Hi, there
I have 2 identiclal untangle boxes site A and site B
Site A on 16.6.1
Site B on 16.5.2
ipsec stoped working on site A after upgradtin to 16.6.1
Can someone shed some light as per why I cannot connect any more?
Many thanks
Alex
Here is the Log from A - that fails to connect
Mar 6 13:41:07 artiplanto-server-A charon: 08[IKE] destroying IKE_SA after failed XAuth authentication
Mar 6 13:41:07 artiplanto-server-A charon: 08[ENC] parsed TRANSACTION response 2408213423 [ HASH CPA(X_STATUS) ]
Mar 6 13:41:07 artiplanto-server-A charon: 08[NET] received packet: from 67.69.76.190[4501] to 174.89.225.43[4500] (68 bytes)
Mar 6 13:41:07 artiplanto-server-A charon: 15[NET] sending packet: from 174.89.225.43[4500] to 67.69.76.190[4501] (68 bytes)
Mar 6 13:41:07 artiplanto-server-A charon: 15[ENC] generating TRANSACTION request 2408213423 [ HASH CPS(X_STATUS) ]
Mar 6 13:41:07 artiplanto-server-A charon: 15[IKE] XAuth authentication of 'pingu.iphone' failed
Mar 6 13:41:07 artiplanto-server-A charon: 15[CFG] XAuth-EAP method backend not supported: radius
Mar 6 13:41:07 artiplanto-server-A charon: 15[ENC] parsed TRANSACTION response 523042316 [ HASH CPRP(X_USER X_PWD) ]
Mar 6 13:41:07 artiplanto-server-A charon: 15[NET] received packet: from 67.69.76.190[4501] to 174.89.225.43[4500] (92 bytes)
Mar 6 13:41:07 artiplanto-server-A charon: 06[NET] sending packet: from 174.89.225.43[4500] to 67.69.76.190[4501] (68 bytes)
Mar 6 13:41:07 artiplanto-server-A charon: 06[ENC] generating TRANSACTION request 523042316 [ HASH CPRQ(X_USER X_PWD) ]
Mar 6 13:41:07 artiplanto-server-A charon: 06[NET] sending packet: from 174.89.225.43[4500] to 67.69.76.190[4501] (68 bytes)
Mar 6 13:41:07 artiplanto-server-A charon: 06[ENC] generating ID_PROT response 0 [ ID HASH ]
Mar 6 13:41:07 artiplanto-server-A charon: 06[CFG] selected peer config "VPN-XAUTH-0"
Mar 6 13:41:07 artiplanto-server-A charon: 06[CFG] looking for XAuthInitPSK peer configs matching 174.89.225.43...67.69.76.190[10.43.137.64]
Mar 6 13:41:07 artiplanto-server-A charon: 06[ENC] parsed ID_PROT request 0 [ ID HASH N(INITIAL_CONTACT) ]
Mar 6 13:41:07 artiplanto-server-A charon: 06[NET] received packet: from 67.69.76.190[4501] to 174.89.225.43[4500] (92 bytes)
Mar 6 13:41:07 artiplanto-server-A charon: 05[NET] sending packet: from 174.89.225.43[500] to 67.69.76.190[1526] (236 bytes)
Mar 6 13:41:07 artiplanto-server-A charon: 05[ENC] generating ID_PROT response 0 [ KE No NAT-D NAT-D ]
Mar 6 13:41:07 artiplanto-server-A charon: 05[IKE] remote host is behind NAT
Mar 6 13:41:07 artiplanto-server-A charon: 05[ENC] parsed ID_PROT request 0 [ KE No NAT-D NAT-D ]
Mar 6 13:41:07 artiplanto-server-A charon: 05[NET] received packet: from 67.69.76.190[1526] to 174.89.225.43[500] (220 bytes)
Mar 6 13:41:06 artiplanto-server-A charon: 14[NET] sending packet: from 174.89.225.43[500] to 67.69.76.190[1526] (156 bytes)
Mar 6 13:41:06 artiplanto-server-A charon: 14[ENC] generating ID_PROT response 0 [ SA V V V V ]
Mar 6 13:41:06 artiplanto-server-A charon: 14[CFG] selected proposal: IKE:3DES_CBC/HMAC_MD5_96/PRF_HMAC_MD5/MODP_1024
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] 67.69.76.190 is initiating a Main Mode IKE_SA
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] 67.69.76.190 is initiating a Main Mode IKE_SA
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received DPD vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received FRAGMENTATION vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received Cisco Unity vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received XAuth vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received draft-ietf-ipsec-nat-t-ike-02\n vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received draft-ietf-ipsec-nat-t-ike-02 vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received draft-ietf-ipsec-nat-t-ike-03 vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received draft-ietf-ipsec-nat-t-ike-04 vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received draft-ietf-ipsec-nat-t-ike-05 vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received draft-ietf-ipsec-nat-t-ike-06 vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received draft-ietf-ipsec-nat-t-ike-07 vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received draft-ietf-ipsec-nat-t-ike-08 vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received draft-ietf-ipsec-nat-t-ike vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received NAT-T (RFC 3947) vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[ENC] parsed ID_PROT request 0 [ SA V V V V V V V V V V V V V V ]
Mar 6 13:41:06 artiplanto-server-A charon: 14[NET] received packet: from 67.69.76.190[1526] to 174.89.225.43[500] (848 bytes)
I have 2 identiclal untangle boxes site A and site B
Site A on 16.6.1
Site B on 16.5.2
ipsec stoped working on site A after upgradtin to 16.6.1
Can someone shed some light as per why I cannot connect any more?
Many thanks
Alex
Here is the Log from A - that fails to connect
Mar 6 13:41:07 artiplanto-server-A charon: 08[IKE] destroying IKE_SA after failed XAuth authentication
Mar 6 13:41:07 artiplanto-server-A charon: 08[ENC] parsed TRANSACTION response 2408213423 [ HASH CPA(X_STATUS) ]
Mar 6 13:41:07 artiplanto-server-A charon: 08[NET] received packet: from 67.69.76.190[4501] to 174.89.225.43[4500] (68 bytes)
Mar 6 13:41:07 artiplanto-server-A charon: 15[NET] sending packet: from 174.89.225.43[4500] to 67.69.76.190[4501] (68 bytes)
Mar 6 13:41:07 artiplanto-server-A charon: 15[ENC] generating TRANSACTION request 2408213423 [ HASH CPS(X_STATUS) ]
Mar 6 13:41:07 artiplanto-server-A charon: 15[IKE] XAuth authentication of 'pingu.iphone' failed
Mar 6 13:41:07 artiplanto-server-A charon: 15[CFG] XAuth-EAP method backend not supported: radius
Mar 6 13:41:07 artiplanto-server-A charon: 15[ENC] parsed TRANSACTION response 523042316 [ HASH CPRP(X_USER X_PWD) ]
Mar 6 13:41:07 artiplanto-server-A charon: 15[NET] received packet: from 67.69.76.190[4501] to 174.89.225.43[4500] (92 bytes)
Mar 6 13:41:07 artiplanto-server-A charon: 06[NET] sending packet: from 174.89.225.43[4500] to 67.69.76.190[4501] (68 bytes)
Mar 6 13:41:07 artiplanto-server-A charon: 06[ENC] generating TRANSACTION request 523042316 [ HASH CPRQ(X_USER X_PWD) ]
Mar 6 13:41:07 artiplanto-server-A charon: 06[NET] sending packet: from 174.89.225.43[4500] to 67.69.76.190[4501] (68 bytes)
Mar 6 13:41:07 artiplanto-server-A charon: 06[ENC] generating ID_PROT response 0 [ ID HASH ]
Mar 6 13:41:07 artiplanto-server-A charon: 06[CFG] selected peer config "VPN-XAUTH-0"
Mar 6 13:41:07 artiplanto-server-A charon: 06[CFG] looking for XAuthInitPSK peer configs matching 174.89.225.43...67.69.76.190[10.43.137.64]
Mar 6 13:41:07 artiplanto-server-A charon: 06[ENC] parsed ID_PROT request 0 [ ID HASH N(INITIAL_CONTACT) ]
Mar 6 13:41:07 artiplanto-server-A charon: 06[NET] received packet: from 67.69.76.190[4501] to 174.89.225.43[4500] (92 bytes)
Mar 6 13:41:07 artiplanto-server-A charon: 05[NET] sending packet: from 174.89.225.43[500] to 67.69.76.190[1526] (236 bytes)
Mar 6 13:41:07 artiplanto-server-A charon: 05[ENC] generating ID_PROT response 0 [ KE No NAT-D NAT-D ]
Mar 6 13:41:07 artiplanto-server-A charon: 05[IKE] remote host is behind NAT
Mar 6 13:41:07 artiplanto-server-A charon: 05[ENC] parsed ID_PROT request 0 [ KE No NAT-D NAT-D ]
Mar 6 13:41:07 artiplanto-server-A charon: 05[NET] received packet: from 67.69.76.190[1526] to 174.89.225.43[500] (220 bytes)
Mar 6 13:41:06 artiplanto-server-A charon: 14[NET] sending packet: from 174.89.225.43[500] to 67.69.76.190[1526] (156 bytes)
Mar 6 13:41:06 artiplanto-server-A charon: 14[ENC] generating ID_PROT response 0 [ SA V V V V ]
Mar 6 13:41:06 artiplanto-server-A charon: 14[CFG] selected proposal: IKE:3DES_CBC/HMAC_MD5_96/PRF_HMAC_MD5/MODP_1024
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] 67.69.76.190 is initiating a Main Mode IKE_SA
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] 67.69.76.190 is initiating a Main Mode IKE_SA
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received DPD vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received FRAGMENTATION vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received Cisco Unity vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received XAuth vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received draft-ietf-ipsec-nat-t-ike-02\n vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received draft-ietf-ipsec-nat-t-ike-02 vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received draft-ietf-ipsec-nat-t-ike-03 vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received draft-ietf-ipsec-nat-t-ike-04 vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received draft-ietf-ipsec-nat-t-ike-05 vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received draft-ietf-ipsec-nat-t-ike-06 vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received draft-ietf-ipsec-nat-t-ike-07 vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received draft-ietf-ipsec-nat-t-ike-08 vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received draft-ietf-ipsec-nat-t-ike vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[IKE] received NAT-T (RFC 3947) vendor ID
Mar 6 13:41:06 artiplanto-server-A charon: 14[ENC] parsed ID_PROT request 0 [ SA V V V V V V V V V V V V V V ]
Mar 6 13:41:06 artiplanto-server-A charon: 14[NET] received packet: from 67.69.76.190[1526] to 174.89.225.43[500] (848 bytes)
Comment