Quantcast
Channel: All EdgeRouter posts
Viewing all articles
Browse latest Browse all 60861

Not able to get site to site VPN up

$
0
0

Hi,

 

I am trying to a get a site to site VPN link up and I get this error message :

Me@EdgeRouterPro8:~$ sudo swanctl --log
12[IKE] sending retransmit 3 of request message ID 0, seq 1
12[NET] sending packet: from 111.111.111.111[500] to 222.222.222.222[500] (156 bytes)
04[NET] error writing to socket: Invalid argument

What would you suggest I look at? I'm a bit lost, I have reviewed my configs multiple times... This is what show vpn ipsec sa is giving me:

Me@EdgeRouterPro8:/$ show vpn ipsec sa
peer-222.222.222.222-tunnel-1: #1, CONNECTING, IKEv1, 12c0fc157b5e816f:0000000000000000
  local  '%any' @ 111.111.111.111
  remote '%any' @ 222.222.222.222
  queued:  QUICK_MODE
  active:  ISAKMP_VENDOR ISAKMP_CERT_PRE MAIN_MODE ISAKMP_CERT_POST ISAKMP_NATD

And Show vpn debug gives:

Me@EdgeRouterPro8:~$ show vpn debug
Status of IKE charon daemon (strongSwan 5.2.2, Linux 3.10.20-UBNT, mips64):
  uptime: 16 minutes, since Nov 26 10:42:51 2016
  malloc: sbrk 382096, mmap 0, used 265648, free 116448
  worker threads: 11 of 16 idle, 5/0/0/0 working, job queue: 0/0/0/0, scheduled: 1
  loaded plugins: charon ldap sqlite pkcs11 aes des sha1 sha2 md5 random nonce x509 revocation constraints pubkey pkcs1 pkcs8 pem openssl agent xcbc cmac ctr ccm gcm curl attr kernel-netlink resolve socket-default stroke vici updown eap-identity eap-md5 eap-mschapv2 eap-radius eap-tls xauth-generic xauth-eap addrblock
Listening IP addresses:
  192.168.101.1
  192.168.10.51
  172.16.101.1
Connections:
peer-222.222.222.222-tunnel-1:  111.111.111.111...222.222.222.222  IKEv1
peer-222.222.222.222-tunnel-1:   local:  [111.111.111.111] uses pre-shared key authentication
peer-222.222.222.222-tunnel-1:   remote: [222.222.222.222] uses pre-shared key authentication
peer-222.222.222.222-tunnel-1:   child:  192.168.101.0/24 === 10.1.1.0/24 TUNNEL
Routed Connections:
peer-222.222.222.222-tunnel-1{1}:  ROUTED, TUNNEL
peer-222.222.222.222-tunnel-1{1}:   192.168.101.0/24 === 10.1.1.0/24
Security Associations (1 up, 0 connecting):
peer-222.222.222.222-tunnel-1[1]: CONNECTING, 111.111.111.111[%any]...222.222.222.222[%any]
peer-222.222.222.222-tunnel-1[1]: IKEv1 SPIs: 12c0fc157b5e816f_i* 0000000000000000_r
peer-222.222.222.222-tunnel-1[1]: Tasks queued: QUICK_MODE
peer-222.222.222.222-tunnel-1[1]: Tasks active: ISAKMP_VENDOR ISAKMP_CERT_PRE MAIN_MODE ISAKMP_CERT_POST ISAKMP_NATD

Thanks,


Viewing all articles
Browse latest Browse all 60861

Trending Articles