<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Phase 1 problem after phase 1 lifetime ends]]></title><description><![CDATA[<p dir="auto">Hi<br />
Having a problem between a pfsense and checkpoint.<br />
When first starting the vpn, all is good. But after the Phase 1 lifetime ends connection fails.</p>
<p dir="auto">This is what i did find in the logs on pfsense</p>
<pre><code>Feb 2 15:58:17  charon: 14[IKE] &lt;con1000|9&gt; received retransmit of response with ID 0, but next request already sent
Feb 2 15:58:17  charon: 14[NET] &lt;con1000|9&gt; received packet: from "Remote host IP"[500] to "Local host IP"[500] (76 bytes)
Feb 2 15:58:13  charon: 09[IKE] &lt;con1000|9&gt; received retransmit of response with ID 0, but next request already sent
Feb 2 15:58:13  charon: 09[NET] &lt;con1000|9&gt; received packet: from "Remote host IP"[500] to "Local host IP"[500] (76 bytes)
Feb 2 15:58:09  charon: 14[IKE] &lt;con1000|9&gt; received retransmit of response with ID 0, but next request already sent
Feb 2 15:58:09  charon: 14[NET] &lt;con1000|9&gt; received packet: from "Remote host IP"[500] to "Local host IP"[500] (76 bytes)
Feb 2 15:58:05  charon: 14[IKE] &lt;con1000|9&gt; received retransmit of response with ID 0, but next request already sent
Feb 2 15:58:05  charon: 14[NET] &lt;con1000|9&gt; received packet: from "Remote host IP"[500] to "Local host IP"[500] (76 bytes)
Feb 2 15:58:01  charon: 16[IKE] &lt;con1000|9&gt; received retransmit of response with ID 0, but next request already sent
Feb 2 15:58:01  charon: 16[NET] &lt;con1000|9&gt; received packet: from "Remote host IP"[500] to "Local host IP"[500] (76 bytes)
Feb 2 15:57:57  charon: 14[IKE] &lt;con1000|9&gt; received retransmit of response with ID 0, but next request already sent
Feb 2 15:57:57  charon: 14[NET] &lt;con1000|9&gt; received packet: from "Remote host IP"[500] to "Local host IP"[500] (76 bytes)
Feb 2 15:57:55  charon: 16[IKE] &lt;con1000|9&gt; received retransmit of response with ID 0, but next request already sent
Feb 2 15:57:55  charon: 16[NET] &lt;con1000|9&gt; received packet: from "Remote host IP"[500] to "Local host IP"[500] (76 bytes)
Feb 2 15:57:53  charon: 14[IKE] &lt;con1000|9&gt; received retransmit of response with ID 0, but next request already sent
Feb 2 15:57:53  charon: 14[NET] &lt;con1000|9&gt; received packet: from "Remote host IP"[500] to "Local host IP"[500] (76 bytes)
Feb 2 15:57:51  charon: 14[IKE] &lt;con1000|9&gt; received retransmit of response with ID 0, but next request already sent
Feb 2 15:57:51  charon: 14[NET] &lt;con1000|9&gt; received packet: from "Remote host IP"[500] to "Local host IP"[500] (76 bytes)
Feb 2 15:57:49  charon: 04[IKE] &lt;con1000|9&gt; received retransmit of response with ID 0, but next request already sent
Feb 2 15:57:49  charon: 04[NET] &lt;con1000|9&gt; received packet: from "Remote host IP"[500] to "Local host IP"[500] (76 bytes)
Feb 2 15:57:47  charon: 14[IKE] &lt;con1000|9&gt; received retransmit of response with ID 0, but next request already sent
Feb 2 15:57:47  charon: 14[NET] &lt;con1000|9&gt; received packet: from "Remote host IP"[500] to "Local host IP"[500] (76 bytes)
Feb 2 15:57:45  charon: 14[IKE] &lt;con1000|9&gt; maximum IKE_SA lifetime 86114s
Feb 2 15:57:45  charon: 14[IKE] &lt;con1000|9&gt; scheduling reauthentication in 85574s
Feb 2 15:57:45  charon: 14[IKE] &lt;con1000|9&gt; IKE_SA con1000[9] established between "Local host IP"["Local host IP"]..."Remote host IP"["Remote host IP"]
Feb 2 15:57:45  charon: 14[ENC] &lt;con1000|9&gt; parsed ID_PROT response 0 [ ID HASH ]
Feb 2 15:57:45  charon: 14[NET] &lt;con1000|9&gt; received packet: from "Remote host IP"[500] to "Local host IP"[500] (76 bytes)
Feb 2 15:57:45  charon: 14[NET] &lt;con1000|9&gt; sending packet: from "Local host IP"[500] to "Remote host IP"[500] (76 bytes)
Feb 2 15:57:45  charon: 14[ENC] &lt;con1000|9&gt; generating ID_PROT request 0 [ ID HASH ]
Feb 2 15:57:45  charon: 14[ENC] &lt;con1000|9&gt; parsed ID_PROT response 0 [ KE No ]
Feb 2 15:57:45  charon: 14[NET] &lt;con1000|9&gt; received packet: from "Remote host IP"[500] to "Local host IP"[500] (184 bytes)
Feb 2 15:57:45  charon: 14[NET] &lt;con1000|9&gt; sending packet: from "Local host IP"[500] to "Remote host IP"[500] (196 bytes)
Feb 2 15:57:45  charon: 14[ENC] &lt;con1000|9&gt; generating ID_PROT request 0 [ KE No ]
Feb 2 15:57:45  charon: 14[IKE] &lt;con1000|9&gt; received FRAGMENTATION vendor ID
Feb 2 15:57:45  charon: 14[ENC] &lt;con1000|9&gt; parsed ID_PROT response 0 [ SA V ]
Feb 2 15:57:45  charon: 14[NET] &lt;con1000|9&gt; received packet: from "Remote host IP"[500] to "Local host IP"[500] (108 bytes)
Feb 2 15:57:45  charon: 14[NET] &lt;con1000|8&gt; sending packet: from "Local host IP"[500] to "Remote host IP"[500] (204 bytes)
Feb 2 15:57:45  charon: 14[ENC] &lt;con1000|8&gt; generating ID_PROT request 0 [ SA V V V V V V ]
Feb 2 15:57:45  charon: 14[IKE] &lt;con1000|8&gt; initiating Main Mode IKE_SA con1000[9] to "Remote host IP"
Feb 2 15:57:45  charon: 14[IKE] &lt;con1000|8&gt; reauthenticating IKE_SA con1000[8]&lt;/con1000|8&gt;&lt;/con1000|8&gt;&lt;/con1000|8&gt;&lt;/con1000|8&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;&lt;/con1000|9&gt;
</code></pre>
<p dir="auto">It starts to work if i stop and start the ipsec service on the pfsense. If I do a reset tunnel on the checkpoint nothing happens.</p>
<p dir="auto">This all started when I updated pfsense to the latest version.</p>
<p dir="auto">Anyone that can help?</p>
]]></description><link>https://forum.netgate.com/topic/95393/phase-1-problem-after-phase-1-lifetime-ends</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 08:53:57 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/95393.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 11 Feb 2016 18:50:14 GMT</pubDate><ttl>60</ttl></channel></rss>