Hi, > ike=3des looks like a very simple proposal. This proposal is actually incomplete. An IKE proposal must contain an encryption and a integrity algorithm (or a combined mode algorithm), and a DH group. Try ike=3des-sha1-modp2048 instead. Regards Martin