Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPsec invalid payload

    Scheduled Pinned Locked Moved IPsec
    5 Posts 2 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      Lipsius
      last edited by

      I followed this guide to set-up IP-sec VPN: https://docs.netgate.com/pfsense/en/latest/recipes/ipsec-mobile-ikev2-eap-mschapv2.html but when I try to connect I always get "received invalid payload". See logs for all details. Any ideas how to fix this please? IPseclogs.txt

      K 1 Reply Last reply Reply Quote 0
      • K
        Konstanti @Lipsius
        last edited by Konstanti

        @lipsius

        Hi

        you have problems in the phase-2 settings

        May 28 18:55:53 	charon 	36179 	06[IKE] <con-mobile|4> no acceptable proposal found
        May 28 18:55:53 	charon 	36179 	06[IKE] <con-mobile|4> failed to establish CHILD_SA, keeping IKE_SA
        
        Keyword: “failed to establish CHILD_SA, keeping IKE_SA”
        
        Probable Causes:
        
        IPsec algorithm is mismatched
        Suggestions:
        
        Verify that all IPsec algorithm parameters (i.e., Authentication/DH Groups/Encryption) match on both VPN configuration
        
        L 1 Reply Last reply Reply Quote 0
        • L
          Lipsius @Konstanti
          last edited by

          @konstanti You are right. I matched the settings and now VPN is working. However cannot go to the URL of the Firewall. Any ideas?

          K 1 Reply Last reply Reply Quote 0
          • K
            Konstanti @Lipsius
            last edited by

            @lipsius

            it is necessary to check the firewall rules on the ipsec interface

            by default , everything is blocked there

            L 1 Reply Last reply Reply Quote 0
            • L
              Lipsius @Konstanti
              last edited by

              @konstanti These are the rules. I'm using port 1600 for the GUI. Is there anything wrong? In IPsec I have added the VPN network of 10.3.200.0/24
              IPsecrule.png FWrules.png

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.