Project

General

Profile

Actions

Bug #7482

closed

found 1 matching config, but none allows pre-shared key authentication using Main Mode

Added by Emmanux . over 8 years ago. Updated over 8 years ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Category:
-
Target version:
-
Start date:
04/19/2017
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
Affected Architecture:
i386

Description

pfSense 2.3.2-RELEASE

We have many site-to-site vpn's configured in our pfSense, an i386 vm running on vmware.
Three of them suddenly begin to fall, one after the other, 2 a.m. the first one, 3 a.m. the second one, at 6 a.m. the third one falls unrecoverable.
When trying to disconnect and connect again, any of them, on the ipsec log we have:

Apr 19 05:15:34 charon: 12[IKE] <7152> found 1 matching config, but none allows pre-shared key authentication using Main Mode

Apr 19 05:15:34 charon: 12[ENC] <7152> generating INFORMATIONAL_V1 request 4141821673 [ HASH N(AUTH_FAILED) ]

The only solution that we found, was to reboot the vm, completely, after what they started to work OK, just like the rest of the site-to-site vpn configurations.

None of the psk was changed, no change was made since weeks ago.

I'm submitting one of the configurations that failed (that at 6 a.m.):

conn con11000
fragmentation = yes
keyexchange = ikev1
reauth = yes
forceencaps = no
mobike = no

rekey = yes
installpolicy = yes
type = tunnel
dpdaction = clear
dpddelay = 10s
dpdtimeout = 60s
auto = add
left = 1xx.xx.xx.126
right = 1xx.xxx.xxx.6
leftid = 1xx.xx.xx.126
ikelifetime = 28800s
lifetime = 3600s
ike = aes256-sha1-modp1024!
esp = aes256-sha1-modp1024!
leftauth = psk
rightauth = psk
rightid = 1xx.xxx.xxx.6
aggressive = no
rightsubnet = 1x.xxx.xx.7
leftsubnet = 1x.xxx.0.0/16

Any help, greatly appreciated.


Files

Actions #1

Updated by Jim Pingle over 8 years ago

  • Status changed from New to Rejected

This is not a support ticket system. Please discuss the issue on the forum. If a specific bug is identified, only then can a report be opened on this site.

Actions #2

Updated by Emmanux . over 8 years ago

Very helpful, Jim Pingle, thanks a lot.

Actions #3

Updated by Emmanux . over 8 years ago

By the way, I'm not going to post anything on the forum, I'm coming from there, other people is experiencing similar issues, no help at all.

Actions #4

Updated by Jim Pingle over 8 years ago

I'm sorry you feel that way, but that does not mean you can open a bug report for what is most likely a configuration issue, or even something that was already fixed because you're running an outdated version. This is not a valid bug report. If you need support, then the forum, mailing list, or our commercial support offerings are the places to seek help.

Actions

Also available in: Atom PDF