Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

payload_malformed notifications - Where comes this from ?

Good morning guys,

we have a VPN connection between an XG and a UTM. (We have access to the XG)

The VPN tunnel has been successfully established, but the log is filled with the following messages.

The PSK is the same on both sides. Does someone know where this message comes from ? And how to fix it ?


Sep 15 08:27:45 "xxxx" #17076: STATE_MAIN_R1: sent MR1, expecting MI2
Sep 15 08:27:45 "xxxx" #17066: max number of retransmissions (2) reached STATE_MAIN_R2
Sep 15 08:27:45 "xxxx" #17076: NAT-Traversal: Result using RFC 3947 (NAT-Traversal): no NAT detected
Sep 15 08:27:45 "xxxx" #17076: transition from state STATE_MAIN_R1 to state STATE_MAIN_R2
Sep 15 08:27:45 "xxxx" #17076: STATE_MAIN_R2: sent MR2, expecting MI3

Sep 15 08:27:45 "xxxx" #17076: next payload type of ISAKMP Identification Payload has an unknown value: 145
Sep 15 08:27:45 "xxxx" #17076: probable authentication failure (mismatch of preshared secrets?): malformed payload in packet
| payload malformed after IV
|   d3 be df c1  d8 73 e8 9b  11 71 8a 31  9b 8c c7 52
Sep 15 08:27:45 "xxxx" #17076: sending notification PAYLOAD_MALFORMED to x.x.x.x:500

 

Regards,

Max



This thread was automatically locked due to age.