<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[IPSec Site to Site tunnel Broken with Advanced Outbound Nat]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">We have a site to site Ipsec tunnel which has been running for the last 2 years without and issues, however we now need to turn of Automatic NAT, as a result the VPN tunnel is now extremely unstable (last night ran for 7 hours, this morning lasted about 5 mins)</p>
<p dir="auto">Jan 25 09:21:30 racoon: NOTIFY: couldn't find the proper pskey, try to get one by the peer's address.<br />
Jan 25 09:21:30 racoon: WARNING: port 500 expected, but 0<br />
Jan 25 09:21:30 racoon: INFO: received Vendor ID: CISCO-UNITY<br />
Jan 25 09:21:30 racoon: INFO: received Vendor ID: DPD<br />
Jan 25 09:21:30 racoon: INFO: received Vendor ID: draft-ietf-ipsra-isakmp-xauth-06.txt<br />
Jan 25 09:21:30 racoon: INFO: begin Aggressive mode.</p>
<p dir="auto">However only the AON has been changed, and as soon as switched back over to Automatic back to stable again, anyone any ideas, at present we are running 1.2.2 due to driver issues on 1.2.3</p>
<p dir="auto">J</p>
]]></description><link>https://forum.netgate.com/topic/20961/ipsec-site-to-site-tunnel-broken-with-advanced-outbound-nat</link><generator>RSS for Node</generator><lastBuildDate>Sun, 07 Jun 2026 02:39:21 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/20961.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 25 Jan 2010 09:27:54 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to IPSec Site to Site tunnel Broken with Advanced Outbound Nat on Fri, 29 Jan 2010 18:54:21 GMT]]></title><description><![CDATA[<p dir="auto">Update, got this fixed, had created a specific NONAT rule for one of the interfaces, removed this, also cleaned up the VPN settings to match the remote system exactly (Key lifetime) and all seems stable now, not really sure which fixed it, but as this was stable beforehand I think it may just be a combination.</p>
<p dir="auto">J</p>
]]></description><link>https://forum.netgate.com/post/221231</link><guid isPermaLink="true">https://forum.netgate.com/post/221231</guid><dc:creator><![CDATA[jsmwalker]]></dc:creator><pubDate>Fri, 29 Jan 2010 18:54:21 GMT</pubDate></item><item><title><![CDATA[Reply to IPSec Site to Site tunnel Broken with Advanced Outbound Nat on Mon, 25 Jan 2010 13:28:34 GMT]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">This is becoming very frutrating, it works perfectly without Manual NAT, so not sure why AON breaks this, also have the following error (Connection stayed up 10mins):</p>
<p dir="auto">Jan 25 13:18:52 racoon: ERROR: not acceptable Identity Protection mode</p>
<p dir="auto">Which points towards the security identifer, however as this is now hardcoded as our external IP and only goes out through WAN1 (multi wan setup) I can't see why this would alter.</p>
<p dir="auto">J</p>
]]></description><link>https://forum.netgate.com/post/220730</link><guid isPermaLink="true">https://forum.netgate.com/post/220730</guid><dc:creator><![CDATA[jsmwalker]]></dc:creator><pubDate>Mon, 25 Jan 2010 13:28:34 GMT</pubDate></item></channel></rss>