Unstable pfsense <-> pfsense vpn, lots of logging noise



  • Hi,

    I have a IPsec VPN between two pfsense boxes, it has proved a bit unstable. Unfortunately, it makes a lot of noise in the log as well, so it's hard to see where the problem happens. I get this constantly:
    Jan 20 18:24:12 racoon: [Unknown Gateway/Dynamic]: ERROR: failed to bind to address 83.89.217.26[4500] (Address already in use).
    Jan 20 18:24:12 racoon: [Unknown Gateway/Dynamic]: ERROR: failed to bind to address 83.89.217.26[500] (Address already in use).
    Jan 20 18:24:12 racoon: INFO: 10.1.0.1[4500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 10.1.0.1[4500] used as isakmp port (fd=19)
    Jan 20 18:24:12 racoon: INFO: 10.1.0.1[500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 10.1.0.1[500] used as isakmp port (fd=18)
    Jan 20 18:24:12 racoon: INFO: 127.0.0.1[4500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 127.0.0.1[4500] used as isakmp port (fd=17)
    Jan 20 18:24:12 racoon: INFO: 127.0.0.1[500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 127.0.0.1[500] used as isakmp port (fd=16)
    Jan 20 18:24:12 racoon: INFO: 83.89.217.26[4500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 83.89.217.26[4500] used as isakmp port (fd=15)
    Jan 20 18:24:12 racoon: INFO: 83.89.217.26[500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 83.89.217.26[500] used as isakmp port (fd=14)
    Jan 20 18:24:12 racoon: NOTIFY: NAT-T is enabled, autoconfiguring ports
    Jan 20 18:24:12 racoon: ERROR: failed to bind to address 83.89.217.26[4500] (Address already in use).
    Jan 20 18:24:12 racoon: ERROR: failed to bind to address 83.89.217.26[500] (Address already in use).
    Jan 20 18:24:12 racoon: INFO: 10.1.0.1[4500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 10.1.0.1[4500] used as isakmp port (fd=19)
    Jan 20 18:24:12 racoon: INFO: 10.1.0.1[500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 10.1.0.1[500] used as isakmp port (fd=18)
    Jan 20 18:24:12 racoon: INFO: 127.0.0.1[4500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 127.0.0.1[4500] used as isakmp port (fd=17)
    Jan 20 18:24:12 racoon: INFO: 127.0.0.1[500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 127.0.0.1[500] used as isakmp port (fd=16)
    Jan 20 18:24:12 racoon: INFO: 83.89.217.26[4500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 83.89.217.26[4500] used as isakmp port (fd=15)
    Jan 20 18:24:12 racoon: INFO: 83.89.217.26[500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 83.89.217.26[500] used as isakmp port (fd=14)
    Jan 20 18:24:12 racoon: NOTIFY: NAT-T is enabled, autoconfiguring ports
    Jan 20 18:24:12 racoon: INFO: 83.89.217.26[4500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 83.89.217.26[4500] used as isakmp port (fd=19)
    Jan 20 18:24:12 racoon: INFO: 83.89.217.26[500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 83.89.217.26[500] used as isakmp port (fd=18)
    Jan 20 18:24:12 racoon: INFO: 10.1.0.1[4500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 10.1.0.1[4500] used as isakmp port (fd=17)
    Jan 20 18:24:12 racoon: INFO: 10.1.0.1[500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 10.1.0.1[500] used as isakmp port (fd=16)
    Jan 20 18:24:12 racoon: INFO: 127.0.0.1[4500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 127.0.0.1[4500] used as isakmp port (fd=15)
    Jan 20 18:24:12 racoon: INFO: 127.0.0.1[500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 127.0.0.1[500] used as isakmp port (fd=14)
    Jan 20 18:24:12 racoon: NOTIFY: NAT-T is enabled, autoconfiguring ports
    Jan 20 18:24:10 racoon: INFO: 83.89.217.26[4500] used for NAT-T
    Jan 20 18:24:10 racoon: [Self]: INFO: 83.89.217.26[4500] used as isakmp port (fd=19)
    Jan 20 18:24:10 racoon: INFO: 83.89.217.26[500] used for NAT-T
    Jan 20 18:24:10 racoon: [Self]: INFO: 83.89.217.26[500] used as isakmp port (fd=18)
    Jan 20 18:24:10 racoon: INFO: 10.1.0.1[4500] used for NAT-T
    Jan 20 18:24:10 racoon: [Self]: INFO: 10.1.0.1[4500] used as isakmp port (fd=17)
    Jan 20 18:24:10 racoon: INFO: 10.1.0.1[500] used for NAT-T
    Jan 20 18:24:10 racoon: [Self]: INFO: 10.1.0.1[500] used as isakmp port (fd=16)
    Jan 20 18:24:10 racoon: INFO: 127.0.0.1[4500] used for NAT-T
    Jan 20 18:24:10 racoon: [Self]: INFO: 127.0.0.1[4500] used as isakmp port (fd=15)
    Jan 20 18:24:10 racoon: INFO: 127.0.0.1[500] used for NAT-T
    Jan 20 18:24:10 racoon: [Self]: INFO: 127.0.0.1[500] used as isakmp port (fd=14)
    Jan 20 18:24:10 racoon: NOTIFY: NAT-T is enabled, autoconfiguring ports
    Jan 20 18:24:08 racoon: INFO: 83.89.217.26[4500] used for NAT-T
    Jan 20 18:24:08 racoon: [Self]: INFO: 83.89.217.26[4500] used as isakmp port (fd=19)
    Jan 20 18:24:08 racoon: INFO: 83.89.217.26[500] used for NAT-T
    Jan 20 18:24:08 racoon: [Self]: INFO: 83.89.217.26[500] used as isakmp port (fd=18)
    Jan 20 18:24:08 racoon: INFO: 10.1.0.1[4500] used for NAT-T
    Jan 20 18:24:08 racoon: [Self]: INFO: 10.1.0.1[4500] used as isakmp port (fd=17)
    Jan 20 18:24:08 racoon: INFO: 10.1.0.1[500] used for NAT-T
    Jan 20 18:24:08 racoon: [Self]: INFO: 10.1.0.1[500] used as isakmp port (fd=16)
    Jan 20 18:24:08 racoon: INFO: 127.0.0.1[4500] used for NAT-T
    Jan 20 18:24:08 racoon: [Self]: INFO: 127.0.0.1[4500] used as isakmp port (fd=15)
    Jan 20 18:24:08 racoon: INFO: 127.0.0.1[500] used for NAT-T
    Jan 20 18:24:08 racoon: [Self]: INFO: 127.0.0.1[500] used as isakmp port (fd=14)
    Jan 20 18:24:08 racoon: NOTIFY: NAT-T is enabled, autoconfiguring ports
    Jan 20 18:23:51 racoon: INFO: 83.89.217.26[4500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 83.89.217.26[4500] used as isakmp port (fd=19)
    Jan 20 18:23:51 racoon: INFO: 83.89.217.26[500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 83.89.217.26[500] used as isakmp port (fd=18)
    Jan 20 18:23:51 racoon: INFO: 10.1.0.1[4500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 10.1.0.1[4500] used as isakmp port (fd=17)
    Jan 20 18:23:51 racoon: INFO: 10.1.0.1[500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 10.1.0.1[500] used as isakmp port (fd=16)
    Jan 20 18:23:51 racoon: INFO: 127.0.0.1[4500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 127.0.0.1[4500] used as isakmp port (fd=15)
    Jan 20 18:23:51 racoon: INFO: 127.0.0.1[500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 127.0.0.1[500] used as isakmp port (fd=14)
    Jan 20 18:23:51 racoon: NOTIFY: NAT-T is enabled, autoconfiguring ports
    Jan 20 18:23:51 racoon: INFO: 83.89.217.26[4500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 83.89.217.26[4500] used as isakmp port (fd=19)
    Jan 20 18:23:51 racoon: INFO: 83.89.217.26[500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 83.89.217.26[500] used as isakmp port (fd=18)
    Jan 20 18:23:51 racoon: INFO: 10.1.0.1[4500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 10.1.0.1[4500] used as isakmp port (fd=17)
    Jan 20 18:23:51 racoon: INFO: 10.1.0.1[500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 10.1.0.1[500] used as isakmp port (fd=16)
    Jan 20 18:23:51 racoon: INFO: 127.0.0.1[4500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 127.0.0.1[4500] used as isakmp port (fd=15)
    Jan 20 18:23:51 racoon: INFO: 127.0.0.1[500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 127.0.0.1[500] used as isakmp port (fd=14)
    Jan 20 18:23:51 racoon: NOTIFY: NAT-T is enabled, autoconfiguring ports
    Jan 20 18:23:51 racoon: INFO: 83.89.217.26[4500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 83.89.217.26[4500] used as isakmp port (fd=19)
    Jan 20 18:23:51 racoon: INFO: 83.89.217.26[500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 83.89.217.26[500] used as isakmp port (fd=18)
    Jan 20 18:23:51 racoon: INFO: 10.1.0.1[4500] used for NAT-T

    83.89.217.26 is the WAN IP. Any idea on minimizing this? The error also makes me slightly nervous, any idea on how to fix that?

    Any help is greatly appreciated!


Locked