Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can't connect IPSec if other IPSec connected

    Scheduled Pinned Locked Moved IPsec
    1 Posts 1 Posters 338 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      syafii404
      last edited by

      alt text
      I have 2 IPSec configuration connect to diffrent host.
      -IPSec A using algo (AES_CBC (256),HMAC_SHA2_256_128,PRF_HMAC_SHA2_256,MODP_2048)
      -IPSec B using algo (AES_CBC (128),HMAC_SHA1_96,PRF_HMAC_SHA1,MODP_1024)

      When IPSec A already ESTABLISHED, IPSec B can connect and ESTABLISHED too, so there are 2 Established IPSec connection.

      The problem is where IPSec B connected first and ESTABLISHED, IPSec A can't connect and stuck on CONNECTING. This condition also occurs if the connection IPSec A Reauth connection (Reauth after 21h established) its stuck on CONNECTING. So i have to disable both IPSec and enable&connect IPSec A first again. Reauth on IPSec B never get trouble.
      This log i have:
      15:44:12 charon 85442 07[IKE] <con100000|22> INFORMATIONAL_V1 request with message ID 2907093269 processing failed
      15:44:12 charon 85442 07[IKE] <con100000|22> ignore malformed INFORMATIONAL request
      15:44:12 charon 85442 07[IKE] <con100000|22> message verification failed
      15:44:12 charon 85442 07[ENC] <con100000|22> ignoring unprotected INFORMATIONAL from 139.XX.XX.XX
      15:44:12 charon 85442 07[ENC] <con100000|22> parsed INFORMATIONAL_V1 request 2907093269 [ N(PLD_MAL) ]
      15:44:12 charon 85442 07[NET] <con100000|22> received packet: from 139.XX.XX.XX[500] to 150.XX.XX.XX[500] (40 bytes)
      15:44:12 charon 85442 07[NET] <con100000|22> sending packet: from 150.XX.XX.XX[500] to 139.XX.XX.XX[500] (92 bytes)

      Can u help me to solve my problem, please?
      Thank you.

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.