Project

General

Profile

Actions

Regression #14217

closed

IPsec Phase 2 rekey failures with some PFS key groups

Added by Georgiy Tyutyunnik about 1 year ago. Updated about 1 year ago.

Status:
Resolved
Priority:
Normal
Category:
IPsec
Target version:
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
23.05
Release Notes:
Default
Affected Version:
2.7.0
Affected Architecture:

Description

IPSec phase 2 with some specific PFS key groups fails to rekey with the following logs message:

Mar 31 12:47:14 charon 84020 10[IKE] <con1|1> unable to install inbound and outbound IPsec SA (SAD) in kernel
Tunnel initiation establishes phase2 successfully, but the phase2 can't rekey and times out. Only bouncing phase1 brings it back.
Affected PFS key groups: 18,19,23,24,27,28,30,31,32.
Logs for the rekey and end-of-lifetime of the affected phase2 attached


Files

logs2301rekey.txt (3.09 KB) logs2301rekey.txt Georgiy Tyutyunnik, 03/31/2023 10:20 AM
logs2301eolp2.txt (12.5 KB) logs2301eolp2.txt Georgiy Tyutyunnik, 03/31/2023 10:20 AM
before-rekey.png (106 KB) before-rekey.png Jim Pingle, 04/18/2023 12:45 PM
after-rekey.png (110 KB) after-rekey.png Jim Pingle, 04/18/2023 12:45 PM
Actions

Also available in: Atom PDF