid>
      <dc:creator>Slawomir Gora</dc:creator>
      <dc:date>2005-02-09T13:40:04Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec between HP - SUN servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481980#M562173</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;if you will have problems try to debug iked daemon:&lt;BR /&gt;&lt;BR /&gt;ikeadm -n set debug all /tmp/iked.log&lt;BR /&gt;&lt;BR /&gt;I know you can have problem with your communication when you will restart or flush keys on solaris site - no information is send to HP and HP will send encrypted packages to solaris and no negotiation until KEY TIMEOUT (in your example 28800) will happen.</description>
      <pubDate>Wed, 09 Feb 2005 13:46:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481980#M562173</guid>
      <dc:creator>Slawomir Gora</dc:creator>
      <dc:date>2005-02-09T13:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec between HP - SUN servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481981#M562174</link>
      <description>IPSec is also very fussy about the declarion of system hostnames, and IP-Addresses. Ensure that both machines really know each other by the exact canonical or alias hostnames, and that if you have amulti-homed hosts, data is arriving through the correct interfaces.</description>
      <pubDate>Thu, 10 Feb 2005 02:31:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481981#M562174</guid>
      <dc:creator>Andrew Cowan</dc:creator>
      <dc:date>2005-02-10T02:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec between HP - SUN servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481982#M562175</link>
      <description>Thank you for your help so far!&lt;BR /&gt;&lt;BR /&gt;I have changed the configuration files as you suggested. &lt;BR /&gt;I donÂ´t get any error msg when starting up the in.iked process, it even says "added rule hpbup_setest02", "config_update succeeded!".&lt;BR /&gt;But, as you wrote, I donÂ´t get any answear from hpbup when trying to telnet hpbup from setest02(SUN). &lt;BR /&gt;Should I wait 8h (28800sec) and see if works after the time_out?&lt;BR /&gt;&lt;BR /&gt;//Fre</description>
      <pubDate>Thu, 10 Feb 2005 04:24:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481982#M562175</guid>
      <dc:creator>Fredric Vådegård</dc:creator>
      <dc:date>2005-02-10T04:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec between HP - SUN servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481983#M562176</link>
      <description>This may sound really stupid but there isn't any IP netmask issues here are there? Re my earlier point: If one of the machines has the wrong netmask, or can be reached on a couple of interfaces, then IP-SEC will fail during the negotiation stage. The other thing you can try is to go to the lowest level of link first e.g. start with AH and no ESP, and see if that works with a really basic secret/key e.g. "test". If successful keep upping the authentication levels until it fails.&lt;BR /&gt;&lt;BR /&gt;Another idea. There aren't any hidden control characters or trailing spaces or tabs in your config files are there?&lt;BR /&gt;</description>
      <pubDate>Thu, 10 Feb 2005 04:58:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481983#M562176</guid>
      <dc:creator>Andrew Cowan</dc:creator>
      <dc:date>2005-02-10T04:58:41Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec between HP - SUN servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481984#M562177</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I have rebooted the SUN box (setest02).&lt;BR /&gt;I have attached the iked.log file, hopefully it is useful.&lt;BR /&gt;&lt;BR /&gt;I will check/test a more basic connection.&lt;BR /&gt;&lt;BR /&gt;//Fredric</description>
      <pubDate>Thu, 10 Feb 2005 05:16:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481984#M562177</guid>
      <dc:creator>Fredric Vådegård</dc:creator>
      <dc:date>2005-02-10T05:16:36Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec between HP - SUN servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481985#M562178</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I have one question do you need to configure&lt;BR /&gt;all trafic between HP and SUN ?&lt;BR /&gt;I always configure only selected services (telnet, ssh etc..).</description>
      <pubDate>Thu, 10 Feb 2005 05:51:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481985#M562178</guid>
      <dc:creator>Slawomir Gora</dc:creator>
      <dc:date>2005-02-10T05:51:11Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec between HP - SUN servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481986#M562179</link>
      <description>I will use the connection for backup (Data Protector, port 5555).</description>
      <pubDate>Thu, 10 Feb 2005 06:17:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481986#M562179</guid>
      <dc:creator>Fredric Vådegård</dc:creator>
      <dc:date>2005-02-10T06:17:01Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec between HP - SUN servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481987#M562180</link>
      <description>From this error message it looks like IP-SEC is unsure of what kind of IKE key to expect. Are you sure that you are not missing a parameter in the config file that explicity mentions a static key, and its format e.g. ASCII or HEX.&lt;BR /&gt;&lt;BR /&gt;I have seen this problem when connecting between two AIX boxes when using the GUI and entering exactly the same data on both. The only solution was to do all the configuration on ONE node and then export it. The export reverses the data. You could see if either Solaris or HP-UX provides such a utility and examine the XML files for strange characters or extra parameters?</description>
      <pubDate>Thu, 10 Feb 2005 06:23:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481987#M562180</guid>
      <dc:creator>Andrew Cowan</dc:creator>
      <dc:date>2005-02-10T06:23:02Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec between HP - SUN servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481988#M562181</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I had renamed the /etc/inet/secret/ike.preshared file. The file is now renamed. I assume that I must have the ike.preshared file, it holds the key. But still it don't work!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I would like to double check with you to see if I doing right after I have changed some of the config files.&lt;BR /&gt;&lt;BR /&gt;1) ipsecconf -f&lt;BR /&gt;2) ipsecconf -a /etc/inet/ipsecinit.conf&lt;BR /&gt;3) pkill in.iked&lt;BR /&gt;4) /usr/lib/inet/in.iked -d&lt;BR /&gt;5) ikeadm -n set debug all /tmp/iked.log&lt;BR /&gt;&lt;BR /&gt;I had a config file earlier called /etc/inet/ipseckey, that  removed. Should I have that file?&lt;BR /&gt;&lt;BR /&gt;I appreciate your help!&lt;BR /&gt;&lt;BR /&gt;//Fredric</description>
      <pubDate>Thu, 10 Feb 2005 06:52:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481988#M562181</guid>
      <dc:creator>Fredric Vådegård</dc:creator>
      <dc:date>2005-02-10T06:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec between HP - SUN servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481989#M562182</link>
      <description>YES - IT WORKS !!!!!!!!!!!&lt;BR /&gt;&lt;BR /&gt;I tried between 2 SUN boxes and get it working at once. Then I found out how to audit the trafic on the HP box and I got more information that lead me on the right target.&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;BR /&gt;&lt;BR /&gt;//Fredric</description>
      <pubDate>Thu, 10 Feb 2005 11:52:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ipsec-between-hp-sun-servers/m-p/3481989#M562182</guid>
      <dc:creator>Fredric Vådegård</dc:creator>
      <dc:date>2005-02-10T11:52:34Z</dc:date>
    </item>
  </channel>
</rss>

