• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

IPSec restarting and not working - log show multiple "queueing QUICK_MODE task" entries

Scheduled Pinned Locked Moved IPsec
ipsec
3 Posts 1 Posters 191 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    marcelosb
    last edited by Feb 14, 2025, 4:50 PM

    Hello!

    I am trying to establish an IPSec tunnel between my site, which does not have public IP, and a remote site that does have it.

    It seems to keep resetting, and does not work.

    "swanctl --list-sas" shows:

    con2: #1160, CONNECTING, IKEv1, 554723062153bfbe_i* 0000000000000000_r
    local 'BDD-2' @ 192.168.1.113[500]
    remote '%any' @ pu.bli.c.ip[500]
    queued: QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE QUICK_MODE
    active: ISAKMP_VENDOR ISAKMP_CERT_PRE AGGRESSIVE_MODE ISAKMP_CERT_POST ISAKMP_NATD

    Any ideas? I have a netgate 6100 running the latest firmware release, my IPSec is configured for IKE v1, aggressive.

    The status page is basically hung in this state, with SPIs changing every few seconds:
    2632dfde-f55f-4f8a-bd15-6209cd49dd3d-image.png

    The remote site is from a third party, I don't know which firewall they use. They sent me a print that may help identify it:
    82212d2b-b702-4bc7-ac83-3323a4fad3e5-image.png

    They say that they are receiving two phase 2 connection requests, and are getting hung on the second one, something like that.

    1 Reply Last reply Reply Quote 0
    • M
      marcelosb
      last edited by Feb 14, 2025, 4:54 PM

      Adding a wireshark capture of the WAN interface, showing that there is some sort of loop: the same messages keep being transmitted periodically.

      3fb2dc51-868e-463e-ae53-e879db23e178-image.png

      1 Reply Last reply Reply Quote 0
      • M
        marcelosb
        last edited by Feb 20, 2025, 11:25 AM

        Just for information to everyone, the problem was solved by changing (on both sides, of course) from IKE v1 to IKE v2.

        1 Reply Last reply Reply Quote 0
        3 out of 3
        • First post
          3/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received