LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 09-28-2018, 02:25 AM   #1
4play
LQ Newbie
 
Registered: Oct 2003
Location: london
Distribution: Centos
Posts: 27

Rep: Reputation: 15
Shrewsoft VPN wont connect


I'm trying to connect to my office VPN that's running pfsense and using ipsec using shrewsoft vpn but it refuses to connect. The same exact config works perfectly on windows but just doesn't connect on fedora 28.

Tried with selinux off, firewall off turned on debug and no errors in the log (which is below, ike-decrypt.pcap is empty). Have tried other vpn clients still nothing.

Any suggestions on how to find the issue here ?

Code:
18/09/28 07:57:40 ## : IKE Daemon, ver 2.2.1
18/09/28 07:57:40 ## : Copyright 2013 Shrew Soft Inc.
18/09/28 07:57:40 ## : This product linked OpenSSL 1.0.2o-fips  27 Mar 2018
18/09/28 07:57:40 ii : opened '/var/log/iked.log'
18/09/28 07:57:40 ii : opened '/var/log/iked/ike-decrypt.pcap'
18/09/28 07:57:40 ii : pfkey process thread begin ...
18/09/28 07:57:40 ii : ipc server process thread begin ...
18/09/28 07:57:40 ii : network process thread begin ...
18/09/28 07:57:40 K< : recv pfkey REGISTER AH message
18/09/28 07:57:40 K< : recv pfkey REGISTER ESP message
18/09/28 07:57:40 K< : recv pfkey REGISTER IPCOMP message
18/09/28 07:57:40 K! : recv X_SPDDUMP message failure ( errno = 2 )
18/09/28 07:57:50 K! : unhandled pfkey message type X_SPDUPDATE ( 13 )
18/09/28 07:57:50 K! : unhandled pfkey message type X_SPDUPDATE ( 13 )
18/09/28 07:57:50 K! : unhandled pfkey message type X_SPDUPDATE ( 13 )
18/09/28 07:57:50 K! : unhandled pfkey message type X_SPDUPDATE ( 13 )
18/09/28 07:57:50 K! : unhandled pfkey message type X_SPDUPDATE ( 13 )
18/09/28 07:57:50 K! : unhandled pfkey message type X_SPDUPDATE ( 13 )
18/09/28 07:57:50 K< : recv pfkey REGISTER AH message ( ignored )
18/09/28 07:57:50 K< : recv pfkey REGISTER ESP message ( ignored )
18/09/28 07:57:50 K< : recv pfkey REGISTER IPCOMP message ( ignored )
18/09/28 08:13:41 ii : ipc client process thread begin ...
18/09/28 08:13:41 <A : peer config add message
18/09/28 08:13:41 <A : proposal config message
18/09/28 08:13:41 <A : proposal config message
18/09/28 08:13:41 <A : client config message
18/09/28 08:13:41 <A : xauth username message
18/09/28 08:13:41 <A : xauth password message
18/09/28 08:13:41 <A : local id 'XXXXXXX' message
18/09/28 08:13:41 <A : preshared key message
18/09/28 08:13:41 <A : peer tunnel enable message
18/09/28 08:13:41 DB : peer added ( obj count = 1 )
18/09/28 08:13:41 ii : local address 192.168.1.147 selected for peer
18/09/28 08:13:41 DB : tunnel added ( obj count = 1 )
18/09/28 08:13:41 DB : new phase1 ( ISAKMP initiator )
18/09/28 08:13:41 DB : exchange type is aggressive
18/09/28 08:13:41 DB : 192.168.1.147:500 <-> 195.188.XX.XX:500
18/09/28 08:13:41 DB : e521c92d2cb30079:0000000000000000
18/09/28 08:13:41 DB : phase1 added ( obj count = 1 )
18/09/28 08:13:41 >> : security association payload
18/09/28 08:13:41 >> : - proposal #1 payload 
18/09/28 08:13:41 >> : -- transform #1 payload 
18/09/28 08:13:41 >> : key exchange payload
18/09/28 08:13:41 >> : nonce payload
18/09/28 08:13:41 >> : identification payload
18/09/28 08:13:41 >> : vendor id payload
18/09/28 08:13:41 ii : local supports XAUTH
18/09/28 08:13:41 >> : vendor id payload
18/09/28 08:13:41 ii : local supports nat-t ( draft v00 )
18/09/28 08:13:41 >> : vendor id payload
18/09/28 08:13:41 ii : local supports nat-t ( draft v01 )
18/09/28 08:13:41 >> : vendor id payload
18/09/28 08:13:41 ii : local supports nat-t ( draft v02 )
18/09/28 08:13:41 >> : vendor id payload
18/09/28 08:13:41 ii : local supports nat-t ( draft v03 )
18/09/28 08:13:41 >> : vendor id payload
18/09/28 08:13:41 ii : local supports nat-t ( rfc )
18/09/28 08:13:41 >> : vendor id payload
18/09/28 08:13:41 >> : vendor id payload
18/09/28 08:13:41 ii : local supports DPDv1
18/09/28 08:13:41 >> : vendor id payload
18/09/28 08:13:41 ii : local is SHREW SOFT compatible
18/09/28 08:13:41 >> : vendor id payload
18/09/28 08:13:41 ii : local is NETSCREEN compatible
18/09/28 08:13:41 >> : vendor id payload
18/09/28 08:13:41 ii : local is SIDEWINDER compatible
18/09/28 08:13:41 >> : vendor id payload
18/09/28 08:13:41 ii : local is CISCO UNITY compatible
18/09/28 08:13:41 >= : cookies e521c92d2cb30079:0000000000000000
18/09/28 08:13:41 >= : message 00000000
18/09/28 08:13:41 -> : send IKE packet 192.168.1.147:500 -> 195.188.XX.XX:500 ( 523 bytes )
18/09/28 08:13:41 DB : phase1 resend event scheduled ( ref count = 2 )
18/09/28 08:13:51 -> : resend 1 phase1 packet(s) [0/2] 192.168.1.147:500 -> 195.188.254.61:500
18/09/28 08:14:01 -> : resend 1 phase1 packet(s) [1/2] 192.168.1.147:500 -> 195.188.254.61:500
18/09/28 08:14:11 -> : resend 1 phase1 packet(s) [2/2] 192.168.1.147:500 -> 195.188.254.61:500
18/09/28 08:14:21 ii : resend limit exceeded for phase1 exchange
18/09/28 08:14:21 ii : phase1 removal before expire time
18/09/28 08:14:21 DB : phase1 deleted ( obj count = 0 )
18/09/28 08:14:21 DB : policy not found
18/09/28 08:14:21 DB : policy not found
18/09/28 08:14:21 DB : removing tunnel config references
18/09/28 08:14:21 DB : removing tunnel phase2 references
18/09/28 08:14:21 DB : removing tunnel phase1 references
18/09/28 08:14:21 DB : tunnel deleted ( obj count = 0 )
18/09/28 08:14:21 DB : removing all peer tunnel references
18/09/28 08:14:21 DB : peer deleted ( obj count = 0 )
18/09/28 08:14:21 ii : ipc client process thread exit ...
 
Old 09-28-2018, 01:04 PM   #2
4play
LQ Newbie
 
Registered: Oct 2003
Location: london
Distribution: Centos
Posts: 27

Original Poster
Rep: Reputation: 15
Guessing it was to do with packets being slightly too large and they have the do not fragment bit set so get dropped upstream.

This fixed it
Code:
echo 1 > /proc/sys/net/ipv4/ip_no_pmtu_disc
echo "net.ipv4.ip_no_pmtu_disc = 1" >> /etc/sysctl.conf
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to connect VPN Client to VPN Server nana12 Linux - Newbie 9 07-12-2017 12:22 AM
[SOLVED] Windows7 VPN clients behind Debian Gateway can not connect to Draytek VPN neopandid Linux - Server 3 08-31-2012 11:34 PM
Connect my netbook to wireless but it wont connect to the internet but it did . Haydn456MJW Linux - Newbie 7 01-26-2011 05:56 PM
Linux VPN Software - How to Connect to a Windows VPN wfernley Linux - Software 2 02-07-2006 09:40 AM
How do i connect Ciscos VPN client to Checkpoint VPN server Klas Linux - Networking 1 11-29-2003 08:00 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 06:19 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration