LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 12-17-2016, 02:47 PM   #1
psycroptic
Member
 
Registered: Aug 2011
Location: USA
Distribution: ArchLinux - 3.0 kernel
Posts: 349

Rep: Reputation: Disabled
Strongswan randomly deletes IPsec connection after rekey


I have the following certificate-based config for Windows 7 to Strongswan 5.2.2 in a remote-access setup:

Code:
conn USB
        keyexchange=ikev2
        ike=aes256-sha1-modp1024!
        esp=aes256-sha1!
        dpdaction=clear
        dpddelay=8s
        dpdtimeout=80s
        rekey=no
        margintime=0m
        rekeyfuzz=0%
        ikelifetime=8h
        lifetime=1h
        auto=add
        leftauth=pubkey
        #rightauth=eap-mschapv2
        rightauth=pubkey
        leftcert=/config/auth/certs/Gateway.RemoteAccess.crt.der
        left=%any
        leftsubnet=0.0.0.0/0
        leftfirewall=yes
        leftid="C=US, ST=state, CN=Gateway"
        right=%any
        rightca=%same
        rightsourceip=192.168.252.8/30
        rightid="C=US, ST=state, CN=Win7"
        rightdns=172.16.16.2
        eap_identity=%any
I can successfully connect using the built-in Win7 VPN client. However, immediately after Windows initiates a re-key, the connection is randomly deleted!!

Here is the output of "swanctl --log". Of course, it is nearly useless:

Code:
12[NET] received packet: from 68.52.125.y[4500] to 76.221.222.x[4500] (568 bytes)
12[ENC] parsed CREATE_CHILD_SA request 14 [ SA KE No ]
12[IKE] 68.52.125.y is initiating an IKE_SA
12[ENC] generating CREATE_CHILD_SA response 14 [ SA No KE ]
12[NET] sending packet: from 76.221.222.x[4500] to 68.52.125.y[4500] (312 bytes)
07[NET] received packet: from 68.52.125.y[4500] to 76.221.222.x[4500] (88 bytes)
07[ENC] parsed INFORMATIONAL request 15 [ D ]
07[IKE] IKE_SA USB[18] rekeyed between 76.221.222.x[C=US, ST=state, CN=Gateway]...68.52.125.y[C=US, ST=state, CN=Win7]
07[IKE] received DELETE for IKE_SA USB[14]
07[IKE] deleting IKE_SA USB[14] between 76.221.222.x[C=US, ST=state, CN=Gateway]...68.52.125.y[C=US, ST=state, CN=Win7]
07[IKE] IKE_SA deleted
07[ENC] generating INFORMATIONAL response 15 [ ]
07[NET] sending packet: from 76.221.222.x[4500] to 68.52.125.y[4500] (88 bytes)
16[IKE] sending DPD request
16[ENC] generating INFORMATIONAL request 0 [ ]
16[NET] sending packet: from 76.221.222.x[4500] to 68.52.125.y[4500] (76 bytes)
13[IKE] retransmit 1 of request with message ID 0
13[NET] sending packet: from 76.221.222.x[4500] to 68.52.125.y[4500] (76 bytes)
12[IKE] retransmit 2 of request with message ID 0
12[NET] sending packet: from 76.221.222.x[4500] to 68.52.125.y[4500] (76 bytes)
16[IKE] retransmit 3 of request with message ID 0
16[NET] sending packet: from 76.221.222.x[4500] to 68.52.125.y[4500] (76 bytes)
05[IKE] retransmit 4 of request with message ID 0
05[NET] sending packet: from 76.221.222.x[4500] to 68.52.125.y[4500] (76 bytes)
10[IKE] retransmit 5 of request with message ID 0
10[NET] sending packet: from 76.221.222.x[4500] to 68.52.125.y[4500] (76 bytes)
After the deletion, the Win7 client still thinks it is connected, but of course no traffic flows, and after the DPD interval expires Windows deletes the connection on its end. There is no log of any "Rasman" evnts in the Windows event viewer.


*sigh* I hate Strongswan..... so any idea why it is deleting the connection?

Last edited by psycroptic; 12-17-2016 at 02:57 PM.
 
Old 12-19-2016, 02:34 PM   #2
nini09
Senior Member
 
Registered: Apr 2009
Posts: 1,857

Rep: Reputation: 161Reputation: 161
Based on swanctl --log, strongswan receive deleting request from client. Is there any other device between Window client and strongswan server?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Strongswan-to-Strongswan IPsec VPN - slow with pure ESP, fast w/UDP encapsulation? psycroptic Linux - Networking 0 11-20-2014 07:44 AM
strongswan ipsec can not use for android 4.4 anttsaon Linux - Networking 0 12-07-2013 03:45 PM
strongswan ipsec related Niharika.R Linux - Networking 0 06-03-2012 10:52 PM
Strongswan IPSec problems speakerbox Linux - Networking 2 05-05-2012 02:10 AM
strongswan ipsec culin Linux - Networking 4 08-16-2011 11:31 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 06:59 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration