<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[IPsec]]></title><description><![CDATA[Discussions about IPsec VPNs]]></description><link>https://forum.netgate.com/category/17</link><generator>RSS for Node</generator><lastBuildDate>Fri, 08 May 2026 09:50:51 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/category/17.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 06 May 2026 13:09:55 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[TCP traffic over IPSec stalls with some packets not appearing on enc0]]></title><description><![CDATA[@tinfoilmatt
Because using policy based it would be something like 30 phase2 entries and we had a problem where some of them would stop working at random.
Anyway, I found a solution to this.
Firewall State Policy - set to "Floating States" (default was "Interface Bound States" and apparently this default was different on the older pfsense version)
Now it seems to work
]]></description><link>https://forum.netgate.com/topic/200639/tcp-traffic-over-ipsec-stalls-with-some-packets-not-appearing-on-enc0</link><guid isPermaLink="true">https://forum.netgate.com/topic/200639/tcp-traffic-over-ipsec-stalls-with-some-packets-not-appearing-on-enc0</guid><dc:creator><![CDATA[Pentium100]]></dc:creator><pubDate>Wed, 06 May 2026 13:09:55 GMT</pubDate></item><item><title><![CDATA[IPsec tunnel is not allowing port 445 traffic]]></title><description><![CDATA[<p dir="auto">Hello...I have a tunnel bettwen to networks setup...I can ping and rdp on both sides of the network. However, on one side of the tunnel, port 445 (Microsoft) works; on the other side it does not work. I have rebuilt the IPSec tunnels...still an issue.</p>
]]></description><link>https://forum.netgate.com/topic/200597/ipsec-tunnel-is-not-allowing-port-445-traffic</link><guid isPermaLink="true">https://forum.netgate.com/topic/200597/ipsec-tunnel-is-not-allowing-port-445-traffic</guid><dc:creator><![CDATA[paulhds]]></dc:creator><pubDate>Sun, 26 Apr 2026 13:21:35 GMT</pubDate></item><item><title><![CDATA[IPSec Tunnel up but only half the remote IPs ping]]></title><description><![CDATA[<p dir="auto">I have created an IPsec Tunnel between to offices.<br />
Office A = 192.168.152.0/24<br />
Office B = 192.168.24.64/26</p>
<p dir="auto">I have no issues getting the tunnel connected.  I can ping and access the devices at 192.168.24.70 - 192.168.24.80 from Office A.  I am not able to access 192.168.24.90 - 192.168.24.110 from Office A.</p>
<p dir="auto">Currently for testing, I am using Allow All rules across the tunnels.</p>
<p dir="auto">I have no issues with my other tunnels from Office A.  They are using CIDR 24 subnets, similar to Office A.</p>
<p dir="auto">I don't know what I am missing.</p>
]]></description><link>https://forum.netgate.com/topic/200411/ipsec-tunnel-up-but-only-half-the-remote-ips-ping</link><guid isPermaLink="true">https://forum.netgate.com/topic/200411/ipsec-tunnel-up-but-only-half-the-remote-ips-ping</guid><dc:creator><![CDATA[Ryan Eback]]></dc:creator><pubDate>Wed, 25 Mar 2026 11:55:39 GMT</pubDate></item><item><title><![CDATA[IPv6 Leakage in IPsec Split-Tunneling (pfSense + FreeRADIUS)]]></title><description><![CDATA[<p dir="auto">Hi all,<br />
Client traffic leaks via IPv6, bypassing the tunnel because pfSense is configured only for IPv4.</p>
<p dir="auto">Setup:<br />
Client: Dual-stack (IPv4/IPv6).<br />
pfSense: IPv4-only, IPsec Split Tunneling  + FreeRADIUS.<br />
Server: Dual-stack (IPv4/IPv6).</p>
<p dir="auto">What is the best way to force IPv4 preference on the client side via pfSense/RADIUS settings? I need all traffic to the server to stay within the tunnel.<br />
Thanks for help.</p>
]]></description><link>https://forum.netgate.com/topic/200359/ipv6-leakage-in-ipsec-split-tunneling-pfsense-freeradius</link><guid isPermaLink="true">https://forum.netgate.com/topic/200359/ipv6-leakage-in-ipsec-split-tunneling-pfsense-freeradius</guid><dc:creator><![CDATA[0x44]]></dc:creator><pubDate>Sun, 15 Mar 2026 06:45:47 GMT</pubDate></item><item><title><![CDATA[IPsec Traffic Initiation Only Works In One Direction]]></title><description><![CDATA[I knew it had to be something stupid.
I had a block rule for "This Firewall" on my internal "WAN" interface (not a real WAN) which was causing the ESP packets to be dropped on that interface.
It's always simple stuff like that lol, after literally weeks and hours of troubleshooting thinking there is no way my config is wrong.
Anyway, if anyone finds this later, check that you don't have block rules on the interface that the ESP packets arrive on.
]]></description><link>https://forum.netgate.com/topic/200344/ipsec-traffic-initiation-only-works-in-one-direction</link><guid isPermaLink="true">https://forum.netgate.com/topic/200344/ipsec-traffic-initiation-only-works-in-one-direction</guid><dc:creator><![CDATA[planedrop]]></dc:creator><pubDate>Fri, 13 Mar 2026 02:47:31 GMT</pubDate></item><item><title><![CDATA[IPSec With Multi WAN Failover Works Until Main WAN Restored]]></title><description><![CDATA[<p dir="auto">I have site A and site B. Site A has two WANs setup with failover group routing. WAN1 on tier 1, WAN 2 on tier 2 using dynamic DNS. Site B has one WAN and has IPSec configured to connect to site A's DDNS address.</p>
<p dir="auto">This starts out fine and when site A's main WAN1 goes down, the tunnel switches over quickly to WAN2 without site B knowing anything different.</p>
<p dir="auto">The problem is when site A's WAN1 is restored, pfSense does not rebuild the tunnel back to WAN1 and the tunnel is still connected through WAN2. IPSec traffic does not pass at this point even with WAN2 connection up. If I change site A's phase 1 "Gateway duplicates" to enable, traffic will pass. This option seems to be a problem because if the tunnel is still connected through WAN2 and WAN2 would go down, the tunnel appears still connected and does not re-establish the tunnel using the restored WAN1 connection. This may actually never happen, but it could...</p>
<p dir="auto">I can manually disconnect tunnel with both WANs up and a re-connection will select WAN1.</p>
<p dir="auto">Is there an option that would make site A's tunnel rebuild the connection back to WAN1 when WAN1 first gets restored?</p>
<p dir="auto">I believe I understand what it is supposed to do - From Netgate docs:</p>
<p dir="auto"><em>-</em>-<em>-</em>-<em>-</em>-<em>-</em>-<em>-</em>-<em>-</em>-<br />
Failover with Gateway Groups and Dynamic DNS</p>
<p dir="auto">IPsec can fail between multiple WANs, but it requires some coordination and relies upon gateway groups and dynamic DNS. If the first gateway goes down the tunnel will move to the next available WAN in the group. <strong>When the first WAN comes back up, the tunnel will be rebuilt there again</strong>.<br />
<em>-</em>-<em>-</em>-<em>-</em>-<em>-</em>-<em>-</em>-<em>-</em>-</p>
<p dir="auto">Thanks.</p>
]]></description><link>https://forum.netgate.com/topic/200284/ipsec-with-multi-wan-failover-works-until-main-wan-restored</link><guid isPermaLink="true">https://forum.netgate.com/topic/200284/ipsec-with-multi-wan-failover-works-until-main-wan-restored</guid><dc:creator><![CDATA[urbnsr]]></dc:creator><pubDate>Tue, 03 Mar 2026 22:28:47 GMT</pubDate></item><item><title><![CDATA[IPsec with NAT Requires Traffic Initiation From One Side?]]></title><description><![CDATA[To add to this, it seems that the packets are just never ending up on the IPsec interface of Site A.
I can see that the ESP packets are hitting the interface they should be on pfSense (it's not really  WAN but we can call it that), but they just don't actually get routed back through to the IPsec interface.
I am not sure what would be dropping them at this point though, seems the state table isn't being opened or something.
The SPD has the proper NATed subnet listed in it too so it's definitely correctly setup.
Am I crazy in thinking this should work? Since this basically 1:1 NATs every IP within the /24 subnets that I have setup, shouldn't traffic destined for any 172.16.51.xxx IP be translated over to the 10.10.12.xxx equivalent IP?
]]></description><link>https://forum.netgate.com/topic/200202/ipsec-with-nat-requires-traffic-initiation-from-one-side</link><guid isPermaLink="true">https://forum.netgate.com/topic/200202/ipsec-with-nat-requires-traffic-initiation-from-one-side</guid><dc:creator><![CDATA[planedrop]]></dc:creator><pubDate>Fri, 20 Feb 2026 00:32:49 GMT</pubDate></item><item><title><![CDATA[Locate OIDs for tracking IPSEC tunnel metrics]]></title><description><![CDATA[<p dir="auto">Hello...trying to find the specific OIDs for the IPSEC tunnel info and metrics. Pfsense docs don't have anything related to them. I ran snmpwalk against ".1.3.6.1.2.1" for standard MIB-II metrics.</p>
<p dir="auto">I'm tracking the SNMP interfaces right now but can't seem to find anything on IPSEC. is there a specific module I need to use?</p>
]]></description><link>https://forum.netgate.com/topic/200177/locate-oids-for-tracking-ipsec-tunnel-metrics</link><guid isPermaLink="true">https://forum.netgate.com/topic/200177/locate-oids-for-tracking-ipsec-tunnel-metrics</guid><dc:creator><![CDATA[cparks96]]></dc:creator><pubDate>Tue, 17 Feb 2026 16:28:30 GMT</pubDate></item><item><title><![CDATA[IPSEC tunnel problem with Linux boxes]]></title><description><![CDATA[Hi,
turns out the problem is with the mtu. Reducing it to 1400 solves the problem.
Best regards,
Mike
]]></description><link>https://forum.netgate.com/topic/200075/ipsec-tunnel-problem-with-linux-boxes</link><guid isPermaLink="true">https://forum.netgate.com/topic/200075/ipsec-tunnel-problem-with-linux-boxes</guid><dc:creator><![CDATA[miboco]]></dc:creator><pubDate>Wed, 04 Feb 2026 09:21:56 GMT</pubDate></item><item><title><![CDATA[IPSEC - VTI mode Failover with PBR]]></title><description><![CDATA[The quick answer is you'll need to set the IPsec Filter Mode to VTI to allow those interfaces to use reply-to so the response traffic will use the correct interface. Set it on both sides.
That will break any tunnel mode IPsec tunnels you may have, but if you don't have any, then it's only a positive change.
The more complicated answer is that you should really run a dynamic routing protocol like BGP between those routers using the FRR package so the routing changes in a more reliable and predictable manner and isn't relying on filter trickery to avoid asymmetric routing.
]]></description><link>https://forum.netgate.com/topic/200072/ipsec-vti-mode-failover-with-pbr</link><guid isPermaLink="true">https://forum.netgate.com/topic/200072/ipsec-vti-mode-failover-with-pbr</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Tue, 03 Feb 2026 20:07:53 GMT</pubDate></item><item><title><![CDATA[Ipsec VPN connected but cannot ping from either side]]></title><description><![CDATA[<p dir="auto">We have a new SG-1100 and trying to get a VPN using ipsec to an openswan 2.6 and IKE v1.  We can get both phases to connect but no luck with any traffic between them.  We have tried adding  ipsec rules in the firewall with no luck.  Is there something we might have missed.  Desperate to gt this working</p>
<p dir="auto">Thanks</p>
]]></description><link>https://forum.netgate.com/topic/200019/ipsec-vpn-connected-but-cannot-ping-from-either-side</link><guid isPermaLink="true">https://forum.netgate.com/topic/200019/ipsec-vpn-connected-but-cannot-ping-from-either-side</guid><dc:creator><![CDATA[edlentz]]></dc:creator><pubDate>Wed, 28 Jan 2026 17:01:34 GMT</pubDate></item><item><title><![CDATA[IPSEC traffic become unidirectional and works fine when disabling firewall at pfsense]]></title><description><![CDATA[<p dir="auto">We have several IPSEC tunnel connecting to pfsense gateway, version used is 2.8.1-RELEASE (amd64), built on Tue Sep 9 16:29:00 UTC 2025, FreeBSD 15.0-CURRENT. We reinstall tunnels quite often, once in a while, one of the tunnel we see traffic going only in one direction which means, from remote endpoint traffic reached at pfsense but no traffic back. We are not added any explicit firewall rules, but initially when we reboot pfsense the problem disappear, later we found that disabling firewall could work. Can you please help me to understand more on this problem. Please let me know what more details needed.</p>
<p dir="auto">Thanks,<br />
Antony</p>
]]></description><link>https://forum.netgate.com/topic/199993/ipsec-traffic-become-unidirectional-and-works-fine-when-disabling-firewall-at-pfsense</link><guid isPermaLink="true">https://forum.netgate.com/topic/199993/ipsec-traffic-become-unidirectional-and-works-fine-when-disabling-firewall-at-pfsense</guid><dc:creator><![CDATA[antonyms]]></dc:creator><pubDate>Mon, 26 Jan 2026 12:11:46 GMT</pubDate></item><item><title><![CDATA[OpenVPN user access to networks behind IPSEC tunnels]]></title><description><![CDATA[@ivica.glavocic Check out this article from the documentation, Assigning OpenVPN Interfaces. That's one way to get OVPN traffic onto an interface that can then be NAT'ed to/from.
(This confusingly-named subsection, Allowing traffic over OpenVPN Tunnels, then becomes relevant, too.)
]]></description><link>https://forum.netgate.com/topic/199726/openvpn-user-access-to-networks-behind-ipsec-tunnels</link><guid isPermaLink="true">https://forum.netgate.com/topic/199726/openvpn-user-access-to-networks-behind-ipsec-tunnels</guid><dc:creator><![CDATA[tinfoilmatt]]></dc:creator><pubDate>Fri, 02 Jan 2026 11:51:59 GMT</pubDate></item><item><title><![CDATA[After Update to 25.11. trouble with ipsec vpn-to-vpn]]></title><description><![CDATA[<p dir="auto">After success update to 25.11. ipsec vpn-to-vpn (between two netgate-boxes), no changes, is established: file service works,  but no remote desktop works!</p>
<p dir="auto">also on OpenVPN all Client configuration lost! But it works and no state informations...</p>
]]></description><link>https://forum.netgate.com/topic/199658/after-update-to-25.11.-trouble-with-ipsec-vpn-to-vpn</link><guid isPermaLink="true">https://forum.netgate.com/topic/199658/after-update-to-25.11.-trouble-with-ipsec-vpn-to-vpn</guid><dc:creator><![CDATA[hsrtreml]]></dc:creator><pubDate>Tue, 23 Dec 2025 09:35:17 GMT</pubDate></item><item><title><![CDATA[External Users can&#x27;t reach IPSec Resources]]></title><description><![CDATA[@bh2026 not used IPSec myself but have you read through Netgate documentation: IPsec Site-to-Site VPN Example, Firewall Rules.
Are there firewall rules in place for the VPN clients to access?
]]></description><link>https://forum.netgate.com/topic/199630/external-users-can-t-reach-ipsec-resources</link><guid isPermaLink="true">https://forum.netgate.com/topic/199630/external-users-can-t-reach-ipsec-resources</guid><dc:creator><![CDATA[patient0]]></dc:creator><pubDate>Fri, 19 Dec 2025 22:08:30 GMT</pubDate></item><item><title><![CDATA[S2S IPSEC creates connections with duplicate reqids]]></title><description><![CDATA[@tinfoilmatt Both the connections use the same reqid. And that is the problem because the reqid is used for creating SAD/SPD entries. The result is that there are two SPD entries pointing to the same SAD entry which makes the formerly established connection not working because there are wrong encryption values used.
]]></description><link>https://forum.netgate.com/topic/199611/s2s-ipsec-creates-connections-with-duplicate-reqids</link><guid isPermaLink="true">https://forum.netgate.com/topic/199611/s2s-ipsec-creates-connections-with-duplicate-reqids</guid><dc:creator><![CDATA[rr247]]></dc:creator><pubDate>Thu, 18 Dec 2025 11:56:51 GMT</pubDate></item><item><title><![CDATA[source interface ip wrong]]></title><description><![CDATA[@jbates58 The right side connects to the left side?
The listener/server is site B here: https://docs.netgate.com/pfsense/en/latest/recipes/ipsec-s2s-psk.html#site-b and has a few differences like Child SA Start Action and LifeTime and Child SA Close Action.
I can see one end of a client's tunnel from here, and Dead Peer Detection is off for it; I want to say we did that on both ends but am not sure offhand.  On that router we have "Peer identifier" set to the FQDN of the other end.
]]></description><link>https://forum.netgate.com/topic/199547/source-interface-ip-wrong</link><guid isPermaLink="true">https://forum.netgate.com/topic/199547/source-interface-ip-wrong</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Fri, 12 Dec 2025 14:27:57 GMT</pubDate></item><item><title><![CDATA[Update]]></title><description><![CDATA[<p dir="auto">Update to this problem. I could not ping from the remote peer to the local peer again. This time I just disable (for testing) the "block all" rule and the remote peer was able to ping again.</p>
<p dir="auto">Interestingly, after I enable the "block all" rule again, the remote peer was still able to ping.<br />
I really don't know why this happens, but I will manually add a rule for the ESP protocol and see if this helps.</p>
<p dir="auto">Anyone an idea why this could happen?</p>
]]></description><link>https://forum.netgate.com/topic/199382/update</link><guid isPermaLink="true">https://forum.netgate.com/topic/199382/update</guid><dc:creator><![CDATA[thespirit]]></dc:creator><pubDate>Fri, 21 Nov 2025 08:41:12 GMT</pubDate></item><item><title><![CDATA[Concatenated IPsec VPN]]></title><description><![CDATA[@conbonbur Here's an option/idea from the docs using OpenVPN instead of IPsec:
OpenVPN Site-to-Site Configuration Example with SSL/TLS
'Hub and spoke' is the topology you're after—where Site A would be your so-called 'hub', and Sites B and C the so-called 'spokes'.
Pretty sure a hub-and-spoke topology could be accomplished with IPsec by implementing a particular NAT configuration and/or static routing.
But either way the short answer is: yes, it's possible.
]]></description><link>https://forum.netgate.com/topic/199371/concatenated-ipsec-vpn</link><guid isPermaLink="true">https://forum.netgate.com/topic/199371/concatenated-ipsec-vpn</guid><dc:creator><![CDATA[tinfoilmatt]]></dc:creator><pubDate>Thu, 20 Nov 2025 13:26:29 GMT</pubDate></item><item><title><![CDATA[Strange behavior with IPsec tunnel and ESP packets getting blocked]]></title><description><![CDATA[@femtosize Ohh yeah i see what you mean.
Yes I do agree, an info on the documentation would definitely help here!
In this case, this post can be considered as done.

]]></description><link>https://forum.netgate.com/topic/199370/strange-behavior-with-ipsec-tunnel-and-esp-packets-getting-blocked</link><guid isPermaLink="true">https://forum.netgate.com/topic/199370/strange-behavior-with-ipsec-tunnel-and-esp-packets-getting-blocked</guid><dc:creator><![CDATA[thespirit]]></dc:creator><pubDate>Thu, 20 Nov 2025 10:51:21 GMT</pubDate></item><item><title><![CDATA[Cato Networks to PFSense Site to Site VPN]]></title><description><![CDATA[<p dir="auto">Has anyone successfully setup a site to site ipsec vpn between Cato Networks and PFSense?</p>
<p dir="auto">We got phase 1 and phase 2 to come up but routing is not working.</p>
<p dir="auto">We are configured with IKEV2 and routed mode.</p>
<p dir="auto">We are not sure what IP to assign to the PFSense VTI Interface and what IP to use for the PFSense next hop.</p>
<p dir="auto">The Cato Management Application does not make this obvious. The CMA Only provides a native network subnet which is not a specific IP.</p>
]]></description><link>https://forum.netgate.com/topic/199364/cato-networks-to-pfsense-site-to-site-vpn</link><guid isPermaLink="true">https://forum.netgate.com/topic/199364/cato-networks-to-pfsense-site-to-site-vpn</guid><dc:creator><![CDATA[JustinMorse]]></dc:creator><pubDate>Wed, 19 Nov 2025 18:23:21 GMT</pubDate></item><item><title><![CDATA[Block with no log rule on WAN breaks IPsec rekeying]]></title><description><![CDATA[<p dir="auto">To stop the logs getting full of rubbish I added an explicit "block IPv4 any any" to the WAN interfaces on a pair of firewalls which are connected using an IPsec VPN.<br />
This seemed to work fine until the phase 2s tried to rekey.<br />
The rekeying failed and the whole VPN was ripped down and reestablished.</p>
<p dir="auto">Is that expected?</p>
<p dir="auto">Disabling the block rules made everything work properly again.</p>
<p dir="auto">Should I have added rules of allow IKE and ESP before the block rule? Or should the automatically added ones been enough?</p>
<p dir="auto">Where do the automatically generated IPsec rules end up in processing order?<br />
Is there a way I can see this?</p>
<p dir="auto">Is there a better way to stop the default block rules logging?</p>
]]></description><link>https://forum.netgate.com/topic/199348/block-with-no-log-rule-on-wan-breaks-ipsec-rekeying</link><guid isPermaLink="true">https://forum.netgate.com/topic/199348/block-with-no-log-rule-on-wan-breaks-ipsec-rekeying</guid><dc:creator><![CDATA[femtosize]]></dc:creator><pubDate>Tue, 18 Nov 2025 13:42:25 GMT</pubDate></item><item><title><![CDATA[Ipsec mobile with Radius NPS MFA]]></title><description><![CDATA[<p dir="auto">So, I have put hours to get this working and it works now. However, there is one part that I could not figure out.</p>
<p dir="auto">When I use Ipsec export apple profile and import this to my device, everything works beautifully, however, if I try to manually define the vpn settings on the IOS device, it just fails shortly after I try connecting.</p>
<p dir="auto">The point of the matter is for me to easily connect to this VPN with AD credentials and MFA. It will not help me as much if I need to import profile everytime.</p>
<p dir="auto">Checking the logs, I see that<br />
crypto proposal matches, everything going well, but after splitting packets the 2nd time, it times out. Traffic never reaches NPS.</p>
<pre><code>
Nov 14 18:46:12	charon	26343	09[IKE] &lt;con-mobile|17&gt; IKE_SA con-mobile[17] state change: CONNECTING =&gt; DESTROYING
Nov 14 18:46:12	charon	26343	09[JOB] &lt;con-mobile|17&gt; deleting half open IKE_SA with 5.156.97.144 after timeout
Nov 14 18:46:11	charon	26343	09[IKE] &lt;con-mobile|15&gt; IKE_SA con-mobile[15] state change: CONNECTING =&gt; DESTROYING
Nov 14 18:46:11	charon	26343	09[JOB] &lt;con-mobile|15&gt; deleting half open IKE_SA with 93.168.76.124 after timeout
Nov 14 18:46:02	charon	26343	09[IKE] &lt;con-mobile|15&gt; sending keep alive to 93.168.76.124[2973]
Nov 14 18:45:42	charon	26343	09[NET] &lt;con-mobile|17&gt; sending packet: from &lt;redacted IP&gt;[4500] to 5.156.97.144[4656] (1103 bytes)
Nov 14 18:45:42	charon	26343	09[NET] &lt;con-mobile|17&gt; sending packet: from &lt;redacted IP&gt;[4500] to 5.156.97.144[4656] (1248 bytes)
Nov 14 18:45:42	charon	26343	09[ENC] &lt;con-mobile|17&gt; generating IKE_AUTH response 1 [ EF(2/2) ]
Nov 14 18:45:42	charon	26343	09[ENC] &lt;con-mobile|17&gt; generating IKE_AUTH response 1 [ EF(1/2) ]
Nov 14 18:45:42	charon	26343	09[ENC] &lt;con-mobile|17&gt; splitting IKE message (2286 bytes) into 2 fragments
Nov 14 18:45:42	charon	26343	09[ENC] &lt;con-mobile|17&gt; generating IKE_AUTH response 1 [ IDr CERT CERT AUTH EAP/REQ/ID ]
Nov 14 18:45:42	charon	26343	09[IKE] &lt;con-mobile|17&gt; sending issuer cert "C=US, O=Let's Encrypt, CN=E7"
Nov 14 18:45:42	charon	26343	09[IKE] &lt;con-mobile|17&gt; sending end entity cert "CN=ipsec.domain.com"
Nov 14 18:45:42	charon	26343	09[IKE] &lt;con-mobile|17&gt; authentication of 'ipsec.domain.com' (myself) with ECDSA_WITH_SHA256_DER successful
Nov 14 18:45:42	charon	26343	09[IKE] &lt;con-mobile|17&gt; received ESP_TFC_PADDING_NOT_SUPPORTED, not using ESPv3 TFC padding
Nov 14 18:45:42	charon	26343	09[IKE] &lt;con-mobile|17&gt; peer supports MOBIKE
Nov 14 18:45:42	charon	26343	09[IKE] &lt;con-mobile|17&gt; processing INTERNAL_DNS_DOMAIN attribute
Nov 14 18:45:42	charon	26343	09[IKE] &lt;con-mobile|17&gt; processing INTERNAL_IP6_DNS attribute
Nov 14 18:45:42	charon	26343	09[IKE] &lt;con-mobile|17&gt; processing INTERNAL_IP6_DHCP attribute
Nov 14 18:45:42	charon	26343	09[IKE] &lt;con-mobile|17&gt; processing INTERNAL_IP6_ADDRESS attribute
Nov 14 18:45:42	charon	26343	09[IKE] &lt;con-mobile|17&gt; processing INTERNAL_IP4_DNS attribute
Nov 14 18:45:42	charon	26343	09[IKE] &lt;con-mobile|17&gt; processing INTERNAL_IP4_DHCP attribute
Nov 14 18:45:42	charon	26343	09[IKE] &lt;con-mobile|17&gt; processing INTERNAL_IP4_NETMASK attribute
Nov 14 18:45:42	charon	26343	09[IKE] &lt;con-mobile|17&gt; processing INTERNAL_IP4_ADDRESS attribute
Nov 14 18:45:42	charon	26343	09[IKE] &lt;con-mobile|17&gt; initiating EAP_IDENTITY method (id 0x00)
Nov 14 18:45:42	charon	26343	09[CFG] &lt;con-mobile|17&gt; selected peer config 'con-mobile'
Nov 14 18:45:42	charon	26343	09[CFG] &lt;17&gt; candidate "con-mobile", match: 20/1/1052 (me/other/ike)
Nov 14 18:45:42	charon	26343	09[CFG] &lt;17&gt; looking for peer configs matching &lt;redacted IP&gt;[ipsec.domain.com]...5.156.97.144[172.17.33.144]
Nov 14 18:45:42	charon	26343	09[IKE] &lt;17&gt; remote endpoint changed from 5.156.97.144[6848] to 5.156.97.144[4656]
Nov 14 18:45:42	charon	26343	09[IKE] &lt;17&gt; local endpoint changed from &lt;redacted IP&gt;[500] to &lt;redacted IP&gt;[4500]
Nov 14 18:45:42	charon	26343	09[ENC] &lt;17&gt; parsed IKE_AUTH request 1 [ IDi N(INIT_CONTACT) IDr CPRQ(ADDR MASK DHCP DNS ADDR6 DHCP6 DNS6 DOMAIN) N(ESP_TFC_PAD_N) N(NON_FIRST_FRAG) SA TSi TSr N(MOBIKE_SUP) ]
Nov 14 18:45:42	charon	26343	09[ENC] &lt;17&gt; unknown attribute type INTERNAL_DNS_DOMAIN
Nov 14 18:45:42	charon	26343	09[NET] &lt;17&gt; received packet: from 5.156.97.144[4656] to &lt;redacted IP&gt;[4500] (374 bytes)
Nov 14 18:45:42	charon	26343	13[NET] &lt;17&gt; sending packet: from &lt;redacted IP&gt;[500] to 5.156.97.144[6848] (509 bytes)
Nov 14 18:45:42	charon	26343	13[ENC] &lt;17&gt; generating IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) CERTREQ N(FRAG_SUP) N(HASH_ALG) N(CHDLESS_SUP) N(MULT_AUTH) ]
Nov 14 18:45:42	charon	26343	13[IKE] &lt;17&gt; sending cert request for "C=US, O=Let's Encrypt, CN=E8"
Nov 14 18:45:42	charon	26343	13[IKE] &lt;17&gt; sending cert request for "C=US, O=Let's Encrypt, CN=E7"
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; sending supported signature hash algorithms: sha256 sha384 sha512 identity
Nov 14 18:45:42	charon	26343	13[IKE] &lt;17&gt; remote host is behind NAT
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; received supported signature hash algorithms: sha512 sha384 sha256
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selected proposal: IKE:AES_GCM_16_256/PRF_HMAC_SHA2_256/MODP_2048
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; configured proposals: IKE:AES_GCM_16_256/PRF_HMAC_SHA2_256/MODP_4096, IKE:AES_GCM_16_256/PRF_HMAC_SHA2_512/ECP_384, IKE:AES_GCM_16_128/PRF_HMAC_SHA2_256/ECP_384, IKE:AES_GCM_16_128/PRF_HMAC_SHA2_256/ECP_256, IKE:AES_GCM_16_256/PRF_HMAC_SHA2_512/ECP_256, IKE:AES_GCM_16_256/PRF_HMAC_SHA2_256/MODP_2048
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; received proposals: IKE:AES_GCM_16_256/PRF_HMAC_SHA2_256/ECP_256/UNKNOWN_6_36, IKE:AES_GCM_16_256/PRF_HMAC_SHA2_256/MODP_2048/UNKNOWN_6_36, IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/ECP_256/UNKNOWN_6_36, IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_2048/UNKNOWN_6_36, IKE:AES_GCM_16_256/PRF_HMAC_SHA2_256/ECP_256, IKE:AES_GCM_16_256/PRF_HMAC_SHA2_256/MODP_2048, IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/ECP_256, IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_2048
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; proposal matches
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable KEY_EXCHANGE_METHOD found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable (6) found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable KEY_EXCHANGE_METHOD found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable PSEUDO_RANDOM_FUNCTION found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable PSEUDO_RANDOM_FUNCTION found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable PSEUDO_RANDOM_FUNCTION found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable PSEUDO_RANDOM_FUNCTION found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable PSEUDO_RANDOM_FUNCTION found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable PSEUDO_RANDOM_FUNCTION found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable PSEUDO_RANDOM_FUNCTION found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable PSEUDO_RANDOM_FUNCTION found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable KEY_EXCHANGE_METHOD found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable KEY_EXCHANGE_METHOD found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable KEY_EXCHANGE_METHOD found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; no acceptable KEY_EXCHANGE_METHOD found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[IKE] &lt;17&gt; IKE_SA (unnamed)[17] state change: CREATED =&gt; CONNECTING
Nov 14 18:45:42	charon	26343	13[IKE] &lt;17&gt; 5.156.97.144 is initiating an IKE_SA
Nov 14 18:45:42	charon	26343	13[IKE] &lt;17&gt; remote endpoint changed from 0.0.0.0 to 5.156.97.144[6848]
Nov 14 18:45:42	charon	26343	13[IKE] &lt;17&gt; local endpoint changed from 0.0.0.0[500] to &lt;redacted IP&gt;[500]
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; found matching ike config: &lt;redacted IP&gt;...0.0.0.0/0, ::/0 with prio 1052
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; candidate: &lt;redacted IP&gt;...0.0.0.0/0, ::/0, prio 1052
Nov 14 18:45:42	charon	26343	13[CFG] &lt;17&gt; looking for an IKEv2 config for &lt;redacted IP&gt;...5.156.97.144
Nov 14 18:45:42	charon	26343	13[ENC] &lt;17&gt; parsed IKE_SA_INIT request 0 [ SA KE No N(REDIR_SUP) N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) N(HASH_ALG) N((16438)) N((16438)) N((16438)) N((16438)) ]
Nov 14 18:45:42	charon	26343	13[NET] &lt;17&gt; received packet: from 5.156.97.144[6848] to &lt;redacted IP&gt;[500] (786 bytes)
Nov 14 18:45:42	charon	26343	13[IKE] &lt;16&gt; IKE_SA (unnamed)[16] state change: CONNECTING =&gt; DESTROYING
Nov 14 18:45:42	charon	26343	13[NET] &lt;16&gt; sending packet: from &lt;redacted IP&gt;[500] to 5.156.97.144[6848] (38 bytes)
Nov 14 18:45:42	charon	26343	13[ENC] &lt;16&gt; generating IKE_SA_INIT response 0 [ N(INVAL_KE) ]
Nov 14 18:45:42	charon	26343	13[IKE] &lt;16&gt; DH group ECP_256 unacceptable, requesting MODP_2048
Nov 14 18:45:42	charon	26343	13[IKE] &lt;16&gt; remote host is behind NAT
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; received supported signature hash algorithms: sha512 sha384 sha256
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selected proposal: IKE:AES_GCM_16_256/PRF_HMAC_SHA2_256/MODP_2048
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; configured proposals: IKE:AES_GCM_16_256/PRF_HMAC_SHA2_256/MODP_4096, IKE:AES_GCM_16_256/PRF_HMAC_SHA2_512/ECP_384, IKE:AES_GCM_16_128/PRF_HMAC_SHA2_256/ECP_384, IKE:AES_GCM_16_128/PRF_HMAC_SHA2_256/ECP_256, IKE:AES_GCM_16_256/PRF_HMAC_SHA2_512/ECP_256, IKE:AES_GCM_16_256/PRF_HMAC_SHA2_256/MODP_2048
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; received proposals: IKE:AES_GCM_16_256/PRF_HMAC_SHA2_256/ECP_256/UNKNOWN_6_36, IKE:AES_GCM_16_256/PRF_HMAC_SHA2_256/MODP_2048/UNKNOWN_6_36, IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/ECP_256/UNKNOWN_6_36, IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_2048/UNKNOWN_6_36, IKE:AES_GCM_16_256/PRF_HMAC_SHA2_256/ECP_256, IKE:AES_GCM_16_256/PRF_HMAC_SHA2_256/MODP_2048, IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/ECP_256, IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_2048
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; proposal matches
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable KEY_EXCHANGE_METHOD found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable (6) found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable KEY_EXCHANGE_METHOD found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable PSEUDO_RANDOM_FUNCTION found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable PSEUDO_RANDOM_FUNCTION found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable PSEUDO_RANDOM_FUNCTION found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable PSEUDO_RANDOM_FUNCTION found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable PSEUDO_RANDOM_FUNCTION found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable PSEUDO_RANDOM_FUNCTION found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable PSEUDO_RANDOM_FUNCTION found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable PSEUDO_RANDOM_FUNCTION found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable KEY_EXCHANGE_METHOD found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable KEY_EXCHANGE_METHOD found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable ENCRYPTION_ALGORITHM found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable KEY_EXCHANGE_METHOD found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; no acceptable KEY_EXCHANGE_METHOD found
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; selecting proposal:
Nov 14 18:45:42	charon	26343	13[IKE] &lt;16&gt; IKE_SA (unnamed)[16] state change: CREATED =&gt; CONNECTING
Nov 14 18:45:42	charon	26343	13[IKE] &lt;16&gt; 5.156.97.144 is initiating an IKE_SA
Nov 14 18:45:42	charon	26343	13[IKE] &lt;16&gt; remote endpoint changed from 0.0.0.0 to 5.156.97.144[6848]
Nov 14 18:45:42	charon	26343	13[IKE] &lt;16&gt; local endpoint changed from 0.0.0.0[500] to &lt;redacted IP&gt;[500]
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; found matching ike config: &lt;redacted IP&gt;...0.0.0.0/0, ::/0 with prio 1052
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; candidate: &lt;redacted IP&gt;...0.0.0.0/0, ::/0, prio 1052
Nov 14 18:45:42	charon	26343	13[CFG] &lt;16&gt; looking for an IKEv2 config for &lt;redacted IP&gt;...5.156.97.144
Nov 14 18:45:42	charon	26343	13[ENC] &lt;16&gt; parsed IKE_SA_INIT request 0 [ SA KE No N(REDIR_SUP) N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) N(HASH_ALG) N((16438)) N((16438)) N((16438)) N((16438)) ]
Nov 14 18:45:42	charon	26343	13[NET] &lt;16&gt; received packet: from 5.156.97.144[6848] to &lt;redacted IP&gt;[500] (594 bytes)
Nov 14 18:45:41	charon	26343	13[NET] &lt;con-mobile|15&gt; sending packet: from &lt;redacted IP&gt;[4500] to 93.168.76.124[2973] (1104 bytes)
Nov 14 18:45:41	charon	26343	13[NET] &lt;con-mobile|15&gt; sending packet: from &lt;redacted IP&gt;[4500] to 93.168.76.124[2973] (1248 bytes)
Nov 14 18:45:41	charon	26343	13[ENC] &lt;con-mobile|15&gt; generating IKE_AUTH response 1 [ EF(2/2) ]
Nov 14 18:45:41	charon	26343	13[ENC] &lt;con-mobile|15&gt; generating IKE_AUTH response 1 [ EF(1/2) ]
Nov 14 18:45:41	charon	26343	13[ENC] &lt;con-mobile|15&gt; splitting IKE message (2287 bytes) into 2 fragments
Nov 14 18:45:41	charon	26343	13[ENC] &lt;con-mobile|15&gt; generating IKE_AUTH response 1 [ IDr CERT CERT AUTH EAP/REQ/ID ]
Nov 14 18:45:41	charon	26343	13[IKE] &lt;con-mobile|15&gt; sending issuer cert "C=US, O=Let's Encrypt, CN=E7"
Nov 14 18:45:41	charon	26343	13[IKE] &lt;con-mobile|15&gt; sending end entity cert "CN=ipsec.domain.com"
Nov 14 18:45:41	charon	26343	13[IKE] &lt;con-mobile|15&gt; authentication of 'ipsec.domain.com' (myself) with ECDSA_WITH_SHA256_DER successful
Nov 14 18:45:41	charon	26343	13[IKE] &lt;con-mobile|15&gt; received ESP_TFC_PADDING_NOT_SUPPORTED, not using ESPv3 TFC padding
Nov 14 18:45:41	charon	26343	13[IKE] &lt;con-mobile|15&gt; peer supports MOBIKE
Nov 14 18:45:41	charon	26343	13[IKE] &lt;con-mobile|15&gt; processing INTERNAL_DNS_DOMAIN attribute
Nov 14 18:45:41	charon	26343	13[IKE] &lt;con-mobile|15&gt; processing INTERNAL_IP6_DNS attribute
Nov 14 18:45:41	charon	26343	13[IKE] &lt;con-mobile|15&gt; processing INTERNAL_IP6_DHCP attribute
Nov 14 18:45:41	charon	26343	13[IKE] &lt;con-mobile|15&gt; processing INTERNAL_IP6_ADDRESS attribute
Nov 14 18:45:41	charon	26343	13[IKE] &lt;con-mobile|15&gt; processing INTERNAL_IP4_DNS attribute
Nov 14 18:45:41	charon	26343	13[IKE] &lt;con-mobile|15&gt; processing INTERNAL_IP4_DHCP attribute
Nov 14 18:45:41	charon	26343	13[IKE] &lt;con-mobile|15&gt; processing INTERNAL_IP4_NETMASK attribute
Nov 14 18:45:41	charon	26343	13[IKE] &lt;con-mobile|15&gt; processing INTERNAL_IP4_ADDRESS attribute
Nov 14 18:45:41	charon	26343	13[IKE] &lt;con-mobile|15&gt; initiating EAP_IDENTITY method (id 0x00)
Nov 14 18:45:41	charon	26343	13[CFG] &lt;con-mobile|15&gt; selected peer config 'con-mobile'
Nov 14 18:45:41	charon	26343	13[CFG] &lt;15&gt; candidate "con-mobile", match: 20/1/1052 (me/other/ike)
Nov 14 18:45:41	charon	26343	13[CFG] &lt;15&gt; looking for peer configs matching &lt;redacted IP&gt;[ipsec.domain.com]...93.168.76.124[2001:16a2:c076:a93f:1cd8:1278:5e5:c7c]
Nov 14 18:45:41	charon	26343	13[IKE] &lt;15&gt; remote endpoint changed from 93.168.76.124[3890] to 93.168.76.124[2973]
Nov 14 18:45:41	charon	26343	13[IKE] &lt;15&gt; local endpoint changed from &lt;redacted IP&gt;[500] to &lt;redacted IP&gt;[4500]
Nov 14 18:45:41	charon	26343	13[ENC] &lt;15&gt; parsed IKE_AUTH request 1 [ IDi N(INIT_CONTACT) IDr CPRQ(ADDR MASK DHCP DNS ADDR6 DHCP6 DNS6 DOMAIN) N(ESP_TFC_PAD_N) N(NON_FIRST_FRAG) SA TSi TSr N(MOBIKE_SUP) ]
Nov 14 18:45:41	charon	26343	13[ENC] &lt;15&gt; unknown attribute type INTERNAL_DNS_DOMAIN
Nov 14 18:45:41	charon	26343	13[NET] &lt;15&gt; received packet: from 93.168.76.124[2973] to &lt;redacted IP&gt;[4500] (386 bytes)
Nov 14 18:45:41	charon	26343	13[NET] &lt;15&gt; sending packet: from &lt;redacted IP&gt;[500] to 93.168.76.124[3890] (509 bytes)
Nov 14 18:45:41	charon	26343	13[ENC] &lt;15&gt; generating IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) CERTREQ N(FRAG_SUP) N(HASH_ALG) N(CHDLESS_SUP) N(MULT_AUTH) ]
Nov 14 18:45:41	charon	26343	13[IKE] &lt;15&gt; sending cert request for "C=US, O=Let's Encrypt, CN=E8"
Nov 14 18:45:41	charon	26343	13[IKE] &lt;15&gt; sending cert request for "C=US, O=Let's Encrypt, CN=E7"
Nov 14 18:45:41	charon	26343	13[CFG] &lt;15&gt; sending supported signature hash algorithms: sha256 sha384 sha512 identity
Nov 14 18:45:41	charon	26343	13[IKE] &lt;15&gt; remote host is behind NAT
Nov 14 18:45:41	charon	26343	13[IKE] &lt;15&gt; local host is behind NAT, sending keep alives
Nov 14 18:45:41	charon	26343	13[CFG] &lt;15&gt; received supported signature hash algorithms: sha512 sha384 sha256
Nov 14 18:45:41	charon	26343	13[CFG] &lt;15&gt; selected proposal: IKE:AES_GCM_16_256/PRF_HMAC_SHA2_256/MODP_2048
Nov 14 18:45:41	charon	26343	13[CFG] &lt;15&gt; configured proposals: IKE:AES_GCM_16_256/PRF_HMAC_SHA2_256/MODP_4096, IKE:AES_GCM_16_256/PRF_HMAC_SHA2_512/ECP_384, IKE:AES_GCM_16_128/PRF_HMAC_SHA2_256/ECP_384, IKE:AES_GCM_16_128/PRF_HMAC_SHA2_256/ECP_256, IKE:AES_GCM_16_256/PRF_HMAC_SHA2_512/ECP_256, IKE:AES_GCM_16_256/PRF_HMAC_SHA2_256/MODP_2048
Nov 14 18:45:41	charon	26343	13[CFG] &lt;15&gt; received proposals: IKE:AES_GCM_16_256/PRF_HMAC_SHA2_256/ECP_256/UNKNOWN_6_36, IKE:AES_GCM_16_256/PRF_HMAC_SHA2_256/MODP_2048/UNKNOWN_6_36, IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/ECP_256/UNKNOWN_6_36, IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_2048/UNKNOWN_6_36, IKE:AES_GCM_16_256/PRF_HMAC_SHA2_256/ECP_256, IKE:AES_GCM_16_256/PRF_HMAC_SHA2_256/MODP_2048, IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/ECP_256, IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_2048
Nov 14 18:45:41	charon	26343	13[CFG] &lt;15&gt; proposal matches
</code></pre>
<p dir="auto">what am I missing here or do I absolutely have to use profile file?</p>
]]></description><link>https://forum.netgate.com/topic/199319/ipsec-mobile-with-radius-nps-mfa</link><guid isPermaLink="true">https://forum.netgate.com/topic/199319/ipsec-mobile-with-radius-nps-mfa</guid><dc:creator><![CDATA[Laxarus]]></dc:creator><pubDate>Fri, 14 Nov 2025 16:09:27 GMT</pubDate></item><item><title><![CDATA[Workaround needed for IPsec VTI limitation with dynamic remote gateways (0.0.0.0 not supported)]]></title><description><![CDATA[@Averlon Indeed.
There are valid use cases for both options.
Thanks for the feedback 
]]></description><link>https://forum.netgate.com/topic/199310/workaround-needed-for-ipsec-vti-limitation-with-dynamic-remote-gateways-0.0.0.0-not-supported</link><guid isPermaLink="true">https://forum.netgate.com/topic/199310/workaround-needed-for-ipsec-vti-limitation-with-dynamic-remote-gateways-0.0.0.0-not-supported</guid><dc:creator><![CDATA[mcury]]></dc:creator><pubDate>Wed, 12 Nov 2025 11:14:11 GMT</pubDate></item><item><title><![CDATA[IPsec VTI tunnel problem with multiple subnets]]></title><description><![CDATA[@HyperactiveSloth Hmm, my VTI tunnels status shows 0.0.0.0/0 as the network in both ends in order for me to assign what traffic goes down the tunnel (by assigning routes to the VTI Gateway created when the IPsec interface sis assigned).
Your IPsec status looks like a tunnelmode Phase 2, where the local/remote subnets are assigned in the Phase 2 settings.
Strange…. If it was tunnelmode I’m quite sure your issue is the “missing” split connections setting….
Guess I’m out of ideas :-(
]]></description><link>https://forum.netgate.com/topic/199303/ipsec-vti-tunnel-problem-with-multiple-subnets</link><guid isPermaLink="true">https://forum.netgate.com/topic/199303/ipsec-vti-tunnel-problem-with-multiple-subnets</guid><dc:creator><![CDATA[keyser]]></dc:creator><pubDate>Tue, 11 Nov 2025 17:22:37 GMT</pubDate></item></channel></rss>