IPsec IKEv2 for mobile clients : NO_PROPOSAL_CHOSEN
-
Hi,
I'm struggling with a first IPsec setup. I followed some standard guides, which resulted in the following config:
Phase 1 :
Phase 2 :
Mobile Client
And I've multiple PSK defined, each with a different identifier
On my windows 10 client :
servername = the same fqdn as specified as my identifier in the Phase 1 config
the PSK is one of the PSK's defined in the PSK tab on Pfsense
username and password, are a username and password as defined in the Pfsense local user manager, part of the vpngroup (with all 3 vpn privileges)Connection to the server is denied fairly quickly, and in the IPSEC log I see the following
(i tried with a W10 client and an iPad)
2022-02-19 19:00:16.941677+01:00 charon 89013 11[NET] <58> sending packet: from MYPUBLICPFSENSEIP[500] to MYPUBLICIPADIP[43062] (40 bytes) 2022-02-19 19:00:16.941659+01:00 charon 89013 11[ENC] <58> generating INFORMATIONAL_V1 request 2701915837 [ N(NO_PROP) ] 2022-02-19 19:00:16.941637+01:00 charon 89013 11[IKE] <58> no IKE config found for MYPUBLICPFSENSEIP...MYPUBLICIPADIP, sending NO_PROPOSAL_CHOSEN 2022-02-19 19:00:16.941615+01:00 charon 89013 11[ENC] <58> parsed AGGRESSIVE request 0 [ SA KE No ID V V V V V V V V V V V V V V ] 2022-02-19 19:00:16.941529+01:00 charon 89013 11[NET] <58> received packet: from MYPUBLICIPADIP[43062] to MYPUBLICPFSENSEIP[500] (767 bytes) 2022-02-19 19:00:16.832576+01:00 charon 89013 11[NET] <57> sending packet: from MYPUBLICPFSENSEIP[500] to MYPUBLICIPADIP[43062] (40 bytes) 2022-02-19 19:00:16.832557+01:00 charon 89013 11[ENC] <57> generating INFORMATIONAL_V1 request 2461767386 [ N(NO_PROP) ] 2022-02-19 19:00:16.832534+01:00 charon 89013 11[IKE] <57> no IKE config found for MYPUBLICPFSENSEIP...MYPUBLICIPADIP, sending NO_PROPOSAL_CHOSEN 2022-02-19 19:00:16.832513+01:00 charon 89013 11[ENC] <57> parsed AGGRESSIVE request 0 [ SA KE No ID V V V V V V V V V V V V V V ] 2022-02-19 19:00:16.832442+01:00 charon 89013 11[NET] <57> received packet: from MYPUBLICIPADIP[43062] to MYPUBLICPFSENSEIP[500] (767 bytes) 2022-02-19 18:58:24.222378+01:00 charon 89013 10[NET] <56> sending packet: from MYPUBLICPFSENSEIP[500] to MYPUBLICIPADIP[43062] (40 bytes) 2022-02-19 18:58:24.222359+01:00 charon 89013 10[ENC] <56> generating INFORMATIONAL_V1 request 2248372947 [ N(NO_PROP) ] 2022-02-19 18:58:24.222338+01:00 charon 89013 10[IKE] <56> no IKE config found for MYPUBLICPFSENSEIP...MYPUBLICIPADIP, sending NO_PROPOSAL_CHOSEN 2022-02-19 18:58:24.222318+01:00 charon 89013 10[ENC] <56> parsed AGGRESSIVE request 0 [ SA KE No ID V V V V V V V V V V V V V V ] 2022-02-19 18:58:24.222235+01:00 charon 89013 10[NET] <56> received packet: from MYPUBLICIPADIP[43062] to MYPUBLICPFSENSEIP[500] (767 bytes) 2022-02-19 18:58:24.071882+01:00 charon 89013 10[NET] <55> sending packet: from MYPUBLICPFSENSEIP[500] to MYPUBLICIPADIP[43062] (40 bytes) 2022-02-19 18:58:24.071863+01:00 charon 89013 10[ENC] <55> generating INFORMATIONAL_V1 request 3612128374 [ N(NO_PROP) ] 2022-02-19 18:58:24.071841+01:00 charon 89013 10[IKE] <55> no IKE config found for MYPUBLICPFSENSEIP...MYPUBLICIPADIP, sending NO_PROPOSAL_CHOSEN 2022-02-19 18:58:24.071820+01:00 charon 89013 10[ENC] <55> parsed AGGRESSIVE request 0 [ SA KE No ID V V V V V V V V V V V V V V ] 2022-02-19 18:58:24.071744+01:00 charon 89013 10[NET] <55> received packet: from MYPUBLICIPADIP[43062] to MYPUBLICPFSENSEIP[500] (767 bytes) 2022-02-19 18:56:55.499610+01:00 charon 89013 10[NET] <54> sending packet: from MYPUBLICPFSENSEIP[500] to MYPUBLICWINDOWS10IP[500] (40 bytes) 2022-02-19 18:56:55.499590+01:00 charon 89013 10[ENC] <54> generating INFORMATIONAL_V1 request 4162345199 [ N(NO_PROP) ] 2022-02-19 18:56:55.499567+01:00 charon 89013 10[IKE] <54> no IKE config found for MYPUBLICPFSENSEIP...MYPUBLICWINDOWS10IP, sending NO_PROPOSAL_CHOSEN 2022-02-19 18:56:55.499544+01:00 charon 89013 10[ENC] <54> parsed ID_PROT request 0 [ SA V V V V V V V V ] 2022-02-19 18:56:55.499477+01:00 charon 89013 10[NET] <54> received packet: from MYPUBLICWINDOWS10IP[500] to MYPUBLICPFSENSEIP[500] (408 bytes) 2022-02-19 18:56:52.484730+01:00 charon 89013 08[NET] <53> sending packet: from MYPUBLICPFSENSEIP[500] to MYPUBLICWINDOWS10IP[500] (40 bytes) 2022-02-19 18:56:52.484709+01:00 charon 89013 08[ENC] <53> generating INFORMATIONAL_V1 request 1812508062 [ N(NO_PROP) ] 2022-02-19 18:56:52.484683+01:00 charon 89013 08[IKE] <53> no IKE config found for MYPUBLICPFSENSEIP...MYPUBLICWINDOWS10IP, sending NO_PROPOSAL_CHOSEN 2022-02-19 18:56:52.484652+01:00 charon 89013 08[ENC] <53> parsed ID_PROT request 0 [ SA V V V V V V V V ] 2022-02-19 18:56:52.484576+01:00 charon 89013 08[NET] <53> received packet: from MYPUBLICWINDOWS10IP[500] to MYPUBLICPFSENSEIP[500] (408 bytes) 2022-02-19 18:56:51.478644+01:00 charon 89013 08[NET] <52> sending packet: from MYPUBLICPFSENSEIP[500] to MYPUBLICWINDOWS10IP[500] (40 bytes) 2022-02-19 18:56:51.478626+01:00 charon 89013 08[ENC] <52> generating INFORMATIONAL_V1 request 1614384759 [ N(NO_PROP) ] 2022-02-19 18:56:51.478604+01:00 charon 89013 08[IKE] <52> no IKE config found for MYPUBLICPFSENSEIP...MYPUBLICWINDOWS10IP, sending NO_PROPOSAL_CHOSEN 2022-02-19 18:56:51.478582+01:00 charon 89013 08[ENC] <52> parsed ID_PROT request 0 [ SA V V V V V V V V ] 2022-02-19 18:56:51.478522+01:00 charon 89013 08[NET] <52> received packet: from MYPUBLICWINDOWS10IP[500] to MYPUBLICPFSENSEIP[500] (408 bytes) 2022-02-19 18:56:50.473879+01:00 charon 89013 08[NET] <51> sending packet: from MYPUBLICPFSENSEIP[500] to MYPUBLICWINDOWS10IP[500] (40 bytes) 2022-02-19 18:56:50.473860+01:00 charon 89013 08[ENC] <51> generating INFORMATIONAL_V1 request 1592190133 [ N(NO_PROP) ] 2022-02-19 18:56:50.473837+01:00 charon 89013 08[IKE] <51> no IKE config found for MYPUBLICPFSENSEIP...MYPUBLICWINDOWS10IP, sending NO_PROPOSAL_CHOSEN 2022-02-19 18:56:50.473815+01:00 charon 89013 08[ENC] <51> parsed ID_PROT request 0 [ SA V V V V V V V V ] 2022-02-19 18:56:50.473742+01:00 charon 89013 08[NET] <51> received packet: from MYPUBLICWINDOWS10IP[500] to MYPUBLICPFSENSEIP[500] (408 bytes) 2022-02-19 18:56:45.802415+01:00 charon 89013 08[NET] <50> sending packet: from MYPUBLICPFSENSEIP[500] to MYPUBLICIPADIP[43062] (40 bytes) 2022-02-19 18:56:45.802393+01:00 charon 89013 08[ENC] <50> generating INFORMATIONAL_V1 request 167866232 [ N(NO_PROP) ] 2022-02-19 18:56:45.802365+01:00 charon 89013 08[IKE] <50> no IKE config found for MYPUBLICPFSENSEIP...MYPUBLICIPADIP, sending NO_PROPOSAL_CHOSEN 2022-02-19 18:56:45.802334+01:00 charon 89013 08[ENC] <50> parsed AGGRESSIVE request 0 [ SA KE No ID V V V V V V V V V V V V V V ] 2022-02-19 18:56:45.802218+01:00 charon 89013 08[NET] <50> received packet: from MYPUBLICIPADIP[43062] to MYPUBLICPFSENSEIP[500] (767 bytes) 2022-02-19 18:56:45.692835+01:00 charon 89013 08[NET] <49> sending packet: from MYPUBLICPFSENSEIP[500] to MYPUBLICIPADIP[43062] (40 bytes) 2022-02-19 18:56:45.692816+01:00 charon 89013 08[ENC] <49> generating INFORMATIONAL_V1 request 1477681132 [ N(NO_PROP) ] 2022-02-19 18:56:45.692793+01:00 charon 89013 08[IKE] <49> no IKE config found for MYPUBLICPFSENSEIP...MYPUBLICIPADIP, sending NO_PROPOSAL_CHOSEN 2022-02-19 18:56:45.692771+01:00 charon 89013 08[ENC] <49> parsed AGGRESSIVE request 0 [ SA KE No ID V V V V V V V V V V V V V V ] 2022-02-19 18:56:45.692693+01:00 charon 89013 08[NET] <49> received packet: from MYPUBLICIPADIP[43062] to MYPUBLICPFSENSEIP[500] (767 bytes) 2022-02-19 18:55:32.959101+01:00 charon 89013 08[NET] <48> sending packet: from MYPUBLICPFSENSEIP[500] to MYPUBLICWINDOWS10IP[500] (40 bytes) 2022-02-19 18:55:32.959083+01:00 charon 89013 08[ENC] <48> generating INFORMATIONAL_V1 request 2549539684 [ N(NO_PROP) ] 2022-02-19 18:55:32.959062+01:00 charon 89013 08[IKE] <48> no IKE config found for MYPUBLICPFSENSEIP...MYPUBLICWINDOWS10IP, sending NO_PROPOSAL_CHOSEN 2022-02-19 18:55:32.959041+01:00 charon 89013 08[ENC] <48> parsed ID_PROT request 0 [ SA V V V V V V V V ] 2022-02-19 18:55:32.958980+01:00 charon 89013 08[NET] <48> received packet: from MYPUBLICWINDOWS10IP[500] to MYPUBLICPFSENSEIP[500] (408 bytes) 2022-02-19 18:55:29.956929+01:00 charon 89013 08[NET] <47> sending packet: from MYPUBLICPFSENSEIP[500] to MYPUBLICWINDOWS10IP[500] (40 bytes) 2022-02-19 18:55:29.956911+01:00 charon 89013 08[ENC] <47> generating INFORMATIONAL_V1 request 1474883172 [ N(NO_PROP) ] 2022-02-19 18:55:29.956889+01:00 charon 89013 08[IKE] <47> no IKE config found for MYPUBLICPFSENSEIP...MYPUBLICWINDOWS10IP, sending NO_PROPOSAL_CHOSEN 2022-02-19 18:55:29.956867+01:00 charon 89013 08[ENC] <47> parsed ID_PROT request 0 [ SA V V V V V V V V ] 2022-02-19 18:55:29.956804+01:00 charon 89013 08[NET] <47> received packet: from MYPUBLICWINDOWS10IP[500] to MYPUBLICPFSENSEIP[500] (408 bytes) 2022-02-19 18:55:28.951082+01:00 charon 89013 08[NET] <46> sending packet: from MYPUBLICPFSENSEIP[500] to MYPUBLICWINDOWS10IP[500] (40 bytes) 2022-02-19 18:55:28.951064+01:00 charon 89013 08[ENC] <46> generating INFORMATIONAL_V1 request 3288034960 [ N(NO_PROP) ] 2022-02-19 18:55:28.951042+01:00 charon 89013 08[IKE] <46> no IKE config found for MYPUBLICPFSENSEIP...MYPUBLICWINDOWS10IP, sending NO_PROPOSAL_CHOSEN 2022-02-19 18:55:28.951020+01:00 charon 89013 08[ENC] <46> parsed ID_PROT request 0 [ SA V V V V V V V V ] 2022-02-19 18:55:28.950959+01:00 charon 89013 08[NET] <46> received packet: from MYPUBLICWINDOWS10IP[500] to MYPUBLICPFSENSEIP[500] (408 bytes) 2022-02-19 18:55:27.939210+01:00 charon 89013 08[NET] <45> sending packet: from MYPUBLICPFSENSEIP[500] to MYPUBLICWINDOWS10IP[500] (40 bytes) 2022-02-19 18:55:27.939191+01:00 charon 89013 08[ENC] <45> generating INFORMATIONAL_V1 request 1108241934 [ N(NO_PROP) ] 2022-02-19 18:55:27.939167+01:00 charon 89013 08[IKE] <45> no IKE config found for MYPUBLICPFSENSEIP...MYPUBLICWINDOWS10IP, sending NO_PROPOSAL_CHOSEN 2022-02-19 18:55:27.939146+01:00 charon 89013 08[ENC] <45> parsed ID_PROT request 0 [ SA V V V V V V V V ] 2022-02-19 18:55:27.939082+01:00 charon 89013 08[NET] <45> received packet: from MYPUBLICWINDOWS10IP[500] to MYPUBLICPFSENSEIP[500] (408 bytes) 2022-02-19 18:49:23.430502+01:00 charon 89013 13[NET] <44> sending packet: from MYPUBLICPFSENSEIP[500] to MYPUBLICWINDOWS10IP[500] (40 bytes) 2022-02-19 18:49:23.430484+01:00 charon 89013 13[ENC] <44> generating INFORMATIONAL_V1 request 1538841808 [ N(NO_PROP) ] 2022-02-19 18:49:23.430463+01:00 charon 89013 13[IKE] <44> no IKE config found for MYPUBLICPFSENSEIP...MYPUBLICWINDOWS10IP, sending NO_PROPOSAL_CHOSEN 2022-02-19 18:49:23.430441+01:00 charon 89013 13[ENC] <44> parsed ID_PROT request 0 [ SA V V V V V V V V ] 2022-02-19 18:49:23.430381+01:00 charon 89013 13[NET] <44> received packet: from MYPUBLICWINDOWS10IP[500] to MYPUBLICPFSENSEIP[500] (408 bytes) 2022-02-19 18:49:20.415427+01:00 charon 89013 13[NET] <43> sending packet: from MYPUBLICPFSENSEIP[500] to MYPUBLICWINDOWS10IP[500] (40 bytes) 2022-02-19 18:49:20.415409+01:00 charon 89013 13[ENC] <43> generating INFORMATIONAL_V1 request 922344318 [ N(NO_PROP) ] 2022-02-19 18:49:20.415387+01:00 charon 89013 13[IKE] <43> no IKE config found for MYPUBLICPFSENSEIP...MYPUBLICWINDOWS10IP, sending NO_PROPOSAL_CHOSEN 2022-02-19 18:49:20.415366+01:00 charon 89013 13[ENC] <43> parsed ID_PROT request 0 [ SA V V V V V V V V ] 2022-02-19 18:49:20.415305+01:00 charon 89013 13[NET] <43> received packet: from MYPUBLICWINDOWS10IP[500] to MYPUBLICPFSENSEIP[500] (408 bytes) 2022-02-19 18:49:19.408581+01:00 charon 89013 13[NET] <42> sending packet: from MYPUBLICPFSENSEIP[500] to MYPUBLICWINDOWS10IP[500] (40 bytes) 2022-02-19 18:49:19.408562+01:00 charon 89013 13[ENC] <42> generating INFORMATIONAL_V1 request 4033065449 [ N(NO_PROP) ] 2022-02-19 18:49:19.408542+01:00 charon 89013 13[IKE] <42> no IKE config found for MYPUBLICPFSENSEIP...MYPUBLICWINDOWS10IP, sending NO_PROPOSAL_CHOSEN 2022-02-19 18:49:19.408519+01:00 charon 89013 13[ENC] <42> parsed ID_PROT request 0 [ SA V V V V V V V V ] 2022-02-19 18:49:19.408456+01:00 charon 89013 13[NET] <42> received packet: from MYPUBLICWINDOWS10IP[500] to MYPUBLICPFSENSEIP[500] (408 bytes) 2022-02-19 18:49:18.410102+01:00 charon 89013 13[NET] <41> sending packet: from MYPUBLICPFSENSEIP[500] to MYPUBLICWINDOWS10IP[500] (40 bytes) 2022-02-19 18:49:18.410084+01:00 charon 89013 13[ENC] <41> generating INFORMATIONAL_V1 request 3164734148 [ N(NO_PROP) ] 2022-02-19 18:49:18.410061+01:00 charon 89013 13[IKE] <41> no IKE config found for MYPUBLICPFSENSEIP...MYPUBLICWINDOWS10IP, sending NO_PROPOSAL_CHOSEN 2022-02-19 18:49:18.410039+01:00 charon 89013 13[ENC] <41> parsed ID_PROT request 0 [ SA V V V V V V V V ] 2022-02-19 18:49:18.409976+01:00 charon 89013 13[NET] <41> received packet: from MYPUBLICWINDOWS10IP[500] to MYPUBLICPFSENSEIP[500] (408 bytes) 2022-02-19 18:45:59.701538+01:00 charon 89013 09[NET] <40> sending packet: from MYPUBLICPFSENSEIP[500] to MYPUBLICIPADIP[43062] (40 bytes) 2022-02-19 18:45:59.701522+01:00 charon 89013 09[ENC] <40> generating INFORMATIONAL_V1 request 2777294049 [ N(NO_PROP) ] 2022-02-19 18:45:59.701503+01:00 charon 89013 09[IKE] <40> no IKE config found for MYPUBLICPFSENSEIP...MYPUBLICIPADIP, sending NO_PROPOSAL_CHOSEN 2022-02-19 18:45:59.701486+01:00 charon 89013 09[ENC] <40> parsed AGGRESSIVE request 0 [ SA KE No ID V V V V V V V V V V V V V V ] 2022-02-19 18:45:59.701418+01:00 charon 89013 09[NET] <40> received packet: from MYPUBLICIPADIP[43062] to MYPUBLICPFSENSEIP[500] (767 bytes) 2022-02-19 18:45:59.592931+01:00 charon 89013 09[NET] <39> sending packet: from MYPUBLICPFSENSEIP[500] to MYPUBLICIPADIP[43062] (40 bytes) 2022-02-19 18:45:59.592912+01:00 charon 89013 09[ENC] <39> generating INFORMATIONAL_V1 request 3668057250 [ N(NO_PROP) ] 2022-02-19 18:45:59.592889+01:00 charon 89013 09[IKE] <39> no IKE config found for MYPUBLICPFSENSEIP...MYPUBLICIPADIP, sending NO_PROPOSAL_CHOSEN 2022-02-19 18:45:59.592867+01:00 charon 89013 09[ENC] <39> parsed AGGRESSIVE request 0 [ SA KE No ID V V V V V V V V V V V V V V ] 2022-02-19 18:45:59.592786+01:00 charon 89013 09[NET] <39> received packet: from MYPUBLICIPADIP[43062] to MYPUBLICPFSENSEIP[500] (767 bytes) 2022-02-19 18:45:03.102592+01:00 charon 89013 12[NET] <38> sending packet: from MYPUBLICPFSENSEIP[500] to MYPUBLICIPADIP[43062] (40 bytes) 2022-02-19 18:45:03.102574+01:00 charon 89013 12[ENC] <38> generating INFORMATIONAL_V1 request 2785358885 [ N(NO_PROP) ] 2022-02-19 18:45:03.102552+01:00 charon 89013 12[IKE] <38> no IKE config found for MYPUBLICPFSENSEIP...MYPUBLICIPADIP, sending NO_PROPOSAL_CHOSEN 2022-02-19 18:45:03.102531+01:00 charon 89013 12[ENC] <38> parsed AGGRESSIVE request 0 [ SA KE No ID V V V V V V V V V V V V V V ] 2022-02-19 18:45:03.102454+01:00 charon 89013 12[NET] <38> received packet: from MYPUBLICIPADIP[43062] to MYPUBLICPFSENSEIP[500] (767 bytes) 2022-02-19 18:45:02.992622+01:00 charon 89013 12[NET] <37> sending packet: from MYPUBLICPFSENSEIP[500] to MYPUBLICIPADIP[43062] (40 bytes) 2022-02-19 18:45:02.992604+01:00 charon 89013 12[ENC] <37> generating INFORMATIONAL_V1 request 588233418 [ N(NO_PROP) ] 2022-02-19 18:45:02.992582+01:00 charon 89013 12[IKE] <37> no IKE config found for MYPUBLICPFSENSEIP...MYPUBLICIPADIP, sending NO_PROPOSAL_CHOSEN 2022-02-19 18:45:02.992560+01:00 charon 89013 12[ENC] <37> parsed AGGRESSIVE request 0 [ SA KE No ID V V V V V V V V V V V V V V ] 2022-02-19 18:45:02.992483+01:00 charon 89013 12[NET] <37> received packet: from MYPUBLICIPADIP[43062] to MYPUBLICPFSENSEIP[500] (767 bytes)
What am I missing?
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.