Unstable pfsense <-> pfsense vpn, lots of logging noise



  • Hi,

    I have a IPsec VPN between two pfsense boxes, it has proved a bit unstable. Unfortunately, it makes a lot of noise in the log as well, so it's hard to see where the problem happens. I get this constantly:
    Jan 20 18:24:12 racoon: [Unknown Gateway/Dynamic]: ERROR: failed to bind to address 83.89.217.26[4500] (Address already in use).
    Jan 20 18:24:12 racoon: [Unknown Gateway/Dynamic]: ERROR: failed to bind to address 83.89.217.26[500] (Address already in use).
    Jan 20 18:24:12 racoon: INFO: 10.1.0.1[4500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 10.1.0.1[4500] used as isakmp port (fd=19)
    Jan 20 18:24:12 racoon: INFO: 10.1.0.1[500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 10.1.0.1[500] used as isakmp port (fd=18)
    Jan 20 18:24:12 racoon: INFO: 127.0.0.1[4500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 127.0.0.1[4500] used as isakmp port (fd=17)
    Jan 20 18:24:12 racoon: INFO: 127.0.0.1[500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 127.0.0.1[500] used as isakmp port (fd=16)
    Jan 20 18:24:12 racoon: INFO: 83.89.217.26[4500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 83.89.217.26[4500] used as isakmp port (fd=15)
    Jan 20 18:24:12 racoon: INFO: 83.89.217.26[500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 83.89.217.26[500] used as isakmp port (fd=14)
    Jan 20 18:24:12 racoon: NOTIFY: NAT-T is enabled, autoconfiguring ports
    Jan 20 18:24:12 racoon: ERROR: failed to bind to address 83.89.217.26[4500] (Address already in use).
    Jan 20 18:24:12 racoon: ERROR: failed to bind to address 83.89.217.26[500] (Address already in use).
    Jan 20 18:24:12 racoon: INFO: 10.1.0.1[4500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 10.1.0.1[4500] used as isakmp port (fd=19)
    Jan 20 18:24:12 racoon: INFO: 10.1.0.1[500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 10.1.0.1[500] used as isakmp port (fd=18)
    Jan 20 18:24:12 racoon: INFO: 127.0.0.1[4500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 127.0.0.1[4500] used as isakmp port (fd=17)
    Jan 20 18:24:12 racoon: INFO: 127.0.0.1[500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 127.0.0.1[500] used as isakmp port (fd=16)
    Jan 20 18:24:12 racoon: INFO: 83.89.217.26[4500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 83.89.217.26[4500] used as isakmp port (fd=15)
    Jan 20 18:24:12 racoon: INFO: 83.89.217.26[500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 83.89.217.26[500] used as isakmp port (fd=14)
    Jan 20 18:24:12 racoon: NOTIFY: NAT-T is enabled, autoconfiguring ports
    Jan 20 18:24:12 racoon: INFO: 83.89.217.26[4500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 83.89.217.26[4500] used as isakmp port (fd=19)
    Jan 20 18:24:12 racoon: INFO: 83.89.217.26[500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 83.89.217.26[500] used as isakmp port (fd=18)
    Jan 20 18:24:12 racoon: INFO: 10.1.0.1[4500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 10.1.0.1[4500] used as isakmp port (fd=17)
    Jan 20 18:24:12 racoon: INFO: 10.1.0.1[500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 10.1.0.1[500] used as isakmp port (fd=16)
    Jan 20 18:24:12 racoon: INFO: 127.0.0.1[4500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 127.0.0.1[4500] used as isakmp port (fd=15)
    Jan 20 18:24:12 racoon: INFO: 127.0.0.1[500] used for NAT-T
    Jan 20 18:24:12 racoon: [Self]: INFO: 127.0.0.1[500] used as isakmp port (fd=14)
    Jan 20 18:24:12 racoon: NOTIFY: NAT-T is enabled, autoconfiguring ports
    Jan 20 18:24:10 racoon: INFO: 83.89.217.26[4500] used for NAT-T
    Jan 20 18:24:10 racoon: [Self]: INFO: 83.89.217.26[4500] used as isakmp port (fd=19)
    Jan 20 18:24:10 racoon: INFO: 83.89.217.26[500] used for NAT-T
    Jan 20 18:24:10 racoon: [Self]: INFO: 83.89.217.26[500] used as isakmp port (fd=18)
    Jan 20 18:24:10 racoon: INFO: 10.1.0.1[4500] used for NAT-T
    Jan 20 18:24:10 racoon: [Self]: INFO: 10.1.0.1[4500] used as isakmp port (fd=17)
    Jan 20 18:24:10 racoon: INFO: 10.1.0.1[500] used for NAT-T
    Jan 20 18:24:10 racoon: [Self]: INFO: 10.1.0.1[500] used as isakmp port (fd=16)
    Jan 20 18:24:10 racoon: INFO: 127.0.0.1[4500] used for NAT-T
    Jan 20 18:24:10 racoon: [Self]: INFO: 127.0.0.1[4500] used as isakmp port (fd=15)
    Jan 20 18:24:10 racoon: INFO: 127.0.0.1[500] used for NAT-T
    Jan 20 18:24:10 racoon: [Self]: INFO: 127.0.0.1[500] used as isakmp port (fd=14)
    Jan 20 18:24:10 racoon: NOTIFY: NAT-T is enabled, autoconfiguring ports
    Jan 20 18:24:08 racoon: INFO: 83.89.217.26[4500] used for NAT-T
    Jan 20 18:24:08 racoon: [Self]: INFO: 83.89.217.26[4500] used as isakmp port (fd=19)
    Jan 20 18:24:08 racoon: INFO: 83.89.217.26[500] used for NAT-T
    Jan 20 18:24:08 racoon: [Self]: INFO: 83.89.217.26[500] used as isakmp port (fd=18)
    Jan 20 18:24:08 racoon: INFO: 10.1.0.1[4500] used for NAT-T
    Jan 20 18:24:08 racoon: [Self]: INFO: 10.1.0.1[4500] used as isakmp port (fd=17)
    Jan 20 18:24:08 racoon: INFO: 10.1.0.1[500] used for NAT-T
    Jan 20 18:24:08 racoon: [Self]: INFO: 10.1.0.1[500] used as isakmp port (fd=16)
    Jan 20 18:24:08 racoon: INFO: 127.0.0.1[4500] used for NAT-T
    Jan 20 18:24:08 racoon: [Self]: INFO: 127.0.0.1[4500] used as isakmp port (fd=15)
    Jan 20 18:24:08 racoon: INFO: 127.0.0.1[500] used for NAT-T
    Jan 20 18:24:08 racoon: [Self]: INFO: 127.0.0.1[500] used as isakmp port (fd=14)
    Jan 20 18:24:08 racoon: NOTIFY: NAT-T is enabled, autoconfiguring ports
    Jan 20 18:23:51 racoon: INFO: 83.89.217.26[4500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 83.89.217.26[4500] used as isakmp port (fd=19)
    Jan 20 18:23:51 racoon: INFO: 83.89.217.26[500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 83.89.217.26[500] used as isakmp port (fd=18)
    Jan 20 18:23:51 racoon: INFO: 10.1.0.1[4500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 10.1.0.1[4500] used as isakmp port (fd=17)
    Jan 20 18:23:51 racoon: INFO: 10.1.0.1[500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 10.1.0.1[500] used as isakmp port (fd=16)
    Jan 20 18:23:51 racoon: INFO: 127.0.0.1[4500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 127.0.0.1[4500] used as isakmp port (fd=15)
    Jan 20 18:23:51 racoon: INFO: 127.0.0.1[500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 127.0.0.1[500] used as isakmp port (fd=14)
    Jan 20 18:23:51 racoon: NOTIFY: NAT-T is enabled, autoconfiguring ports
    Jan 20 18:23:51 racoon: INFO: 83.89.217.26[4500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 83.89.217.26[4500] used as isakmp port (fd=19)
    Jan 20 18:23:51 racoon: INFO: 83.89.217.26[500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 83.89.217.26[500] used as isakmp port (fd=18)
    Jan 20 18:23:51 racoon: INFO: 10.1.0.1[4500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 10.1.0.1[4500] used as isakmp port (fd=17)
    Jan 20 18:23:51 racoon: INFO: 10.1.0.1[500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 10.1.0.1[500] used as isakmp port (fd=16)
    Jan 20 18:23:51 racoon: INFO: 127.0.0.1[4500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 127.0.0.1[4500] used as isakmp port (fd=15)
    Jan 20 18:23:51 racoon: INFO: 127.0.0.1[500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 127.0.0.1[500] used as isakmp port (fd=14)
    Jan 20 18:23:51 racoon: NOTIFY: NAT-T is enabled, autoconfiguring ports
    Jan 20 18:23:51 racoon: INFO: 83.89.217.26[4500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 83.89.217.26[4500] used as isakmp port (fd=19)
    Jan 20 18:23:51 racoon: INFO: 83.89.217.26[500] used for NAT-T
    Jan 20 18:23:51 racoon: [Self]: INFO: 83.89.217.26[500] used as isakmp port (fd=18)
    Jan 20 18:23:51 racoon: INFO: 10.1.0.1[4500] used for NAT-T

    83.89.217.26 is the WAN IP. Any idea on minimizing this? The error also makes me slightly nervous, any idea on how to fix that?

    Any help is greatly appreciated!


Log in to reply