Hi, I have some existing Site to Site VPN Tunnels on our Draytek routers which we are upgrading to Sophos XG.
I am having some issues when setting up Site to Site VPN Tunnels, even though these are setup exactly the same on the Drayteks which work without issue.
I am trying to understand the logs better to resolve these tunnels. Any help in understanding these would be much appreciated.
Tunnel 1:
2021-07-22 15:49:17 14[IKE] <Site1-1|2> giving up after 5 retransmits
2021-07-22 15:49:17 14[DMN] <Site1-1|2> [GARNER-LOGGING] (child_alert) ALERT: IKE message (68001400) retransmission to 110.141.215.236 timed out
2021-07-22 15:49:17 14[DMN] <Site1-1|2> [GARNER-LOGGING] (child_alert) ALERT: peer did not respond to initial message 2
2021-07-22 15:49:17 14[IKE] <Site1-1|2> peer not responding, trying again (4/0)
2021-07-22 15:49:17 14[IKE] <Site1-1|2> initiating Main Mode IKE_SA Site1-1[2] to 110.141.215.236
2021-07-22 15:49:17 14[ENC] <Site1-1|2> generating ID_PROT request 0 [ SA V V V V V V ]
2021-07-22 15:49:17 14[NET] <Site1-1|2> sending packet: from 61.68.29.167[500] to 110.141.215.236[500] (312 bytes)
2021-07-22 15:49:17 20[NET] <Site1-1|2> received packet: from 110.141.215.236[500] to 61.68.29.167[500] (128 bytes)
2021-07-22 15:49:17 20[ENC] <Site1-1|2> parsed ID_PROT response 0 [ SA V V ]
2021-07-22 15:49:17 20[IKE] <Site1-1|2> received DPD vendor ID
2021-07-22 15:49:17 20[IKE] <Site1-1|2> received NAT-T (RFC 3947) vendor ID
2021-07-22 15:49:17 20[ENC] <Site1-1|2> generating ID_PROT request 0 [ KE No NAT-D NAT-D ]
2021-07-22 15:49:17 20[NET] <Site1-1|2> sending packet: from 61.68.29.167[500] to 110.141.215.236[500] (364 bytes)
2021-07-22 15:49:17 21[NET] <Site1-1|2> received packet: from 110.141.215.236[500] to 61.68.29.167[500] (348 bytes)
2021-07-22 15:49:17 21[ENC] <Site1-1|2> parsed ID_PROT response 0 [ KE No NAT-D NAT-D ]
2021-07-22 15:49:17 21[ENC] <Site1-1|2> generating ID_PROT request 0 [ ID HASH ]
2021-07-22 15:49:17 21[NET] <Site1-1|2> sending packet: from 61.68.29.167[4500] to 110.141.215.236[4500] (76 bytes)
Tunnel 2:
2021-07-22 15:44:42 27[ENC] <30> generating INFORMATIONAL_V1 request 2811380931 [ HASH N(PLD_MAL) ]
2021-07-22 15:44:42 27[IKE] <30> ID_PROT request with message ID 0 processing failed
2021-07-22 15:44:42 25[JOB] <23> deleting half open IKE_SA with 203.39.128.154 after timeout
2021-07-22 15:44:42 25[DMN] <23> [GARNER-LOGGING] (child_alert) ALERT: IKE_SA timed out before it could be established
2021-07-22 15:44:44 07[NET] <31> received packet: from 203.39.128.154[500] to 203.198.128.106[500] (292 bytes)
2021-07-22 15:44:44 07[ENC] <31> parsed ID_PROT request 0 [ SA V V V V V V V V V V ]
2021-07-22 15:44:44 07[IKE] <31> received NAT-T (RFC 3947) vendor ID
2021-07-22 15:44:44 07[IKE] <31> received draft-ietf-ipsec-nat-t-ike-03 vendor ID
2021-07-22 15:44:44 07[IKE] <31> received draft-ietf-ipsec-nat-t-ike-02 vendor ID
2021-07-22 15:44:44 07[IKE] <31> received draft-ietf-ipsec-nat-t-ike-02\n vendor ID
2021-07-22 15:44:44 07[ENC] <31> received unknown vendor ID: 16:f6:ca:16:e4:a4:06:6d:83:82:1a:0f:0a:ea:a8:62
2021-07-22 15:44:44 07[IKE] <31> received draft-ietf-ipsec-nat-t-ike-00 vendor ID
2021-07-22 15:44:44 07[IKE] <31> received DPD vendor ID
2021-07-22 15:44:44 07[IKE] <31> received FRAGMENTATION vendor ID
2021-07-22 15:44:44 07[IKE] <31> received FRAGMENTATION vendor ID
2021-07-22 15:44:44 07[ENC] <31> received unknown vendor ID: 82:99:03:17:57:a3:82:c6:a6:21:de:00:00:00:00
2021-07-22 15:44:44 07[IKE] <31> 203.39.128.154 is initiating a Main Mode IKE_SA
2021-07-22 15:44:44 07[ENC] <31> generating ID_PROT response 0 [ SA V V V V V ]
2021-07-22 15:44:44 07[NET] <31> sending packet: from 203.198.128.106[500] to 203.39.128.154[500] (184 bytes)
2021-07-22 15:44:44 21[NET] <31> received packet: from 203.39.128.154[500] to 203.198.128.106[500] (292 bytes)
2021-07-22 15:44:44 21[ENC] <31> parsed ID_PROT request 0 [ KE No NAT-D NAT-D ]
2021-07-22 15:44:44 21[ENC] <31> generating ID_PROT response 0 [ KE No NAT-D NAT-D ]
2021-07-22 15:44:44 21[NET] <31> sending packet: from 203.198.128.106[500] to 203.39.128.154[500] (308 bytes)
2021-07-22 15:44:44 16[NET] <31> received packet: from 203.39.128.154[500] to 203.198.128.106[500] (108 bytes)
2021-07-22 15:44:44 16[ENC] <31> invalid ID_V1 payload length, decryption failed?
2021-07-22 15:44:44 16[ENC] <31> could not decrypt payloads
2021-07-22 15:44:44 16[IKE] <31> message parsing failed
2021-07-22 15:44:44 16[ENC] <31> generating INFORMATIONAL_V1 request 1915868167 [ HASH N(PLD_MAL) ]
2021-07-22 15:44:44 16[NET] <31> sending packet: from 203.198.128.106[500] to 203.39.128.154[500] (76 bytes)
2021-07-22 15:44:44 16[IKE] <31> ID_PROT request with message ID 0 processing failed
2021-07-22 15:44:44 16[DMN] <31> [GARNER-LOGGING] (child_alert) ALERT: parsing IKE message from 203.39.128.154[500] failed
Tunnel 3:
2021-07-22 15:46:27 10[DMN] <Site3-1|4> [GARNER-LOGGING] (child_alert) ALERT: IKE message (90000E40) retransmission to 192.140.226.189 timed out
2021-07-22 15:46:27 10[DMN] <Site3-1|4> [GARNER-LOGGING] (child_alert) ALERT: peer did not respond to initial message 1
2021-07-22 15:46:27 10[IKE] <Site3-1|4> peer not responding, trying again (3/0)
2021-07-22 15:46:27 10[IKE] <Site3-1|4> initiating IKE_SA 201.140.226.188-1[4] to 192.140.226.189
2021-07-22 15:46:27 10[ENC] <Site3-1|4> generating IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) N(HASH_ALG) N(REDIR_SUP) ]
2021-07-22 15:46:27 10[NET] <Site3-1|4> sending packet: from 201.140.226.188[500] to 192.140.226.189[500] (1046 bytes)
Tunnel 4:
2021-07-22 15:46:27 13[IKE] <Site4-1|1> giving up after 5 retransmits
2021-07-22 15:46:27 13[DMN] <Site4-1|1> [GARNER-LOGGING] (child_alert) ALERT: IKE message (70004270) retransmission to 203.39.130.222 timed out
2021-07-22 15:46:27 13[DMN] <Site4-1|1> [GARNER-LOGGING] (child_alert) ALERT: peer did not respond to initial message 1
2021-07-22 15:46:27 13[IKE] <Site4-1|1> peer not responding, trying again (3/0)
2021-07-22 15:46:27 13[IKE] <Site4-1|1> initiating Main Mode IKE_SA Site4-1[1] to 203.39.130.222
2021-07-22 15:46:27 13[ENC] <Site4-1|1> generating ID_PROT request 0 [ SA V V V V V V ]
2021-07-22 15:46:27 13[NET] <Site4-1|1> sending packet: from 61.68.10.150[500] to 203.39.130.222[500] (312 bytes)
Thank you!
Steele
This thread was automatically locked due to age.