<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Problemas IPSec]]></title><description><![CDATA[<p dir="auto">Boa tarde,</p>
<p dir="auto">Estou tendo problema ao configurar o PfSense natiado a partir de outro firewall como IPSec, segue cenário:</p>
<p dir="auto">Meu lado:<br />
IP 186.x.x.x<br />
Rede Local: 192.168.0.0/24<br />
PfSense: 192.168.0.10</p>
<p dir="auto">Outro lado:<br />
IP: 187.x.x.x<br />
ID Remoto: 192.168.4.30<br />
Rede remota: 172.25.54.0/29</p>
<p dir="auto">Estou obtendo o seguinte LOG:</p>
<pre><code>3[NET] sending packet: from 192.168.0.10[4500] to 187.x.x.x[4500] (108 bytes)
13[NET] &lt;con1000|57&gt;sending packet: from 192.168.0.10[4500] to 187.x.x.x[4500] (108 bytes)
07[NET] received packet: from 187.x.x.x[4500] to 192.168.0.10[4500] (92 bytes)
 07[NET] &lt;con1000|57&gt;received packet: from 187.x.x.x[4500] to 192.168.0.10[4500] (92 bytes)
 07[ENC] parsed ID_PROT response 0 [ ID HASH V ]
 07[ENC] &lt;con1000|57&gt;parsed ID_PROT response 0 [ ID HASH V ]
 07[IKE] received DPD vendor ID
 07[IKE] &lt;con1000|57&gt;received DPD vendor ID
 07[IKE] IKE_SA con1000[57] established between 192.168.0.10[192.168.0.10]...187.x.x.x[192.168.4.30]
 07[IKE] &lt;con1000|57&gt;IKE_SA con1000[57] established between 192.168.0.10[192.168.0.10]...187.x.x.x[192.168.4.30]
 07[IKE] IKE_SA con1000[57] state change: CONNECTING =&gt; ESTABLISHED
 07[IKE] &lt;con1000|57&gt;IKE_SA con1000[57] state change: CONNECTING =&gt; ESTABLISHED
 07[IKE] scheduling reauthentication in 85704s
 07[IKE] &lt;con1000|57&gt;scheduling reauthentication in 85704s
 07[IKE] maximum IKE_SA lifetime 86244s
 07[IKE] &lt;con1000|57&gt;maximum IKE_SA lifetime 86244s
 07[IKE] activating new tasks
 07[IKE] &lt;con1000|57&gt;activating new tasks
 07[IKE] activating QUICK_MODE task
 07[IKE] &lt;con1000|57&gt;activating QUICK_MODE task
 07[CFG] configured proposals: ESP:AES_CBC_256/HMAC_SHA1_96/MODP_1536/NO_EXT_SEQ
 07[CFG] &lt;con1000|57&gt;configured proposals: ESP:AES_CBC_256/HMAC_SHA1_96/MODP_1536/NO_EXT_SEQ
 07[CFG] configured proposals: ESP:AES_CBC_256/HMAC_SHA1_96/MODP_1536/NO_EXT_SEQ
 07[CFG] &lt;con1000|57&gt;configured proposals: ESP:AES_CBC_256/HMAC_SHA1_96/MODP_1536/NO_EXT_SEQ
 07[CFG] proposing traffic selectors for us:
 07[CFG] &lt;con1000|57&gt;proposing traffic selectors for us:
 07[CFG] 192.168.0.25/32|/0
 07[CFG] &lt;con1000|57&gt;192.168.0.25/32|/0
 07[CFG] proposing traffic selectors for other:
 07[CFG] &lt;con1000|57&gt;proposing traffic selectors for other:
 07[CFG] 172.25.54.0/29|/0
 07[CFG] &lt;con1000|57&gt;172.25.54.0/29|/0
 07[ENC] generating QUICK_MODE request 2716593543 [ HASH SA No KE ID ID ]
 07[ENC] &lt;con1000|57&gt;generating QUICK_MODE request 2716593543 [ HASH SA No KE ID ID ]
 07[NET] sending packet: from 192.168.0.10[4500] to 187.x.x.x[4500] (380 bytes)
 07[NET] &lt;con1000|57&gt;sending packet: from 192.168.0.10[4500] to 187.x.x.x[4500] (380 bytes)
 07[NET] received packet: from 187.x.x.x[4500] to 192.168.0.10[4500] (428 bytes)
 07[NET] &lt;con1000|57&gt;received packet: from 187.x.x.x[4500] to 192.168.0.10[4500] (428 bytes)
 07[ENC] parsed INFORMATIONAL_V1 request 3928564372 [ HASH N(INVAL_ID) ]
 07[ENC] &lt;con1000|57&gt;parsed INFORMATIONAL_V1 request 3928564372 [ HASH N(INVAL_ID) ]
 07[IKE] received INVALID_ID_INFORMATION error notify
 07[IKE] &lt;con1000|57&gt;received INVALID_ID_INFORMATION error notify
 13[NET] received packet: from 187.x.x.x[4500] to 192.168.0.10[4500] (92 bytes)
 13[NET] &lt;con1000|57&gt;received packet: from 187.x.x.x[4500] to 192.168.0.10[4500] (92 bytes)
 13[ENC] parsed INFORMATIONAL_V1 request 1831796261 [ HASH D ]
 13[ENC] &lt;con1000|57&gt;parsed INFORMATIONAL_V1 request 1831796261 [ HASH D ]
 13[IKE] received DELETE for IKE_SA con1000[57]
 13[IKE] &lt;con1000|57&gt;received DELETE for IKE_SA con1000[57]
 13[IKE] deleting IKE_SA con1000[57] between 192.168.0.10[192.168.0.10]...187.x.x.x[192.168.4.30]
 13[IKE] &lt;con1000|57&gt;deleting IKE_SA con1000[57] between 192.168.0.10[192.168.0.10]...187.x.x.x[192.168.4.30]&lt;/con1000|57&gt;&lt;/con1000|57&gt;&lt;/con1000|57&gt;&lt;/con1000|57&gt;&lt;/con1000|57&gt;&lt;/con1000|57&gt;&lt;/con1000|57&gt;&lt;/con1000|57&gt;&lt;/con1000|57&gt;&lt;/con1000|57&gt;&lt;/con1000|57&gt;&lt;/con1000|57&gt;&lt;/con1000|57&gt;&lt;/con1000|57&gt;&lt;/con1000|57&gt;&lt;/con1000|57&gt;&lt;/con1000|57&gt;&lt;/con1000|57&gt;&lt;/con1000|57&gt;&lt;/con1000|57&gt;&lt;/con1000|57&gt;&lt;/con1000|57&gt;&lt;/con1000|57&gt;&lt;/con1000|57&gt;&lt;/con1000|57&gt; 
</code></pre>
]]></description><link>https://forum.netgate.com/topic/117916/problemas-ipsec</link><generator>RSS for Node</generator><lastBuildDate>Sat, 09 May 2026 20:44:05 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/117916.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 10 Jul 2017 20:18:54 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Problemas IPSec on Fri, 14 Jul 2017 12:12:13 GMT]]></title><description><![CDATA[<p dir="auto">Boa tarde,</p>
<p dir="auto">Resolvi o problema alterando a Local Network que estava incorreta. Porém comecei a ter problemas de roteamento, pois como funcionava:</p>
<p dir="auto">Estação(192.168.0.10)-&gt;REDE LOCAL (192.168.0.0) -&gt; IPSEC PFS (172.16.200.25/24) -&gt;TUNNEL&lt;- IPSEC CISCO ASA (172.25.54.0/29) &lt;- Rede CLIENTE (192.168.63.0)&lt;- ECliente (192.168.63.23)<br />
ESTAÇÃO &lt;–----------------------------------------------NAT PORTAS X,Y E Z PARA REDE LOCAL</p>
<p dir="auto">Mas porque não usa no IPSEC direto a rede local? Pois o cliente já possui outra empresa que tem rota para a rede 192.168.0.0, então tive que criar uma interface e fazer NAT para rede local.</p>
<p dir="auto">O cliente quando pingava para minha rede local, chegava certinho, pois ele tem uma rota assim: ip route 172.16.200.25/32 via 192.168.63.1.</p>
<p dir="auto">Do meu lado deixei sem rota, pensando que o IPSEC iria criar automaticamente, sem sucesso. Criei a rota destino -&gt; 172.25.54.0/29 gateway -&gt;172.16.200.25. Parava sempre na imagem a seguir.</p>
<p dir="auto">Enfim, para resolver, coloquei IP virtual direto no servidor na faixa 172.16.200.x e criei uma rota dizendo que todo pacote para rede 172.25.54.0/29 i gateway seria 172.16.200.25 e resolveu.</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/i90%5Ecimgpsh_orig.png" alt="i90^cimgpsh_orig.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/i90%5Ecimgpsh_orig.png_thumb" alt="i90^cimgpsh_orig.png_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/711300</link><guid isPermaLink="true">https://forum.netgate.com/post/711300</guid><dc:creator><![CDATA[nandoiin]]></dc:creator><pubDate>Fri, 14 Jul 2017 12:12:13 GMT</pubDate></item><item><title><![CDATA[Reply to Problemas IPSec on Wed, 12 Jul 2017 02:08:55 GMT]]></title><description><![CDATA[<p dir="auto">Já pesquisou o erro para ver alternativas de versão de ike, main, agressive, etc?</p>
<p dir="auto">https://wiki.strongswan.org/issues/819</p>
]]></description><link>https://forum.netgate.com/post/710784</link><guid isPermaLink="true">https://forum.netgate.com/post/710784</guid><dc:creator><![CDATA[marcelloc]]></dc:creator><pubDate>Wed, 12 Jul 2017 02:08:55 GMT</pubDate></item><item><title><![CDATA[Reply to Problemas IPSec on Tue, 11 Jul 2017 12:50:55 GMT]]></title><description><![CDATA[<p dir="auto">Alterei todos os identificadores e sempre acontece o mesmo problema.</p>
<p dir="auto">Resolvi colocar um IP válido no PfSense e fechar o tunnel direto com o outro lado. Com as mesmas configurações já avancei bastante, porém agora o IPSec conecta, fica em torno de 30 segundos e cai..</p>
<blockquote>
<p dir="auto">Jul 11 09:47:43 charon 05[IKE] &lt;con1000|4&gt;sending DPD request<br />
Jul 11 09:47:43 charon 05[IKE] &lt;con1000|4&gt;queueing ISAKMP_DPD task<br />
Jul 11 09:47:43 charon 05[IKE] &lt;con1000|4&gt;activating new tasks<br />
Jul 11 09:47:43 charon 05[IKE] &lt;con1000|4&gt;activating ISAKMP_DPD task<br />
Jul 11 09:47:43 charon 05[ENC] &lt;con1000|4&gt;generating INFORMATIONAL_V1 request 3271703021 [ HASH N(DPD) ]<br />
Jul 11 09:47:43 charon 05[NET] &lt;con1000|4&gt;sending packet: from 186.x.x.x[4500] to 187.x.x.x[4500] (92 bytes)<br />
Jul 11 09:47:43 charon 05[IKE] &lt;con1000|4&gt;activating new tasks<br />
Jul 11 09:47:43 charon 05[IKE] &lt;con1000|4&gt;nothing to initiate<br />
Jul 11 09:47:43 charon 05[NET] &lt;con1000|4&gt;received packet: from 187.x.x.x[4500] to 186.x.x.x.[4500] (92 bytes)<br />
Jul 11 09:47:43 charon 05[ENC] &lt;con1000|4&gt;parsed INFORMATIONAL_V1 request 4240920048 [ HASH N(DPD_ACK) ]<br />
Jul 11 09:47:43 charon 05[IKE] &lt;con1000|4&gt;activating new tasks<br />
Jul 11 09:47:43 charon 05[IKE] &lt;con1000|4&gt;nothing to initiate<br />
Jul 11 09:47:47 charon 05[NET] &lt;con1000|4&gt;received packet: from 187.x.x.x[4500] to 186.x.x.x[4500] (396 bytes)<br />
Jul 11 09:47:47 charon 05[ENC] &lt;con1000|4&gt;parsed QUICK_MODE request 378493840 [ HASH SA No KE ID ID N(INITIAL_CONTACT) ]<br />
Jul 11 09:47:47 charon 05[ENC] &lt;con1000|4&gt;received HASH payload does not match<br />
Jul 11 09:47:47 charon 05[IKE] &lt;con1000|4&gt;integrity check failed<br />
Jul 11 09:47:47 charon 05[ENC] &lt;con1000|4&gt;generating INFORMATIONAL_V1 request 2966470392 [ HASH N(INVAL_HASH) ]<br />
Jul 11 09:47:47 charon 05[NET] &lt;con1000|4&gt;sending packet: from 186.x.x.x[4500] to 187.x.x.x[4500] (76 bytes)<br />
Jul 11 09:47:47 charon 05[IKE] &lt;con1000|4&gt;QUICK_MODE request with message ID 378493840 processing failed<br />
Jul 11 09:47:47 charon 08[CFG] vici client 22 connected<br />
Jul 11 09:47:47 charon 08[CFG] vici client 22 registered for: list-sa<br />
Jul 11 09:47:47 charon 05[CFG] vici client 22 requests: list-sas<br />
Jul 11 09:47:47 charon 05[CFG] vici client 22 disconnected&lt;/con1000|4&gt;&lt;/con1000|4&gt;&lt;/con1000|4&gt;&lt;/con1000|4&gt;&lt;/con1000|4&gt;&lt;/con1000|4&gt;&lt;/con1000|4&gt;&lt;/con1000|4&gt;&lt;/con1000|4&gt;&lt;/con1000|4&gt;&lt;/con1000|4&gt;&lt;/con1000|4&gt;&lt;/con1000|4&gt;&lt;/con1000|4&gt;&lt;/con1000|4&gt;&lt;/con1000|4&gt;&lt;/con1000|4&gt;&lt;/con1000|4&gt;&lt;/con1000|4&gt;</p>
</blockquote>
<p dir="auto">Percebo que ele inicia a requisição do HASH e repois gera/recebe o Inval_Hash…. Então a VPN fica seus 30 segundos Established, cai e reconecta. O que pode ser?</p>
]]></description><link>https://forum.netgate.com/post/710655</link><guid isPermaLink="true">https://forum.netgate.com/post/710655</guid><dc:creator><![CDATA[nandoiin]]></dc:creator><pubDate>Tue, 11 Jul 2017 12:50:55 GMT</pubDate></item><item><title><![CDATA[Reply to Problemas IPSec on Tue, 11 Jul 2017 07:00:50 GMT]]></title><description><![CDATA[<p dir="auto">[HASH SA No KE ID ID ]</p>
<p dir="auto">[ HASH N(INVAL_ID)</p>
<p dir="auto">Tenta mudar os identificadores tanto remoto quanto local já que está passando por nat(s)</p>
]]></description><link>https://forum.netgate.com/post/710619</link><guid isPermaLink="true">https://forum.netgate.com/post/710619</guid><dc:creator><![CDATA[marcelloc]]></dc:creator><pubDate>Tue, 11 Jul 2017 07:00:50 GMT</pubDate></item><item><title><![CDATA[Reply to Problemas IPSec on Mon, 10 Jul 2017 21:02:41 GMT]]></title><description><![CDATA[<p dir="auto">Imagens</p>
<p dir="auto">![phase 1.jpg](/public/<em>imported_attachments</em>/1/phase 1.jpg)<br />
![phase 1.jpg_thumb](/public/<em>imported_attachments</em>/1/phase 1.jpg_thumb)<br />
<img src="/public/_imported_attachments_/1/geral.jpg" alt="geral.jpg" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/geral.jpg_thumb" alt="geral.jpg_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/710560</link><guid isPermaLink="true">https://forum.netgate.com/post/710560</guid><dc:creator><![CDATA[nandoiin]]></dc:creator><pubDate>Mon, 10 Jul 2017 21:02:41 GMT</pubDate></item></channel></rss>