<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[IPSEC tunnels all dropping at random times after upgrade from 1.2.3 to 2.0]]></title><description><![CDATA[<p dir="auto">Our VPN tunnels drop at random intervals.  When this happens if we click save to update policy then they all come back.</p>
<p dir="auto">We have 4 tunnels two going to pfsense 1.2.3, one going to a Cisco RVS400 and one going to a SnapGear router.</p>
<p dir="auto">Here is the relevant part of our log with the ips removed and labeled with type of router.  If anyone has seen this before or knows of a fix please let us know.  Thanks in Advance.</p>
<p dir="auto">Aug 25 10:00:02 colbert racoon: INFO: initiate new phase 1 negotiation: pfsense2.0.ip[500]&lt;=&gt;pfsense1.2.3rc1.ip[500]<br />
Aug 25 10:00:02 colbert racoon: INFO: begin Aggressive mode.<br />
Aug 25 10:00:02 colbert racoon: ERROR: phase1 negotiation failed due to send error. 1686ec4ab8a3549a:0000000000000000<br />
Aug 25 10:00:02 colbert racoon: ERROR: failed to begin ipsec sa negotication.<br />
Aug 25 10:00:07 colbert racoon: INFO: IPsec-SA request for pfsense1.2.3.ip queued due to no phase1 found.<br />
Aug 25 10:00:07 colbert racoon: INFO: initiate new phase 1 negotiation: pfsense2.0.ip[500]&lt;=&gt;pfsense1.2.3.ip[500]<br />
Aug 25 10:00:07 colbert racoon: INFO: begin Aggressive mode.<br />
Aug 25 10:00:07 colbert racoon: ERROR: phase1 negotiation failed due to send error. 47a8c87827cc143a:0000000000000000<br />
Aug 25 10:00:07 colbert racoon: ERROR: failed to begin ipsec sa negotication.<br />
Aug 25 10:00:09 colbert racoon: INFO: IPsec-SA request for snapGear.ip queued due to no phase1 found.<br />
Aug 25 10:00:09 colbert racoon: INFO: initiate new phase 1 negotiation: pfsense2.0.ip[500]&lt;=&gt;snapGear.ip[500]<br />
Aug 25 10:00:09 colbert racoon: INFO: begin Aggressive mode.<br />
Aug 25 10:00:09 colbert racoon: ERROR: phase1 negotiation failed due to send error. e136782a40a70ee2:0000000000000000<br />
Aug 25 10:00:09 colbert racoon: ERROR: failed to begin ipsec sa negotication.<br />
Aug 25 10:00:10 colbert racoon: INFO: IPsec-SA request for pfsense1.2.3.ip queued due to no phase1 found.<br />
Aug 25 10:00:10 colbert racoon: INFO: initiate new phase 1 negotiation: pfsense2.0.ip[500]&lt;=&gt;pfsense1.2.3.ip[500]<br />
Aug 25 10:00:10 colbert racoon: INFO: begin Aggressive mode.<br />
Aug 25 10:00:10 colbert racoon: ERROR: phase1 negotiation failed due to send error. aad3d96b46ffe46d:0000000000000000<br />
Aug 25 10:00:10 colbert racoon: ERROR: failed to begin ipsec sa negotication.<br />
Aug 25 10:00:15 colbert racoon: INFO: IPsec-SA request for pfsense1.2.3.ip queued due to no phase1 found.<br />
Aug 25 10:00:15 colbert racoon: INFO: initiate new phase 1 negotiation: pfsense2.0.ip[500]&lt;=&gt;pfsense1.2.3.ip[500]<br />
Aug 25 10:00:15 colbert racoon: INFO: begin Aggressive mode.<br />
Aug 25 10:00:15 colbert racoon: ERROR: phase1 negotiation failed due to send error. 08b7129323fd82ae:0000000000000000<br />
Aug 25 10:00:15 colbert racoon: ERROR: failed to begin ipsec sa negotication.<br />
Aug 25 10:00:18 colbert racoon: INFO: IPsec-SA request for pfsense1.2.3.ip queued due to no phase1 found.<br />
Aug 25 10:00:18 colbert racoon: INFO: initiate new phase 1 negotiation: pfsense2.0.ip[500]&lt;=&gt;pfsense1.2.3.ip[500]<br />
Aug 25 10:00:18 colbert racoon: INFO: begin Aggressive mode.<br />
Aug 25 10:00:18 colbert racoon: ERROR: phase1 negotiation failed due to send error. 59d9186201c82b6d:0000000000000000<br />
Aug 25 10:00:18 colbert racoon: ERROR: failed to begin ipsec sa negotication.<br />
Aug 25 10:00:18 colbert racoon: INFO: IPsec-SA request for ciscoRVS400.ip queued due to no phase1 found.<br />
Aug 25 10:00:18 colbert racoon: INFO: initiate new phase 1 negotiation: pfsense2.0.ip[500]&lt;=&gt;ciscoRVS400.ip[500]<br />
Aug 25 10:00:18 colbert racoon: INFO: begin Identity Protection mode.<br />
Aug 25 10:00:18 colbert racoon: ERROR: phase1 negotiation failed due to send error. 432264a59b93befb:0000000000000000<br />
Aug 25 10:00:18 colbert racoon: ERROR: failed to begin ipsec sa negotication.<br />
Aug 25 10:00:22 colbert racoon: INFO: IPsec-SA request for pfsense1.2.3.ip queued due to no phase1 found.<br />
Aug 25 10:00:22 colbert racoon: INFO: initiate new phase 1 negotiation: pfsense2.0.ip[500]&lt;=&gt;pfsense1.2.3.ip[500]<br />
Aug 25 10:00:22 colbert racoon: INFO: begin Aggressive mode.<br />
Aug 25 10:00:22 colbert racoon: ERROR: phase1 negotiation failed due to send error. ea49983f6d509512:0000000000000000<br />
Aug 25 10:00:22 colbert racoon: ERROR: failed to begin ipsec sa negotication.<br />
Aug 25 10:00:24 colbert racoon: INFO: IPsec-SA request for pfsense1.2.3rc1.ip queued due to no phase1 found.<br />
Aug 25 10:00:24 colbert racoon: INFO: initiate new phase 1 negotiation: pfsense2.0.ip[500]&lt;=&gt;pfsense1.2.3rc1.ip[500]<br />
Aug 25 10:00:24 colbert racoon: INFO: begin Aggressive mode.<br />
Aug 25 10:00:24 colbert racoon: ERROR: phase1 negotiation failed due to send error. 6b0573448d3e6426:0000000000000000<br />
Aug 25 10:00:24 colbert racoon: ERROR: failed to begin ipsec sa negotication.<br />
Aug 25 10:00:28 colbert racoon: INFO: IPsec-SA request for ciscoRVS400.ip queued due to no phase1 found.<br />
Aug 25 10:00:28 colbert racoon: INFO: initiate new phase 1 negotiation: pfsense2.0.ip[500]&lt;=&gt;ciscoRVS400.ip[500]<br />
Aug 25 10:00:28 colbert racoon: INFO: begin Identity Protection mode.<br />
Aug 25 10:00:28 colbert racoon: ERROR: phase1 negotiation failed due to send error. 09a4b0472d308e01:0000000000000000<br />
Aug 25 10:00:28 colbert racoon: ERROR: failed to begin ipsec sa negotication.<br />
Aug 25 10:00:30 colbert racoon: INFO: IPsec-SA request for pfsense1.2.3.ip queued due to no phase1 found.<br />
Aug 25 10:00:30 colbert racoon: INFO: initiate new phase 1 negotiation: pfsense2.0.ip[500]&lt;=&gt;pfsense1.2.3.ip[500]<br />
Aug 25 10:00:30 colbert racoon: INFO: begin Aggressive mode.<br />
Aug 25 10:00:30 colbert racoon: ERROR: phase1 negotiation failed due to send error. e596419712a16b74:0000000000000000<br />
Aug 25 10:00:30 colbert racoon: ERROR: failed to begin ipsec sa negotication.<br />
Aug 25 10:00:31 colbert racoon: INFO: IPsec-SA request for pfsense1.2.3.ip queued due to no phase1 found.<br />
Aug 25 10:00:31 colbert racoon: INFO: initiate new phase 1 negotiation: pfsense2.0.ip[500]&lt;=&gt;pfsense1.2.3.ip[500]<br />
Aug 25 10:00:31 colbert racoon: INFO: begin Aggressive mode.<br />
Aug 25 10:00:32 colbert racoon: ERROR: phase1 negotiation failed due to send error. 52f97f80f9d35273:0000000000000000<br />
Aug 25 10:00:32 colbert racoon: ERROR: failed to begin ipsec sa negotication.<br />
Aug 25 10:00:37 colbert racoon: INFO: IPsec-SA request for snapGear.ip queued due to no phase1 found.<br />
Aug 25 10:00:37 colbert racoon: INFO: initiate new phase 1 negotiation: pfsense2.0.ip[500]&lt;=&gt;snapGear.ip[500]<br />
Aug 25 10:00:37 colbert racoon: INFO: begin Aggressive mode.<br />
Aug 25 10:00:37 colbert racoon: ERROR: phase1 negotiation failed due to send error. 109a0bde22d78759:0000000000000000<br />
Aug 25 10:00:37 colbert racoon: ERROR: failed to begin ipsec sa negotication.<br />
Aug 25 10:00:42 colbert racoon: INFO: IPsec-SA request for pfsense1.2.3rc1.ip queued due to no phase1 found.<br />
Aug 25 10:00:42 colbert racoon: INFO: initiate new phase 1 negotiation: pfsense2.0.ip[500]&lt;=&gt;pfsense1.2.3rc1.ip[500]<br />
Aug 25 10:00:42 colbert racoon: INFO: begin Aggressive mode.<br />
Aug 25 10:00:42 colbert racoon: ERROR: phase1 negotiation failed due to send error. 48d8239318d9eac1:0000000000000000<br />
Aug 25 10:00:42 colbert racoon: ERROR: failed to begin ipsec sa negotication.<br />
Aug 25 10:00:45 colbert racoon: INFO: IPsec-SA request for pfsense1.2.3rc1.ip queued due to no phase1 found.</p>
]]></description><link>https://forum.netgate.com/topic/36663/ipsec-tunnels-all-dropping-at-random-times-after-upgrade-from-1-2-3-to-2-0</link><generator>RSS for Node</generator><lastBuildDate>Mon, 20 Jul 2026 22:50:47 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/36663.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 25 Aug 2011 15:42:06 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to IPSEC tunnels all dropping at random times after upgrade from 1.2.3 to 2.0 on Fri, 16 Sep 2011 15:10:56 GMT]]></title><description><![CDATA[<p dir="auto">Hello everyone,<br />
  Thank you for responses.  I have since downgraded to 1.2.3 stable and have not had a tunnel drop out since.  It is too bad because I really wanted to use some of the new functionality of pfSense 2.0 however, everyone is much happier now that the network is stable.</p>
<p dir="auto">Andrew</p>
]]></description><link>https://forum.netgate.com/post/296084</link><guid isPermaLink="true">https://forum.netgate.com/post/296084</guid><dc:creator><![CDATA[afinkinfotech]]></dc:creator><pubDate>Fri, 16 Sep 2011 15:10:56 GMT</pubDate></item><item><title><![CDATA[Reply to IPSEC tunnels all dropping at random times after upgrade from 1.2.3 to 2.0 on Mon, 12 Sep 2011 17:51:40 GMT]]></title><description><![CDATA[<p dir="auto">It's quite possible that the DPD (Dead Peer Detection) feature is the culprit for some of the problems with IPsec VPNs to third-party routers reported here, since pfSense 2.0 uses the latest racoon (ipsec-tools 0.8.0).</p>
<p dir="auto">Have a look at the discussion and patch at ipsec-tools list:</p>
<blockquote>
<p dir="auto">http://sourceforge.net/mailarchive/forum.php?thread_name=4DA4F48F.1060809%40open.ch&amp;forum_name=ipsec-tools-devel</p>
<p dir="auto">Racoon (0.8.0) strictly checks the cookies within the encrypted part of<br />
DPD messages. According to RFC 3706 section 5.3 [1], the SPI content may<br />
contain the cookies, but it does not have to.</p>
<p dir="auto">In comparison, pluto from openswan strictly checks the SPI size,<br />
tolerating any SPI content. But the SPI size can be arbitrary as well,<br />
according to RFC.</p>
<p dir="auto">In the field I encountered a Cisco device (version/type unknown; Vendor<br />
ID: CISCO-UNITY), which sends the cookies of the encrypted part of DPD<br />
packets in reversed order, "violating" section 5.3 of RFC 3706 as I<br />
understand the relevant phrase:</p>
<ul>
<li>Security Parameter Index (16 octets) - SHOULD be set to the<br />
  cookies of the Initiator and Responder of the IKE SA (in that<br />
  order)</li>
</ul>
<p dir="auto">So my understanding is "you may put the cookies in there, and if you do,<br />
they must come in the given order".</p>
<p dir="auto">Since I fail to see any security implication, I produced this patch that<br />
makes racoon ignore the cookie content in DPD acks. This is in full<br />
compliance to RFC 3706 and allows racoon to use DPD with old Cisco<br />
devices that send inverted cookies (initiator/responder) in the<br />
encrypted part of the packets.</p>
<p dir="auto">This patch can also make DPD work with other vendors that do not send<br />
valid cookies within the DPD payload at all.</p>
<p dir="auto">Because the sequence number, which is in the encrypted part of DPD<br />
packets, is still being checked, this does not mean that racoon will<br />
accept bogus DPD acks.</p>
</blockquote>
]]></description><link>https://forum.netgate.com/post/295442</link><guid isPermaLink="true">https://forum.netgate.com/post/295442</guid><dc:creator><![CDATA[dhatz]]></dc:creator><pubDate>Mon, 12 Sep 2011 17:51:40 GMT</pubDate></item><item><title><![CDATA[Reply to IPSEC tunnels all dropping at random times after upgrade from 1.2.3 to 2.0 on Thu, 01 Sep 2011 02:33:58 GMT]]></title><description><![CDATA[<p dir="auto">afinkinfotech thanks for the info<br />
i already had tried that when this problem first aroused.<br />
and doing that didn't helped me but for some it might work</p>
<ol>
<li>changed mode to main mode</li>
<li>disabled DPD</li>
<li>ticked prefer old IPSEC<br />
worked for 2-3 hours without any problem and raccon stops after that.<br />
tried to read the log but could not find the actual cause.<br />
friends at this forum suggested might be a mismatching configuration but that's not so because it works for hours.<br />
so what i diagnosed was IPSEC between pfsense to pfsense is perfect but there might be problem with other hardwares in my case it was Trendnet Router.<br />
thanks for sharing<br />
kalu</li>
</ol>
]]></description><link>https://forum.netgate.com/post/294012</link><guid isPermaLink="true">https://forum.netgate.com/post/294012</guid><dc:creator><![CDATA[kalu]]></dc:creator><pubDate>Thu, 01 Sep 2011 02:33:58 GMT</pubDate></item><item><title><![CDATA[Reply to IPSEC tunnels all dropping at random times after upgrade from 1.2.3 to 2.0 on Wed, 31 Aug 2011 19:20:00 GMT]]></title><description><![CDATA[<p dir="auto">Here is what I did, and I think it has resolved the issue:</p>
<p dir="auto">1.  Switched all tunnels to main mode.<br />
2.  Disabled DPD (Dead Peer Detection)</p>
<p dir="auto">So far all good.  *Knocking on wood.</p>
]]></description><link>https://forum.netgate.com/post/293954</link><guid isPermaLink="true">https://forum.netgate.com/post/293954</guid><dc:creator><![CDATA[afinkinfotech]]></dc:creator><pubDate>Wed, 31 Aug 2011 19:20:00 GMT</pubDate></item><item><title><![CDATA[Reply to IPSEC tunnels all dropping at random times after upgrade from 1.2.3 to 2.0 on Wed, 31 Aug 2011 11:58:41 GMT]]></title><description><![CDATA[<p dir="auto">i had quite similar issue with ipsec and i switched to open vpn<br />
http://forum.pfsense.org/index.php/topic,39383.0.html<br />
may be a bug in ipsec in v2<br />
thanks</p>
]]></description><link>https://forum.netgate.com/post/293849</link><guid isPermaLink="true">https://forum.netgate.com/post/293849</guid><dc:creator><![CDATA[kalu]]></dc:creator><pubDate>Wed, 31 Aug 2011 11:58:41 GMT</pubDate></item><item><title><![CDATA[Reply to IPSEC tunnels all dropping at random times after upgrade from 1.2.3 to 2.0 on Wed, 31 Aug 2011 01:30:36 GMT]]></title><description><![CDATA[<p dir="auto">I have switched all of my tunnels to main mode as suggested to me in #pfSense IRC as well as suggested on a similar thread (<a href="http://forum.pfsense.org/index.php/topic,34595.0.html" target="_blank" rel="noopener noreferrer nofollow ugc">http://forum.pfsense.org/index.php/topic,34595.0.html</a>).  I will report the success or failure, in a couple days.</p>
]]></description><link>https://forum.netgate.com/post/293807</link><guid isPermaLink="true">https://forum.netgate.com/post/293807</guid><dc:creator><![CDATA[afinkinfotech]]></dc:creator><pubDate>Wed, 31 Aug 2011 01:30:36 GMT</pubDate></item></channel></rss>