Quantcast
Channel: EdgeRouter topics
Viewing all articles
Browse latest Browse all 20028

IPSEC VPN issues Please Help!!!

$
0
0

Hello,

 

After about a week of running a new erlite with 1.9.0, the vpn suddenly went down.

 

The VPN is connected to an ERPRO 8 with 1.7.0 and in turn that router is connected to another ERLite running 1.9.0 withour issues.

 

When looking at the VPN connection one the ERLite is see it is stuck connecting.

show vpn ipsec sa

peer-104.244.2.50-tunnel-1: #1, CONNECTING, IKEv1, HASH HIDDEN
  local  '71.95.x.x' @ 71.95.x.x
  remote '%any' @ 104.244.x.x  AES_CBC-256/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_2048
  queued:  QUICK_MODE QUICK_MODE
  active:  ISAKMP_VENDOR MAIN_MODE

On the ERPro logs I see this

 

Oct 20 23:49:30	 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: sending encrypted notification PAYLOAD_MALFORMED to 71.95.x.x:500
Oct 20 23:49:30	 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: probable authentication failure (mismatch of preshared secrets?): malformed payload in packet
Oct 20 23:49:30	 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: next payload type of ISAKMP Identification Payload has an unknown value: 104
Oct 20 23:49:22	 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: sending encrypted notification PAYLOAD_MALFORMED to 71.95.x.x:500
Oct 20 23:49:22	 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: probable authentication failure (mismatch of preshared secrets?): malformed payload in packet
Oct 20 23:49:22	 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: next payload type of ISAKMP Identification Payload has an unknown value: 104
Oct 20 23:49:18	 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: sending encrypted notification PAYLOAD_MALFORMED to 71.95.x.x:500
Oct 20 23:49:18	 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: probable authentication failure (mismatch of preshared secrets?): malformed payload in packet
Oct 20 23:49:18	 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: next payload type of ISAKMP Identification Payload has an unknown value: 104
Oct 20 23:49:18	 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: multiple ipsec.secrets entries with distinct secrets match endpoints: first secret used
Oct 20 23:49:17	 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: NAT-Traversal: Result using RFC 3947: no NAT detected
Oct 20 23:49:17	 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: multiple ipsec.secrets entries with distinct secrets match endpoints: first secret used
Oct 20 23:49:17	 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: responding to Main Mode

I noticed where is said authentication failure, but everything matches


Viewing all articles
Browse latest Browse all 20028

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>