I have done a bit more work on this problem and, correct me if I'm wrong, I no longer think it is driver related.
- Queries
- All Stories
- Search
- Advanced Search
- Transactions
- Transaction Logs
Advanced Search
Feb 5 2019
Feb 3 2019
Feb 2 2019
Jan 31 2019
Package needs to be build from source. There are already some packages which we build that way like libyang or librtr so not a big deal.
Change was reverted because "libcidr-dev is not available until Debian Buster thus the container can't be built"
Jan 30 2019
Jan 29 2019
@hagbard Did you merge the second PR also? For vyos/vyatta-nat?
Pull request created: https://github.com/vyos/vyos-build/pull/43
Hi.
Sorry for bad english.
@hagbard created an iso image and loaded it in a VM. I can add the configuration and at commit the right ip6tables rules are created.
@hagbard the changes are created with the patch files mentioned earlier.
I am in the process of creating packages and an iso with it.
@Merijn Have you tested your changes already? I was only bale to find https://github.com/vyos/vyatta-cfg-firewall/pull/12 which only contains the ip6tables targets, did you send PRs for systctl too?
@hagbard PRs created, first time so hope its done right.
@danhusan is this your expected behavior?
can you share your DHCP configuration with us for reproducibility?
Jan 28 2019
Note that this has taken down DNS on our firewall (and hence our network) a couple of times now, both annoyingly early in the morning when nobody was in to fix it.
In T1160#31671, @c-po wrote:But what should be the desired behavior?
- When no network or client is speciefied we allow allo but as soon as one network/client is specified we limit it down?
IMHO this is a general CLI design issue.
Jan 27 2019
Jan 26 2019
Jan 25 2019
Jan 23 2019
Yes, when I change Hub site remote_ts from dynamic to 0.0.0.0/0, That VPN was worked.
@bjtangseng so changing that remote_ts = 0.0.0.0/0[gre] fixed it right?
And more bug, when I change Hub swanctl.conf file. And run show IPSec sa and run show IPSec sa v. I can see deferent information.
Congratulations, VPN is connected
@bjtangseng
On the HUB, can you change in /etc/swanctl/swanctl.conf
remote_ts = dynamic[gre] to remote_ts = 0.0.0.0/0[gre]
In spoke site
can you do:
sudo swanctl --list-sas
You can see that the Remote ID used between the two sites does not match. In the last three line.
In spoke site
@bjtangseng, Ah that is the problem. I do not know if there is an option allow any network, have to do some research.
Yes, When I redial pppoe the IP meybe change.
@bjtangseng,
Does your nat address change everytime?
This is my Hub site log
can you put log from hub?
ipsec log
that IP(115.60.59.223) is public IP after NAT.
@bjtangseng
I think you replaced the wrong ip in the swanctl.conf
I try to change local_ts in swanctl.conf, but nothing to change.
vyos@vyos# sudo swanctl -i -c dmvpn -S 0.0.0.0 -R 116.90.86.181 -l 2
[JOB] watcher got notification, rebuilding
[JOB] watcher going to poll() 9 fds
[MGR] checkout IKE_SA by config 'dmvpn-DEVELVPN-tun0', me %any, other 116.90.86.181
[JOB] watcher got notification, rebuilding
[JOB] watcher going to poll() 9 fds
[JOB] watched FD 25 ready to write
[MGR] created IKE_SA (unnamed)[100]
[KNL] using 100.64.206.174 as address to reach 116.90.86.181/32
[IKE] queueing ISAKMP_VENDOR task
[IKE] queueing ISAKMP_CERT_PRE task
[IKE] queueing MAIN_MODE task
[IKE] queueing ISAKMP_CERT_POST task
[IKE] queueing ISAKMP_NATD task
[IKE] queueing QUICK_MODE task
[IKE] activating new tasks
[IKE] activating ISAKMP_VENDOR task
[IKE] activating ISAKMP_CERT_PRE task
[IKE] activating MAIN_MODE task
[IKE] activating ISAKMP_CERT_POST task
[IKE] activating ISAKMP_NATD task
[IKE] sending XAuth vendor ID
[ENC] added payload of type VENDOR_ID_V1 to message
[IKE] sending DPD vendor ID
[ENC] added payload of type VENDOR_ID_V1 to message
[IKE] sending FRAGMENTATION vendor ID
[ENC] added payload of type VENDOR_ID_V1 to message
[IKE] sending NAT-T (RFC 3947) vendor ID
[ENC] added payload of type VENDOR_ID_V1 to message
[IKE] sending draft-ietf-ipsec-nat-t-ike-02\n vendor ID
[ENC] added payload of type VENDOR_ID_V1 to message
[IKE] initiating Main Mode IKE_SA dmvpn-DEVELVPN-tun0[100] to 116.90.86.181
[IKE] IKE_SA dmvpn-DEVELVPN-tun0[100] state change: CREATED => CONNECTING
[CFG] configured proposals: IKE:AES_CBC_256/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024, IKE:AES_CBC_128/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024
[ENC] added payload of type SECURITY_ASSOCIATION_V1 to message
[ENC] order payloads in message
[ENC] added payload of type SECURITY_ASSOCIATION_V1 to message
[ENC] added payload of type VENDOR_ID_V1 to message
[ENC] added payload of type VENDOR_ID_V1 to message
[ENC] added payload of type VENDOR_ID_V1 to message
[ENC] added payload of type VENDOR_ID_V1 to message
[ENC] added payload of type VENDOR_ID_V1 to message
[ENC] generating ID_PROT request 0 [ SA V V V V V ]
[ENC] not encrypting payloads
[ENC] generating payload of type HEADER
[ENC] generating rule 0 IKE_SPI
[ENC] generating rule 1 IKE_SPI
[ENC] generating rule 2 U_INT_8
[ENC] generating rule 3 U_INT_4
[ENC] generating rule 4 U_INT_4
[ENC] generating rule 5 U_INT_8
[ENC] generating rule 6 RESERVED_BIT
[ENC] generating rule 7 RESERVED_BIT
[ENC] generating rule 8 FLAG
[ENC] generating rule 9 FLAG
[ENC] generating rule 10 FLAG
[ENC] generating rule 11 FLAG
[ENC] generating rule 12 FLAG
[ENC] generating rule 13 FLAG
[ENC] generating rule 14 U_INT_32
[ENC] generating rule 15 HEADER_LENGTH
[ENC] generating HEADER payload finished
[ENC] generating payload of type SECURITY_ASSOCIATION_V1
[ENC] generating rule 0 U_INT_8
[ENC] generating rule 1 RESERVED_BIT
[ENC] generating rule 2 RESERVED_BIT
[ENC] generating rule 3 RESERVED_BIT
[ENC] generating rule 4 RESERVED_BIT
[ENC] generating rule 5 RESERVED_BIT
[ENC] generating rule 6 RESERVED_BIT
[ENC] generating rule 7 RESERVED_BIT
[ENC] generating rule 8 RESERVED_BIT
[ENC] generating rule 9 PAYLOAD_LENGTH
[ENC] generating rule 10 U_INT_32
[ENC] generating rule 11 U_INT_32
[ENC] generating rule 12 (1259)
[ENC] generating payload of type PROPOSAL_SUBSTRUCTURE_V1
[ENC] generating rule 0 U_INT_8
[ENC] generating rule 1 RESERVED_BYTE
[ENC] generating rule 2 PAYLOAD_LENGTH
[ENC] generating rule 3 U_INT_8
[ENC] generating rule 4 U_INT_8
[ENC] generating rule 5 SPI_SIZE
[ENC] generating rule 6 U_INT_8
[ENC] generating rule 7 SPI
[ENC] generating rule 8 (1261)
[ENC] generating payload of type TRANSFORM_SUBSTRUCTURE_V1
[ENC] generating rule 0 U_INT_8
[ENC] generating rule 1 RESERVED_BYTE
[ENC] generating rule 2 PAYLOAD_LENGTH
[ENC] generating rule 3 U_INT_8
[ENC] generating rule 4 U_INT_8
[ENC] generating rule 5 RESERVED_BYTE
[ENC] generating rule 6 RESERVED_BYTE
[ENC] generating rule 7 (1263)
[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
[ENC] generating rule 0 ATTRIBUTE_FORMAT
[ENC] generating rule 1 ATTRIBUTE_TYPE
[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] generating rule 3 ATTRIBUTE_VALUE
[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
[ENC] generating rule 0 ATTRIBUTE_FORMAT
[ENC] generating rule 1 ATTRIBUTE_TYPE
[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] generating rule 3 ATTRIBUTE_VALUE
[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
[ENC] generating rule 0 ATTRIBUTE_FORMAT
[ENC] generating rule 1 ATTRIBUTE_TYPE
[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] generating rule 3 ATTRIBUTE_VALUE
[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
[ENC] generating rule 0 ATTRIBUTE_FORMAT
[ENC] generating rule 1 ATTRIBUTE_TYPE
[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] generating rule 3 ATTRIBUTE_VALUE
[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
[ENC] generating rule 0 ATTRIBUTE_FORMAT
[ENC] generating rule 1 ATTRIBUTE_TYPE
[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] generating rule 3 ATTRIBUTE_VALUE
[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
[ENC] generating rule 0 ATTRIBUTE_FORMAT
[ENC] generating rule 1 ATTRIBUTE_TYPE
[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] generating rule 3 ATTRIBUTE_VALUE
[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
[ENC] generating rule 0 ATTRIBUTE_FORMAT
[ENC] generating rule 1 ATTRIBUTE_TYPE
[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] generating rule 3 ATTRIBUTE_VALUE
[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] generating TRANSFORM_SUBSTRUCTURE_V1 payload finished
[ENC] generating payload of type TRANSFORM_SUBSTRUCTURE_V1
[ENC] generating rule 0 U_INT_8
[ENC] generating rule 1 RESERVED_BYTE
[ENC] generating rule 2 PAYLOAD_LENGTH
[ENC] generating rule 3 U_INT_8
[ENC] generating rule 4 U_INT_8
[ENC] generating rule 5 RESERVED_BYTE
[ENC] generating rule 6 RESERVED_BYTE
[ENC] generating rule 7 (1263)
[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
[ENC] generating rule 0 ATTRIBUTE_FORMAT
[ENC] generating rule 1 ATTRIBUTE_TYPE
[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] generating rule 3 ATTRIBUTE_VALUE
[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
[ENC] generating rule 0 ATTRIBUTE_FORMAT
[ENC] generating rule 1 ATTRIBUTE_TYPE
[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] generating rule 3 ATTRIBUTE_VALUE
[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
[ENC] generating rule 0 ATTRIBUTE_FORMAT
[ENC] generating rule 1 ATTRIBUTE_TYPE
[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] generating rule 3 ATTRIBUTE_VALUE
[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
[ENC] generating rule 0 ATTRIBUTE_FORMAT
[ENC] generating rule 1 ATTRIBUTE_TYPE
[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] generating rule 3 ATTRIBUTE_VALUE
[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
[ENC] generating rule 0 ATTRIBUTE_FORMAT
[ENC] generating rule 1 ATTRIBUTE_TYPE
[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] generating rule 3 ATTRIBUTE_VALUE
[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
[ENC] generating rule 0 ATTRIBUTE_FORMAT
[ENC] generating rule 1 ATTRIBUTE_TYPE
[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] generating rule 3 ATTRIBUTE_VALUE
[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
[ENC] generating rule 0 ATTRIBUTE_FORMAT
[ENC] generating rule 1 ATTRIBUTE_TYPE
[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] generating rule 3 ATTRIBUTE_VALUE
[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] generating TRANSFORM_SUBSTRUCTURE_V1 payload finished
[ENC] generating PROPOSAL_SUBSTRUCTURE_V1 payload finished
[ENC] generating SECURITY_ASSOCIATION_V1 payload finished
[ENC] generating payload of type VENDOR_ID_V1
[ENC] generating rule 0 U_INT_8
[ENC] generating rule 1 FLAG
[ENC] generating rule 2 RESERVED_BIT
[ENC] generating rule 3 RESERVED_BIT
[ENC] generating rule 4 RESERVED_BIT
[ENC] generating rule 5 RESERVED_BIT
[ENC] generating rule 6 RESERVED_BIT
[ENC] generating rule 7 RESERVED_BIT
[ENC] generating rule 8 RESERVED_BIT
[ENC] generating rule 9 PAYLOAD_LENGTH
[ENC] generating rule 10 CHUNK_DATA
[ENC] generating VENDOR_ID_V1 payload finished
[ENC] generating payload of type VENDOR_ID_V1
[ENC] generating rule 0 U_INT_8
[ENC] generating rule 1 FLAG
[ENC] generating rule 2 RESERVED_BIT
[ENC] generating rule 3 RESERVED_BIT
[ENC] generating rule 4 RESERVED_BIT
[ENC] generating rule 5 RESERVED_BIT
[ENC] generating rule 6 RESERVED_BIT
[ENC] generating rule 7 RESERVED_BIT
[ENC] generating rule 8 RESERVED_BIT
[ENC] generating rule 9 PAYLOAD_LENGTH
[ENC] generating rule 10 CHUNK_DATA
[ENC] generating VENDOR_ID_V1 payload finished
[ENC] generating payload of type VENDOR_ID_V1
[ENC] generating rule 0 U_INT_8
[ENC] generating rule 1 FLAG
[ENC] generating rule 2 RESERVED_BIT
[ENC] generating rule 3 RESERVED_BIT
[ENC] generating rule 4 RESERVED_BIT
[ENC] generating rule 5 RESERVED_BIT
[ENC] generating rule 6 RESERVED_BIT
[ENC] generating rule 7 RESERVED_BIT
[ENC] generating rule 8 RESERVED_BIT
[ENC] generating rule 9 PAYLOAD_LENGTH
[ENC] generating rule 10 CHUNK_DATA
[ENC] generating VENDOR_ID_V1 payload finished
[ENC] generating payload of type VENDOR_ID_V1
[ENC] generating rule 0 U_INT_8
[ENC] generating rule 1 FLAG
[ENC] generating rule 2 RESERVED_BIT
[ENC] generating rule 3 RESERVED_BIT
[ENC] generating rule 4 RESERVED_BIT
[ENC] generating rule 5 RESERVED_BIT
[ENC] generating rule 6 RESERVED_BIT
[ENC] generating rule 7 RESERVED_BIT
[ENC] generating rule 8 RESERVED_BIT
[ENC] generating rule 9 PAYLOAD_LENGTH
[ENC] generating rule 10 CHUNK_DATA
[ENC] generating VENDOR_ID_V1 payload finished
[ENC] generating payload of type VENDOR_ID_V1
[ENC] generating rule 0 U_INT_8
[ENC] generating rule 1 FLAG
[ENC] generating rule 2 RESERVED_BIT
[ENC] generating rule 3 RESERVED_BIT
[ENC] generating rule 4 RESERVED_BIT
[ENC] generating rule 5 RESERVED_BIT
[ENC] generating rule 6 RESERVED_BIT
[ENC] generating rule 7 RESERVED_BIT
[ENC] generating rule 8 RESERVED_BIT
[ENC] generating rule 9 PAYLOAD_LENGTH
[ENC] generating rule 10 CHUNK_DATA
[ENC] generating VENDOR_ID_V1 payload finished
[NET] sending packet: from 100.64.206.174[500] to 116.90.86.181[500] (216 bytes)
[MGR] checkin IKE_SA dmvpn-DEVELVPN-tun0[100]
[MGR] checkin of IKE_SA successful
[NET] received packet: from 116.90.86.181[500] to 100.64.206.174[500] (160 bytes)
[ENC] parsing body of message, first payload is SECURITY_ASSOCIATION_V1
[ENC] starting parsing a SECURITY_ASSOCIATION_V1 payload
[ENC] parsing SECURITY_ASSOCIATION_V1 payload, 132 bytes left
[ENC] parsing rule 0 U_INT_8
[ENC] parsing rule 1 RESERVED_BIT
[ENC] parsing rule 2 RESERVED_BIT
[ENC] parsing rule 3 RESERVED_BIT
[ENC] parsing rule 4 RESERVED_BIT
[ENC] parsing rule 5 RESERVED_BIT
[ENC] parsing rule 6 RESERVED_BIT
[ENC] parsing rule 7 RESERVED_BIT
[ENC] parsing rule 8 RESERVED_BIT
[ENC] parsing rule 9 PAYLOAD_LENGTH
[ENC] parsing rule 10 U_INT_32
[ENC] parsing rule 11 U_INT_32
[ENC] parsing rule 12 (1259)
[ENC] 44 bytes left, parsing recursively PROPOSAL_SUBSTRUCTURE_V1
[ENC] parsing PROPOSAL_SUBSTRUCTURE_V1 payload, 120 bytes left
[ENC] parsing rule 0 U_INT_8
[ENC] parsing rule 1 RESERVED_BYTE
[ENC] parsing rule 2 PAYLOAD_LENGTH
[ENC] parsing rule 3 U_INT_8
[ENC] parsing rule 4 U_INT_8
[ENC] parsing rule 5 SPI_SIZE
[ENC] parsing rule 6 U_INT_8
[ENC] parsing rule 7 SPI
[ENC] parsing rule 8 (1261)
[ENC] 36 bytes left, parsing recursively TRANSFORM_SUBSTRUCTURE_V1
[ENC] parsing TRANSFORM_SUBSTRUCTURE_V1 payload, 112 bytes left
[ENC] parsing rule 0 U_INT_8
[ENC] parsing rule 1 RESERVED_BYTE
[ENC] parsing rule 2 PAYLOAD_LENGTH
[ENC] parsing rule 3 U_INT_8
[ENC] parsing rule 4 U_INT_8
[ENC] parsing rule 5 RESERVED_BYTE
[ENC] parsing rule 6 RESERVED_BYTE
[ENC] parsing rule 7 (1263)
[ENC] 28 bytes left, parsing recursively TRANSFORM_ATTRIBUTE_V1
[ENC] parsing TRANSFORM_ATTRIBUTE_V1 payload, 104 bytes left
[ENC] parsing rule 0 ATTRIBUTE_FORMAT
[ENC] parsing rule 1 ATTRIBUTE_TYPE
[ENC] parsing rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] parsing rule 3 ATTRIBUTE_VALUE
[ENC] parsing TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] 24 bytes left, parsing recursively TRANSFORM_ATTRIBUTE_V1
[ENC] parsing TRANSFORM_ATTRIBUTE_V1 payload, 100 bytes left
[ENC] parsing rule 0 ATTRIBUTE_FORMAT
[ENC] parsing rule 1 ATTRIBUTE_TYPE
[ENC] parsing rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] parsing rule 3 ATTRIBUTE_VALUE
[ENC] parsing TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] 20 bytes left, parsing recursively TRANSFORM_ATTRIBUTE_V1
[ENC] parsing TRANSFORM_ATTRIBUTE_V1 payload, 96 bytes left
[ENC] parsing rule 0 ATTRIBUTE_FORMAT
[ENC] parsing rule 1 ATTRIBUTE_TYPE
[ENC] parsing rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] parsing rule 3 ATTRIBUTE_VALUE
[ENC] parsing TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] 16 bytes left, parsing recursively TRANSFORM_ATTRIBUTE_V1
[ENC] parsing TRANSFORM_ATTRIBUTE_V1 payload, 92 bytes left
[ENC] parsing rule 0 ATTRIBUTE_FORMAT
[ENC] parsing rule 1 ATTRIBUTE_TYPE
[ENC] parsing rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] parsing rule 3 ATTRIBUTE_VALUE
[ENC] parsing TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] 12 bytes left, parsing recursively TRANSFORM_ATTRIBUTE_V1
[ENC] parsing TRANSFORM_ATTRIBUTE_V1 payload, 88 bytes left
[ENC] parsing rule 0 ATTRIBUTE_FORMAT
[ENC] parsing rule 1 ATTRIBUTE_TYPE
[ENC] parsing rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] parsing rule 3 ATTRIBUTE_VALUE
[ENC] parsing TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] 8 bytes left, parsing recursively TRANSFORM_ATTRIBUTE_V1
[ENC] parsing TRANSFORM_ATTRIBUTE_V1 payload, 84 bytes left
[ENC] parsing rule 0 ATTRIBUTE_FORMAT
[ENC] parsing rule 1 ATTRIBUTE_TYPE
[ENC] parsing rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] parsing rule 3 ATTRIBUTE_VALUE
[ENC] parsing TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] 4 bytes left, parsing recursively TRANSFORM_ATTRIBUTE_V1
[ENC] parsing TRANSFORM_ATTRIBUTE_V1 payload, 80 bytes left
[ENC] parsing rule 0 ATTRIBUTE_FORMAT
[ENC] parsing rule 1 ATTRIBUTE_TYPE
[ENC] parsing rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] parsing rule 3 ATTRIBUTE_VALUE
[ENC] parsing TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] parsing TRANSFORM_SUBSTRUCTURE_V1 payload finished
[ENC] parsing PROPOSAL_SUBSTRUCTURE_V1 payload finished
[ENC] parsing SECURITY_ASSOCIATION_V1 payload finished
[ENC] verifying payload of type SECURITY_ASSOCIATION_V1
[ENC] SECURITY_ASSOCIATION_V1 payload verified, adding to payload list
[ENC] starting parsing a VENDOR_ID_V1 payload
[ENC] parsing VENDOR_ID_V1 payload, 76 bytes left
[ENC] parsing rule 0 U_INT_8
[ENC] parsing rule 1 FLAG
[ENC] parsing rule 2 RESERVED_BIT
[ENC] parsing rule 3 RESERVED_BIT
[ENC] parsing rule 4 RESERVED_BIT
[ENC] parsing rule 5 RESERVED_BIT
[ENC] parsing rule 6 RESERVED_BIT
[ENC] parsing rule 7 RESERVED_BIT
[ENC] parsing rule 8 RESERVED_BIT
[ENC] parsing rule 9 PAYLOAD_LENGTH
[ENC] parsing rule 10 CHUNK_DATA
[ENC] parsing VENDOR_ID_V1 payload finished
[ENC] verifying payload of type VENDOR_ID_V1
[ENC] VENDOR_ID_V1 payload verified, adding to payload list
[ENC] starting parsing a VENDOR_ID_V1 payload
[ENC] parsing VENDOR_ID_V1 payload, 64 bytes left
[ENC] parsing rule 0 U_INT_8
[ENC] parsing rule 1 FLAG
[ENC] parsing rule 2 RESERVED_BIT
[ENC] parsing rule 3 RESERVED_BIT
[ENC] parsing rule 4 RESERVED_BIT
[ENC] parsing rule 5 RESERVED_BIT
[ENC] parsing rule 6 RESERVED_BIT
[ENC] parsing rule 7 RESERVED_BIT
[ENC] parsing rule 8 RESERVED_BIT
[ENC] parsing rule 9 PAYLOAD_LENGTH
[ENC] parsing rule 10 CHUNK_DATA
[ENC] parsing VENDOR_ID_V1 payload finished
[ENC] verifying payload of type VENDOR_ID_V1
[ENC] VENDOR_ID_V1 payload verified, adding to payload list
[ENC] starting parsing a VENDOR_ID_V1 payload
[ENC] parsing VENDOR_ID_V1 payload, 44 bytes left
[ENC] parsing rule 0 U_INT_8
[ENC] parsing rule 1 FLAG
[ENC] parsing rule 2 RESERVED_BIT
[ENC] parsing rule 3 RESERVED_BIT
[ENC] parsing rule 4 RESERVED_BIT
[ENC] parsing rule 5 RESERVED_BIT
[ENC] parsing rule 6 RESERVED_BIT
[ENC] parsing rule 7 RESERVED_BIT
[ENC] parsing rule 8 RESERVED_BIT
[ENC] parsing rule 9 PAYLOAD_LENGTH
[ENC] parsing rule 10 CHUNK_DATA
[ENC] parsing VENDOR_ID_V1 payload finished
[ENC] verifying payload of type VENDOR_ID_V1
[ENC] VENDOR_ID_V1 payload verified, adding to payload list
[ENC] starting parsing a VENDOR_ID_V1 payload
[ENC] parsing VENDOR_ID_V1 payload, 20 bytes left
[ENC] parsing rule 0 U_INT_8
[ENC] parsing rule 1 FLAG
[ENC] parsing rule 2 RESERVED_BIT
[ENC] parsing rule 3 RESERVED_BIT
[ENC] parsing rule 4 RESERVED_BIT
[ENC] parsing rule 5 RESERVED_BIT
[ENC] parsing rule 6 RESERVED_BIT
[ENC] parsing rule 7 RESERVED_BIT
[ENC] parsing rule 8 RESERVED_BIT
[ENC] parsing rule 9 PAYLOAD_LENGTH
[ENC] parsing rule 10 CHUNK_DATA
[ENC] parsing VENDOR_ID_V1 payload finished
[ENC] verifying payload of type VENDOR_ID_V1
[ENC] VENDOR_ID_V1 payload verified, adding to payload list
[ENC] process payload of type SECURITY_ASSOCIATION_V1
[ENC] process payload of type VENDOR_ID_V1
[ENC] process payload of type VENDOR_ID_V1
[ENC] process payload of type VENDOR_ID_V1
[ENC] process payload of type VENDOR_ID_V1
[ENC] verifying message structure
[ENC] found payload of type SECURITY_ASSOCIATION_V1
[ENC] found payload of type VENDOR_ID_V1
[ENC] found payload of type VENDOR_ID_V1
[ENC] found payload of type VENDOR_ID_V1
[ENC] found payload of type VENDOR_ID_V1
[ENC] parsed ID_PROT response 0 [ SA V V V V ]
[IKE] received XAuth vendor ID
[IKE] received DPD vendor ID
[IKE] received FRAGMENTATION vendor ID
[IKE] received NAT-T (RFC 3947) vendor ID
[CFG] selecting proposal:
[CFG] proposal matches
[CFG] received proposals: IKE:AES_CBC_256/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024
[CFG] configured proposals: IKE:AES_CBC_256/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024, IKE:AES_CBC_128/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024
[CFG] selected proposal: IKE:AES_CBC_256/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024
[IKE] reinitiating already active tasks
[IKE] ISAKMP_VENDOR task
[IKE] MAIN_MODE task
[LIB] size of DH secret exponent: 1023 bits
[ENC] added payload of type KEY_EXCHANGE_V1 to message
[ENC] added payload of type NONCE_V1 to message
[ENC] added payload of type NAT_D_V1 to message
[ENC] added payload of type NAT_D_V1 to message
[ENC] order payloads in message
[ENC] added payload of type KEY_EXCHANGE_V1 to message
[ENC] added payload of type NONCE_V1 to message
[ENC] added payload of type NAT_D_V1 to message
[ENC] added payload of type NAT_D_V1 to message
[ENC] generating ID_PROT request 0 [ KE No NAT-D NAT-D ]
[ENC] not encrypting payloads
[ENC] generating payload of type HEADER
[ENC] generating rule 0 IKE_SPI
[ENC] generating rule 1 IKE_SPI
[ENC] generating rule 2 U_INT_8
[ENC] generating rule 3 U_INT_4
[ENC] generating rule 4 U_INT_4
[ENC] generating rule 5 U_INT_8
[ENC] generating rule 6 RESERVED_BIT
[ENC] generating rule 7 RESERVED_BIT
[ENC] generating rule 8 FLAG
[ENC] generating rule 9 FLAG
[ENC] generating rule 10 FLAG
[ENC] generating rule 11 FLAG
[ENC] generating rule 12 FLAG
[ENC] generating rule 13 FLAG
[ENC] generating rule 14 U_INT_32
[ENC] generating rule 15 HEADER_LENGTH
[ENC] generating HEADER payload finished
[ENC] generating payload of type KEY_EXCHANGE_V1
[ENC] generating rule 0 U_INT_8
[ENC] generating rule 1 RESERVED_BYTE
[ENC] generating rule 2 PAYLOAD_LENGTH
[ENC] generating rule 3 CHUNK_DATA
[ENC] generating KEY_EXCHANGE_V1 payload finished
[ENC] generating payload of type NONCE_V1
[ENC] generating rule 0 U_INT_8
[ENC] generating rule 1 FLAG
[ENC] generating rule 2 RESERVED_BIT
[ENC] generating rule 3 RESERVED_BIT
[ENC] generating rule 4 RESERVED_BIT
[ENC] generating rule 5 RESERVED_BIT
[ENC] generating rule 6 RESERVED_BIT
[ENC] generating rule 7 RESERVED_BIT
[ENC] generating rule 8 RESERVED_BIT
[ENC] generating rule 9 PAYLOAD_LENGTH
[ENC] generating rule 10 CHUNK_DATA
[ENC] generating NONCE_V1 payload finished
[ENC] generating payload of type NAT_D_V1
[ENC] generating rule 0 U_INT_8
[ENC] generating rule 1 RESERVED_BYTE
[ENC] generating rule 2 PAYLOAD_LENGTH
[ENC] generating rule 3 CHUNK_DATA
[ENC] generating NAT_D_V1 payload finished
[ENC] generating payload of type NAT_D_V1
[ENC] generating rule 0 U_INT_8
[ENC] generating rule 1 RESERVED_BYTE
[ENC] generating rule 2 PAYLOAD_LENGTH
[ENC] generating rule 3 CHUNK_DATA
[ENC] generating NAT_D_V1 payload finished
[NET] sending packet: from 100.64.206.174[500] to 116.90.86.181[500] (244 bytes)
[MGR] checkin IKE_SA dmvpn-DEVELVPN-tun0[100]
[MGR] checkin of IKE_SA successful
[NET] received packet: from 116.90.86.181[500] to 100.64.206.174[500] (244 bytes)
[ENC] parsing body of message, first payload is KEY_EXCHANGE_V1
[ENC] starting parsing a KEY_EXCHANGE_V1 payload
[ENC] parsing KEY_EXCHANGE_V1 payload, 216 bytes left
[ENC] parsing rule 0 U_INT_8
[ENC] parsing rule 1 RESERVED_BYTE
[ENC] parsing rule 2 PAYLOAD_LENGTH
[ENC] parsing rule 3 CHUNK_DATA
[ENC] parsing KEY_EXCHANGE_V1 payload finished
[ENC] verifying payload of type KEY_EXCHANGE_V1
[ENC] KEY_EXCHANGE_V1 payload verified, adding to payload list
[ENC] starting parsing a NONCE_V1 payload
[ENC] parsing NONCE_V1 payload, 84 bytes left
[ENC] parsing rule 0 U_INT_8
[ENC] parsing rule 1 FLAG
[ENC] parsing rule 2 RESERVED_BIT
[ENC] parsing rule 3 RESERVED_BIT
[ENC] parsing rule 4 RESERVED_BIT
[ENC] parsing rule 5 RESERVED_BIT
[ENC] parsing rule 6 RESERVED_BIT
[ENC] parsing rule 7 RESERVED_BIT
[ENC] parsing rule 8 RESERVED_BIT
[ENC] parsing rule 9 PAYLOAD_LENGTH
[ENC] parsing rule 10 CHUNK_DATA
[ENC] parsing NONCE_V1 payload finished
[ENC] verifying payload of type NONCE_V1
[ENC] NONCE_V1 payload verified, adding to payload list
[ENC] starting parsing a NAT_D_V1 payload
[ENC] parsing NAT_D_V1 payload, 48 bytes left
[ENC] parsing rule 0 U_INT_8
[ENC] parsing rule 1 RESERVED_BYTE
[ENC] parsing rule 2 PAYLOAD_LENGTH
[ENC] parsing rule 3 CHUNK_DATA
[ENC] parsing NAT_D_V1 payload finished
[ENC] verifying payload of type NAT_D_V1
[ENC] NAT_D_V1 payload verified, adding to payload list
[ENC] starting parsing a NAT_D_V1 payload
[ENC] parsing NAT_D_V1 payload, 24 bytes left
[ENC] parsing rule 0 U_INT_8
[ENC] parsing rule 1 RESERVED_BYTE
[ENC] parsing rule 2 PAYLOAD_LENGTH
[ENC] parsing rule 3 CHUNK_DATA
[ENC] parsing NAT_D_V1 payload finished
[ENC] verifying payload of type NAT_D_V1
[ENC] NAT_D_V1 payload verified, adding to payload list
[ENC] process payload of type KEY_EXCHANGE_V1
[ENC] process payload of type NONCE_V1
[ENC] process payload of type NAT_D_V1
[ENC] process payload of type NAT_D_V1
[ENC] verifying message structure
[ENC] found payload of type KEY_EXCHANGE_V1
[ENC] found payload of type NONCE_V1
[ENC] found payload of type NAT_D_V1
[ENC] found payload of type NAT_D_V1
[ENC] parsed ID_PROT response 0 [ KE No NAT-D NAT-D ]
[IKE] local host is behind NAT, sending keep alives
[IKE] reinitiating already active tasks
[IKE] ISAKMP_VENDOR task
[IKE] MAIN_MODE task
[ENC] added payload of type ID_V1 to message
[ENC] added payload of type HASH_V1 to message
[ENC] order payloads in message
[ENC] added payload of type ID_V1 to message
[ENC] added payload of type HASH_V1 to message
[ENC] generating ID_PROT request 0 [ ID HASH ]
[ENC] insert payload ID_V1 into encrypted payload
[ENC] insert payload HASH_V1 into encrypted payload
[ENC] generating payload of type HEADER
[ENC] generating rule 0 IKE_SPI
[ENC] generating rule 1 IKE_SPI
[ENC] generating rule 2 U_INT_8
[ENC] generating rule 3 U_INT_4
[ENC] generating rule 4 U_INT_4
[ENC] generating rule 5 U_INT_8
[ENC] generating rule 6 RESERVED_BIT
[ENC] generating rule 7 RESERVED_BIT
[ENC] generating rule 8 FLAG
[ENC] generating rule 9 FLAG
[ENC] generating rule 10 FLAG
[ENC] generating rule 11 FLAG
[ENC] generating rule 12 FLAG
[ENC] generating rule 13 FLAG
[ENC] generating rule 14 U_INT_32
[ENC] generating rule 15 HEADER_LENGTH
[ENC] generating HEADER payload finished
[ENC] generating payload of type ID_V1
[ENC] generating rule 0 U_INT_8
[ENC] generating rule 1 RESERVED_BYTE
[ENC] generating rule 2 PAYLOAD_LENGTH
[ENC] generating rule 3 U_INT_8
[ENC] generating rule 4 U_INT_8
[ENC] generating rule 5 U_INT_16
[ENC] generating rule 6 CHUNK_DATA
[ENC] generating ID_V1 payload finished
[ENC] generating payload of type HASH_V1
[ENC] generating rule 0 U_INT_8
[ENC] generating rule 1 RESERVED_BYTE
[ENC] generating rule 2 PAYLOAD_LENGTH
[ENC] generating rule 3 CHUNK_DATA
[ENC] generating HASH_V1 payload finished
[ENC] generated content in encrypted payload
[ENC] generating payload of type ENCRYPTED_V1
[ENC] generating rule 0 ENCRYPTED_DATA
[ENC] generating ENCRYPTED_V1 payload finished
[NET] sending packet: from 100.64.206.174[4500] to 116.90.86.181[4500] (76 bytes)
[MGR] checkin IKE_SA dmvpn-DEVELVPN-tun0[100]
[MGR] checkin of IKE_SA successful
[NET] received packet: from 116.90.86.181[4500] to 100.64.206.174[4500] (76 bytes)
[ENC] parsing body of message, first payload is ID_V1
[ENC] parsing ENCRYPTED_V1 payload, 48 bytes left
[ENC] parsing rule 0 ENCRYPTED_DATA
[ENC] parsing ENCRYPTED_V1 payload finished
[ENC] process payload of type ENCRYPTED_V1
[ENC] found an encrypted payload
[ENC] parsing ID_V1 payload, 48 bytes left
[ENC] parsing rule 0 U_INT_8
[ENC] parsing rule 1 RESERVED_BYTE
[ENC] parsing rule 2 PAYLOAD_LENGTH
[ENC] parsing rule 3 U_INT_8
[ENC] parsing rule 4 U_INT_8
[ENC] parsing rule 5 U_INT_16
[ENC] parsing rule 6 CHUNK_DATA
[ENC] parsing ID_V1 payload finished
[ENC] parsing HASH_V1 payload, 36 bytes left
[ENC] parsing rule 0 U_INT_8
[ENC] parsing rule 1 RESERVED_BYTE
[ENC] parsing rule 2 PAYLOAD_LENGTH
[ENC] parsing rule 3 CHUNK_DATA
[ENC] parsing HASH_V1 payload finished
[ENC] parsed content of encrypted payload
[ENC] insert decrypted payload of type ID_V1 at end of list
[ENC] insert decrypted payload of type HASH_V1 at end of list
[ENC] verifying message structure
[ENC] found payload of type ID_V1
[ENC] found payload of type HASH_V1
[ENC] parsed ID_PROT response 0 [ ID HASH ]
[IKE] IKE_SA dmvpn-DEVELVPN-tun0[100] established between 100.64.206.174[100.64.206.174]...116.90.86.181[116.90.86.181]
[IKE] IKE_SA dmvpn-DEVELVPN-tun0[100] state change: CONNECTING => ESTABLISHED
[IKE] scheduling rekeying in 3559s
[IKE] maximum IKE_SA lifetime 3919s
[IKE] activating new tasks
[IKE] activating QUICK_MODE task
[CFG] configured proposals: ESP:AES_CBC_256/HMAC_SHA1_96/MODP_1024/NO_EXT_SEQ, ESP:3DES_CBC/HMAC_MD5_96/MODP_1024/NO_EXT_SEQ
[KNL] got SPI c7d749ca
[CFG] configured proposals: ESP:AES_CBC_256/HMAC_SHA1_96/MODP_1024/NO_EXT_SEQ, ESP:3DES_CBC/HMAC_MD5_96/MODP_1024/NO_EXT_SEQ
[LIB] size of DH secret exponent: 1023 bits
[ENC] added payload of type SECURITY_ASSOCIATION_V1 to message
[ENC] added payload of type NONCE_V1 to message
[ENC] added payload of type KEY_EXCHANGE_V1 to message
[CFG] proposing traffic selectors for us:
[CFG] 115.60.59.223/32[gre]
[CFG] proposing traffic selectors for other:
[CFG] 116.90.86.181/32[gre]
[ENC] added payload of type ID_V1 to message
[ENC] added payload of type ID_V1 to message
[ENC] order payloads in message
[ENC] added payload of type SECURITY_ASSOCIATION_V1 to message
[ENC] added payload of type NONCE_V1 to message
[ENC] added payload of type KEY_EXCHANGE_V1 to message
[ENC] added payload of type ID_V1 to message
[ENC] added payload of type ID_V1 to message
[ENC] generating QUICK_MODE request 2108957326 [ HASH SA No KE ID ID ]
[ENC] insert payload HASH_V1 into encrypted payload
[ENC] insert payload SECURITY_ASSOCIATION_V1 into encrypted payload
[ENC] insert payload NONCE_V1 into encrypted payload
[ENC] insert payload KEY_EXCHANGE_V1 into encrypted payload
[ENC] insert payload ID_V1 into encrypted payload
[ENC] insert payload ID_V1 into encrypted payload
[ENC] generating payload of type HEADER
[ENC] generating rule 0 IKE_SPI
[ENC] generating rule 1 IKE_SPI
[ENC] generating rule 2 U_INT_8
[ENC] generating rule 3 U_INT_4
[ENC] generating rule 4 U_INT_4
[ENC] generating rule 5 U_INT_8
[ENC] generating rule 6 RESERVED_BIT
[ENC] generating rule 7 RESERVED_BIT
[ENC] generating rule 8 FLAG
[ENC] generating rule 9 FLAG
[ENC] generating rule 10 FLAG
[ENC] generating rule 11 FLAG
[ENC] generating rule 12 FLAG
[ENC] generating rule 13 FLAG
[ENC] generating rule 14 U_INT_32
[ENC] generating rule 15 HEADER_LENGTH
[ENC] generating HEADER payload finished
[ENC] generating payload of type HASH_V1
[ENC] generating rule 0 U_INT_8
[ENC] generating rule 1 RESERVED_BYTE
[ENC] generating rule 2 PAYLOAD_LENGTH
[ENC] generating rule 3 CHUNK_DATA
[ENC] generating HASH_V1 payload finished
[ENC] generating payload of type SECURITY_ASSOCIATION_V1
[ENC] generating rule 0 U_INT_8
[ENC] generating rule 1 RESERVED_BIT
[ENC] generating rule 2 RESERVED_BIT
[ENC] generating rule 3 RESERVED_BIT
[ENC] generating rule 4 RESERVED_BIT
[ENC] generating rule 5 RESERVED_BIT
[ENC] generating rule 6 RESERVED_BIT
[ENC] generating rule 7 RESERVED_BIT
[ENC] generating rule 8 RESERVED_BIT
[ENC] generating rule 9 PAYLOAD_LENGTH
[ENC] generating rule 10 U_INT_32
[ENC] generating rule 11 U_INT_32
[ENC] generating rule 12 (1259)
[ENC] generating payload of type PROPOSAL_SUBSTRUCTURE_V1
[ENC] generating rule 0 U_INT_8
[ENC] generating rule 1 RESERVED_BYTE
[ENC] generating rule 2 PAYLOAD_LENGTH
[ENC] generating rule 3 U_INT_8
[ENC] generating rule 4 U_INT_8
[ENC] generating rule 5 SPI_SIZE
[ENC] generating rule 6 U_INT_8
[ENC] generating rule 7 SPI
[ENC] generating rule 8 (1261)
[ENC] generating payload of type TRANSFORM_SUBSTRUCTURE_V1
[ENC] generating rule 0 U_INT_8
[ENC] generating rule 1 RESERVED_BYTE
[ENC] generating rule 2 PAYLOAD_LENGTH
[ENC] generating rule 3 U_INT_8
[ENC] generating rule 4 U_INT_8
[ENC] generating rule 5 RESERVED_BYTE
[ENC] generating rule 6 RESERVED_BYTE
[ENC] generating rule 7 (1263)
[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
[ENC] generating rule 0 ATTRIBUTE_FORMAT
[ENC] generating rule 1 ATTRIBUTE_TYPE
[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] generating rule 3 ATTRIBUTE_VALUE
[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
[ENC] generating rule 0 ATTRIBUTE_FORMAT
[ENC] generating rule 1 ATTRIBUTE_TYPE
[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] generating rule 3 ATTRIBUTE_VALUE
[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
[ENC] generating rule 0 ATTRIBUTE_FORMAT
[ENC] generating rule 1 ATTRIBUTE_TYPE
[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] generating rule 3 ATTRIBUTE_VALUE
[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
[ENC] generating rule 0 ATTRIBUTE_FORMAT
[ENC] generating rule 1 ATTRIBUTE_TYPE
[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] generating rule 3 ATTRIBUTE_VALUE
[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
[ENC] generating rule 0 ATTRIBUTE_FORMAT
[ENC] generating rule 1 ATTRIBUTE_TYPE
[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] generating rule 3 ATTRIBUTE_VALUE
[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
[ENC] generating rule 0 ATTRIBUTE_FORMAT
[ENC] generating rule 1 ATTRIBUTE_TYPE
[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] generating rule 3 ATTRIBUTE_VALUE
[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] generating TRANSFORM_SUBSTRUCTURE_V1 payload finished
[ENC] generating payload of type TRANSFORM_SUBSTRUCTURE_V1
[ENC] generating rule 0 U_INT_8
[ENC] generating rule 1 RESERVED_BYTE
[ENC] generating rule 2 PAYLOAD_LENGTH
[ENC] generating rule 3 U_INT_8
[ENC] generating rule 4 U_INT_8
[ENC] generating rule 5 RESERVED_BYTE
[ENC] generating rule 6 RESERVED_BYTE
[ENC] generating rule 7 (1263)
[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
[ENC] generating rule 0 ATTRIBUTE_FORMAT
[ENC] generating rule 1 ATTRIBUTE_TYPE
[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] generating rule 3 ATTRIBUTE_VALUE
[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
[ENC] generating rule 0 ATTRIBUTE_FORMAT
[ENC] generating rule 1 ATTRIBUTE_TYPE
[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] generating rule 3 ATTRIBUTE_VALUE
[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
[ENC] generating rule 0 ATTRIBUTE_FORMAT
[ENC] generating rule 1 ATTRIBUTE_TYPE
[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] generating rule 3 ATTRIBUTE_VALUE
[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
[ENC] generating rule 0 ATTRIBUTE_FORMAT
[ENC] generating rule 1 ATTRIBUTE_TYPE
[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] generating rule 3 ATTRIBUTE_VALUE
[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
[ENC] generating rule 0 ATTRIBUTE_FORMAT
[ENC] generating rule 1 ATTRIBUTE_TYPE
[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
[ENC] generating rule 3 ATTRIBUTE_VALUE
[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
[ENC] generating TRANSFORM_SUBSTRUCTURE_V1 payload finished
[ENC] generating PROPOSAL_SUBSTRUCTURE_V1 payload finished
[ENC] generating SECURITY_ASSOCIATION_V1 payload finished
[ENC] generating payload of type NONCE_V1
[ENC] generating rule 0 U_INT_8
[ENC] generating rule 1 FLAG
[ENC] generating rule 2 RESERVED_BIT
[ENC] generating rule 3 RESERVED_BIT
[ENC] generating rule 4 RESERVED_BIT
[ENC] generating rule 5 RESERVED_BIT
[ENC] generating rule 6 RESERVED_BIT
[ENC] generating rule 7 RESERVED_BIT
[ENC] generating rule 8 RESERVED_BIT
[ENC] generating rule 9 PAYLOAD_LENGTH
[ENC] generating rule 10 CHUNK_DATA
[ENC] generating NONCE_V1 payload finished
[ENC] generating payload of type KEY_EXCHANGE_V1
[ENC] generating rule 0 U_INT_8
[ENC] generating rule 1 RESERVED_BYTE
[ENC] generating rule 2 PAYLOAD_LENGTH
[ENC] generating rule 3 CHUNK_DATA
[ENC] generating KEY_EXCHANGE_V1 payload finished
[ENC] generating payload of type ID_V1
[ENC] generating rule 0 U_INT_8
[ENC] generating rule 1 RESERVED_BYTE
[ENC] generating rule 2 PAYLOAD_LENGTH
[ENC] generating rule 3 U_INT_8
[ENC] generating rule 4 U_INT_8
[ENC] generating rule 5 U_INT_16
[ENC] generating rule 6 CHUNK_DATA
[ENC] generating ID_V1 payload finished
[ENC] generating payload of type ID_V1
[ENC] generating rule 0 U_INT_8
[ENC] generating rule 1 RESERVED_BYTE
[ENC] generating rule 2 PAYLOAD_LENGTH
[ENC] generating rule 3 U_INT_8
[ENC] generating rule 4 U_INT_8
[ENC] generating rule 5 U_INT_16
[ENC] generating rule 6 CHUNK_DATA
[ENC] generating ID_V1 payload finished
[ENC] generated content in encrypted payload
[ENC] generating payload of type ENCRYPTED_V1
[ENC] generating rule 0 ENCRYPTED_DATA
[ENC] generating ENCRYPTED_V1 payload finished
[NET] sending packet: from 100.64.206.174[4500] to 116.90.86.181[4500] (332 bytes)
[MGR] checkin IKE_SA dmvpn-DEVELVPN-tun0[100]
[MGR] checkin of IKE_SA successful
[NET] received packet: from 116.90.86.181[4500] to 100.64.206.174[4500] (76 bytes)
[ENC] parsing body of message, first payload is HASH_V1
[ENC] parsing ENCRYPTED_V1 payload, 48 bytes left
[ENC] parsing rule 0 ENCRYPTED_DATA
[ENC] parsing ENCRYPTED_V1 payload finished
[ENC] process payload of type ENCRYPTED_V1
[ENC] found an encrypted payload
[ENC] parsing HASH_V1 payload, 48 bytes left
[ENC] parsing rule 0 U_INT_8
[ENC] parsing rule 1 RESERVED_BYTE
[ENC] parsing rule 2 PAYLOAD_LENGTH
[ENC] parsing rule 3 CHUNK_DATA
[ENC] parsing HASH_V1 payload finished
[ENC] parsing NOTIFY_V1 payload, 24 bytes left
[ENC] parsing rule 0 U_INT_8
[ENC] parsing rule 1 RESERVED_BIT
[ENC] parsing rule 2 RESERVED_BIT
[ENC] parsing rule 3 RESERVED_BIT
[ENC] parsing rule 4 RESERVED_BIT
[ENC] parsing rule 5 RESERVED_BIT
[ENC] parsing rule 6 RESERVED_BIT
[ENC] parsing rule 7 RESERVED_BIT
[ENC] parsing rule 8 RESERVED_BIT
[ENC] parsing rule 9 PAYLOAD_LENGTH
[ENC] parsing rule 10 U_INT_32
[ENC] parsing rule 11 U_INT_8
[ENC] parsing rule 12 SPI_SIZE
[ENC] parsing rule 13 U_INT_16
[ENC] parsing rule 14 SPI
[ENC] parsing rule 15 CHUNK_DATA
[ENC] parsing NOTIFY_V1 payload finished
[ENC] parsed content of encrypted payload
[ENC] insert decrypted payload of type HASH_V1 at end of list
[ENC] insert decrypted payload of type NOTIFY_V1 at end of list
[ENC] verifying message structure
[ENC] found payload of type NOTIFY_V1
[ENC] found payload of type NOTIFY_V1
[ENC] parsed INFORMATIONAL_V1 request 2815069379 [ HASH N(INVAL_ID) ]
[IKE] received INVALID_ID_INFORMATION error notify
[CHD] CHILD_SA dmvpn{241} state change: CREATED => DESTROYING
[KNL] deleting SAD entry with SPI c7d749ca
[KNL] deleted SAD entry with SPI c7d749ca
[MGR] checkin IKE_SA dmvpn-DEVELVPN-tun0[100]
[MGR] checkin of IKE_SA successful
initiate failed: establishing CHILD_SA 'dmvpn' failed
[edit]
@bjtangseng Can you post the output, than i can maybe look and mod things.
Now I will help you test DMVPN, If you have time, maybe we can do it together
@bjtangseng thanks!
jool 4.0.0 has been released.
http://jool.mx/en/index.html
Jan 22 2019
I have taken a look at the steps for moving the commands into a separate shell script.
OK, I will test at tomorrow night (Beijing Time). If have any information, I will send messages
@bjtangseng The spoke, and do not reboot.
make sure hub is up and do changes mentioned in previous post on the spoke (no reboot)
and post the output of:
which site you want to change, Hub site or Spoke Site. last time I change swanctl.conf file, If I reboot Vyos that file will be change back to dynamic[gre].
Jan 21 2019
@bjtangseng
can you please edit your swanctl.conf file and put the local_ts to 115.60.62.155/32[gre] ( local_ts = 115.60.62.155/32[gre] )
after editing swanctl please run:
sudo swanctl -q
then please check if you can connect with:
sudo swanctl -i -c dmvpn -S 100.64.161.96 -R 116.90.86.181 -l 2
or:
sudo swanctl -i -c dmvpn -S 0.0.0.0 -R 116.90.86.181 -l 2
Can't reproduce with EPA3
Today, I try to edit swancl.conf, but doesn't work. I will wait you new build. I can test that again
Jan 20 2019
Hi all, I honestly forgot that I wrote this or I would have closed it. I'll go through and check for any other tickets I have open shortly.
@bjtangseng could you try with IKEv2 on both hub and spoke?
set vpn ipsec ike-group IKE-HUB key-exchange ikev2 for hub
set vpn ipsec ike-group IKE-SPOKE key-exchange ikev2 for spoke.
We need more info and full config