Hello,
After about a week of running a new erlite with 1.9.0, the vpn suddenly went down.
The VPN is connected to an ERPRO 8 with 1.7.0 and in turn that router is connected to another ERLite running 1.9.0 withour issues.
When looking at the VPN connection one the ERLite is see it is stuck connecting.
show vpn ipsec sa peer-104.244.2.50-tunnel-1: #1, CONNECTING, IKEv1, HASH HIDDEN local '71.95.x.x' @ 71.95.x.x remote '%any' @ 104.244.x.x AES_CBC-256/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_2048 queued: QUICK_MODE QUICK_MODE active: ISAKMP_VENDOR MAIN_MODE
On the ERPro logs I see this
Oct 20 23:49:30 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: sending encrypted notification PAYLOAD_MALFORMED to 71.95.x.x:500 Oct 20 23:49:30 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: probable authentication failure (mismatch of preshared secrets?): malformed payload in packet Oct 20 23:49:30 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: next payload type of ISAKMP Identification Payload has an unknown value: 104 Oct 20 23:49:22 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: sending encrypted notification PAYLOAD_MALFORMED to 71.95.x.x:500 Oct 20 23:49:22 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: probable authentication failure (mismatch of preshared secrets?): malformed payload in packet Oct 20 23:49:22 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: next payload type of ISAKMP Identification Payload has an unknown value: 104 Oct 20 23:49:18 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: sending encrypted notification PAYLOAD_MALFORMED to 71.95.x.x:500 Oct 20 23:49:18 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: probable authentication failure (mismatch of preshared secrets?): malformed payload in packet Oct 20 23:49:18 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: next payload type of ISAKMP Identification Payload has an unknown value: 104 Oct 20 23:49:18 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: multiple ipsec.secrets entries with distinct secrets match endpoints: first secret used Oct 20 23:49:17 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: NAT-Traversal: Result using RFC 3947: no NAT detected Oct 20 23:49:17 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: multiple ipsec.secrets entries with distinct secrets match endpoints: first secret used Oct 20 23:49:17 pluto[10385]: "peer-71.95.x.x-tunnel-2" #52: responding to Main Mode
I noticed where is said authentication failure, but everything matches