<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Unable to get past P1 Authentication with PSK because of Aggressive mode on Yamaha RTX]]></title><description><![CDATA[<p dir="auto">I have Site A (pfsense, static IP) and Site B (Yamaha RTX-810, dynamic IP + DDNS).<br />
The Yamaha is trying to connect to the pfsense.</p>
<p dir="auto">The Yamaha has no choice but to do IKEv1 in Aggressive Mode. No matter how I configure the Phase 1 IDs, I can't get this to authenticate!</p>
<pre><code>12[NET] &lt;4&gt; received packet: from 118.8.30.73[500] to 180.43.61.110[500] (328 bytes)
Jul 1 18:27:43	charon		12[ENC] &lt;4&gt; parsed AGGRESSIVE request 0 [ SA KE No ID V ]
Jul 1 18:27:43	charon		12[CFG] &lt;4&gt; looking for an ike config for 180.43.61.110...118.8.30.73
Jul 1 18:27:43	charon		12[CFG] &lt;4&gt; candidate: %any...%any, prio 24
Jul 1 18:27:43	charon		12[CFG] &lt;4&gt; candidate: 180.43.61.110...kai-annex.aa0.netvolante.jp, prio 3100
Jul 1 18:27:43	charon		12[CFG] &lt;4&gt; found matching ike config: 180.43.61.110...kai-annex.aa0.netvolante.jp with prio 3100
Jul 1 18:27:43	charon		12[IKE] &lt;4&gt; received DPD vendor ID
Jul 1 18:27:43	charon		12[IKE] &lt;4&gt; 118.8.30.73 is initiating a Aggressive Mode IKE_SA
Jul 1 18:27:43	charon		12[IKE] &lt;4&gt; IKE_SA (unnamed)[4] state change: CREATED =&gt; CONNECTING
Jul 1 18:27:43	charon		12[CFG] &lt;4&gt; selecting proposal:
Jul 1 18:27:43	charon		12[CFG] &lt;4&gt; proposal matches
Jul 1 18:27:43	charon		12[CFG] &lt;4&gt; received proposals: IKE:AES_CBC_128/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024
Jul 1 18:27:43	charon		12[CFG] &lt;4&gt; configured proposals: IKE:AES_CBC_128/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024
Jul 1 18:27:43	charon		12[CFG] &lt;4&gt; selected proposal: IKE:AES_CBC_128/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024
Jul 1 18:27:43	charon		12[CFG] &lt;4&gt; looking for pre-shared key peer configs matching 180.43.61.110...118.8.30.73[d1:d4:3f:33:b6:75:17:99:47:06:0e:61:d9:44:93:1c]
Jul 1 18:27:43	charon		12[CFG] &lt;4&gt; candidate "bypasslan", match: 1/1/24 (me/other/ike)
Jul 1 18:27:43	charon		12[IKE] &lt;4&gt; found 1 matching config, but none allows pre-shared key authentication using Aggressive Mode
Jul 1 18:27:43	charon		12[IKE] &lt;4&gt; queueing INFORMATIONAL task
Jul 1 18:27:43	charon		12[IKE] &lt;4&gt; activating new tasks
Jul 1 18:27:43	charon		12[IKE] &lt;4&gt; activating INFORMATIONAL task
Jul 1 18:27:43	charon		12[ENC] &lt;4&gt; generating INFORMATIONAL_V1 request 3541139542 [ N(AUTH_FAILED) ]
Jul 1 18:27:43	charon		12[NET] &lt;4&gt; sending packet: from 180.43.61.110[500] to 118.8.30.73[500] (56 bytes)
Jul 1 18:27:43	charon		12[IKE] &lt;4&gt; IKE_SA (unnamed)[4] state change: CONNECTING =&gt; DESTROYING
</code></pre>
]]></description><link>https://forum.netgate.com/topic/132403/unable-to-get-past-p1-authentication-with-psk-because-of-aggressive-mode-on-yamaha-rtx</link><generator>RSS for Node</generator><lastBuildDate>Thu, 05 Mar 2026 14:47:08 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/132403.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 01 Jul 2018 09:32:02 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Unable to get past P1 Authentication with PSK because of Aggressive mode on Yamaha RTX on Sun, 01 Jul 2018 09:46:23 GMT]]></title><description><![CDATA[<p dir="auto">Specifically:</p>
<p dir="auto"><strong>found 1 matching config, but none allows pre-shared key authentication using Aggressive Mode</strong></p>
<p dir="auto">If my P1 entry is doing Aggressive with PSK for the "My IP address" and "Peer IP address" and it matches my proposals for hash and encryption...why can't it recognize my PSK?</p>
]]></description><link>https://forum.netgate.com/post/774900</link><guid isPermaLink="true">https://forum.netgate.com/post/774900</guid><dc:creator><![CDATA[kaijls]]></dc:creator><pubDate>Sun, 01 Jul 2018 09:46:23 GMT</pubDate></item></channel></rss>