I have downloaded certificate to the PC and installed it and set up an IPSec client using windows built in function. Following the instruction at https://www.asus.com/support/faq/1044397/
I am using DDNS from Asus and use IKEv2 ( tried Automatic negotiation in the client also)
Error message in windows client Wrong parameter"
Log file in ASUS
ug 26 14:12:08 06[NET] received packet: from 77.xxx.229.252[51933] to 83.xxx.167.80[500] (1104 bytes)
Aug 26 14:12:08 06[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(FRAG_SUP) N(NATD_S_IP) N(NATD_D_IP) V V V V ]
Aug 26 14:12:08 06[IKE] received MS NT5 ISAKMPOAKLEY v9 vendor ID
Aug 26 14:12:08 06[IKE] received MS-Negotiation Discovery Capable vendor ID
Aug 26 14:12:08 06[IKE] received Vid-Initial-Contact vendor ID
Aug 26 14:12:08 06[ENC] received unknown vendor ID: 01:52:8b:bb:c0:06:96:12:18:49:ab:9a:1c:5b:2a:51:00:00:00:02
Aug 26 14:12:08 06[IKE] 77.xxx.229.252 is initiating an IKE_SA
Aug 26 14:12:08 06[CFG] selected proposal: IKE:AES_CBC_256/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024
Aug 26 14:12:08 06[IKE] remote host is behind NAT
Aug 26 14:12:08 06[IKE] sending cert request for "C=TW, O=ASUS, CN=ASUS RT-AX58U-5C48 Root CA"
Aug 26 14:12:08 06[ENC] generating IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) CERTREQ N(FRAG_SUP) N(CHDLESS_SUP) N(MULT_AUTH) V ]
Aug 26 14:12:08 06[NET] sending packet: from 83.xxx.167.80[500] to 77.xxx.229.252[51933] (373 bytes)
Aug 26 14:12:38 07[JOB] deleting half open IKE_SA with 77.xxx.229.252 after timeout
Getting really frustrated, have earlier also tried the other available protocols but none has been working
I am using DDNS from Asus and use IKEv2 ( tried Automatic negotiation in the client also)
Error message in windows client Wrong parameter"
Log file in ASUS
ug 26 14:12:08 06[NET] received packet: from 77.xxx.229.252[51933] to 83.xxx.167.80[500] (1104 bytes)
Aug 26 14:12:08 06[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(FRAG_SUP) N(NATD_S_IP) N(NATD_D_IP) V V V V ]
Aug 26 14:12:08 06[IKE] received MS NT5 ISAKMPOAKLEY v9 vendor ID
Aug 26 14:12:08 06[IKE] received MS-Negotiation Discovery Capable vendor ID
Aug 26 14:12:08 06[IKE] received Vid-Initial-Contact vendor ID
Aug 26 14:12:08 06[ENC] received unknown vendor ID: 01:52:8b:bb:c0:06:96:12:18:49:ab:9a:1c:5b:2a:51:00:00:00:02
Aug 26 14:12:08 06[IKE] 77.xxx.229.252 is initiating an IKE_SA
Aug 26 14:12:08 06[CFG] selected proposal: IKE:AES_CBC_256/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024
Aug 26 14:12:08 06[IKE] remote host is behind NAT
Aug 26 14:12:08 06[IKE] sending cert request for "C=TW, O=ASUS, CN=ASUS RT-AX58U-5C48 Root CA"
Aug 26 14:12:08 06[ENC] generating IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) CERTREQ N(FRAG_SUP) N(CHDLESS_SUP) N(MULT_AUTH) V ]
Aug 26 14:12:08 06[NET] sending packet: from 83.xxx.167.80[500] to 77.xxx.229.252[51933] (373 bytes)
Aug 26 14:12:38 07[JOB] deleting half open IKE_SA with 77.xxx.229.252 after timeout
Getting really frustrated, have earlier also tried the other available protocols but none has been working