i have a problem with one of my site 2 site vpns.
If the vpn is down becaus of an internet outage, it only comes up partiaölly on it's own, i.e. only 3 of 6 SAs comeup again.
I have to diosable the vpn and enable it to come up again.
In the logs i see stuff like that
2015:08:05-14:40:15 fwmuc pluto[7126]: | route owner of "S_REF_IpsSitMucffm_2"[14] 79.255.56.46:4500 unrouted: "S_REF_IpsSitMucffm_2"[1] 79.255.13.156:4500 erouted HOLD; eroute owner: "S_REF_IpsSitMucffm_2"[1] 79.255.13.156:4500 erouted HOLD
2015:08:05-14:40:15 fwmuc pluto[7126]: "S_REF_IpsSitMucffm_2"[14] 79.255.56.46:4500: deleting connection "S_REF_IpsSitMucffm_2"[14] instance with peer 79.255.56.46 {isakmp=#0/ipsec=#0}
2015:08:05-14:40:15 fwmuc pluto[7126]: | next event EVENT_RETRANSMIT in 0 seconds for #2758
2015:08:05-14:40:15 fwmuc pluto[7126]: |
2015:08:05-14:40:15 fwmuc pluto[7126]: | *time to handle event
2015:08:05-14:40:15 fwmuc pluto[7126]: | event after this is EVENT_RETRANSMIT in 0 seconds
2015:08:05-14:40:15 fwmuc pluto[7126]: | handling event EVENT_RETRANSMIT for 79.255.56.46 "S_REF_IpsSitMucffm_0" #2758
2015:08:05-14:40:15 fwmuc pluto[7126]: "S_REF_IpsSitMucffm_0"[14] 79.255.56.46:4500 #2758: max number of retransmissions (2) reached STATE_QUICK_R1
2015:08:05-14:40:15 fwmuc pluto[7126]: | **emit ISAKMP Message:
2015:08:05-14:40:15 fwmuc pluto[7126]: | initiator cookie:
2015:08:05-14:40:15 fwmuc pluto[7126]: | 53 d2 aa 3e d9 c6 a2 55
2015:08:05-14:40:15 fwmuc pluto[7126]: | responder cookie:
2015:08:05-14:40:15 fwmuc pluto[7126]: | 49 40 53 c0 c0 c2 13 97
2015:08:05-14:40:15 fwmuc pluto[7126]: | next payload type: ISAKMP_NEXT_HASH
2015:08:05-14:40:15 fwmuc pluto[7126]: | ISAKMP version: ISAKMP Version 1.0
2015:08:05-14:40:15 fwmuc pluto[7126]: | exchange type: ISAKMP_XCHG_INFO
2015:08:05-14:40:15 fwmuc pluto[7126]: | flags: ISAKMP_FLAG_ENCRYPTION
2015:08:05-14:40:15 fwmuc pluto[7126]: | message ID: 45 30 3e 8a
2015:08:05-14:40:15 fwmuc pluto[7126]: | ***emit ISAKMP Hash Payload:
2015:08:05-14:40:15 fwmuc pluto[7126]: | next payload type: ISAKMP_NEXT_D
2015:08:05-14:40:15 fwmuc pluto[7126]: | emitting 16 zero bytes of HASH(1) into ISAKMP Hash Payload
2015:08:05-14:40:15 fwmuc pluto[7126]: | emitting length of ISAKMP Hash Payload: 20
2015:08:05-14:40:15 fwmuc pluto[7126]: | ***emit ISAKMP Delete Payload:
2015:08:05-14:40:15 fwmuc pluto[7126]: | next payload type: ISAKMP_NEXT_NONE
2015:08:05-14:40:15 fwmuc pluto[7126]: | DOI: ISAKMP_DOI_IPSEC
2015:08:05-14:40:15 fwmuc pluto[7126]: | protocol ID: 3
2015:08:05-14:40:15 fwmuc pluto[7126]: | SPI size: 4
2015:08:05-14:40:15 fwmuc pluto[7126]: | number of SPIs: 1
2015:08:05-14:40:15 fwmuc pluto[7126]: | emitting 4 raw bytes of delete payload into ISAKMP Delete Payload
2015:08:05-14:40:15 fwmuc pluto[7126]: | delete payload 39 7a 77 19
2015:08:05-14:40:15 fwmuc pluto[7126]: | emitting length of ISAKMP Delete Payload: 16
2015:08:05-14:40:15 fwmuc pluto[7126]: | HASH(1) computed:
2015:08:05-14:40:15 fwmuc pluto[7126]: | 68 00 9e 76 6f a2 d4 60 e0 39 1d ca 2f 83 4e 71
2015:08:05-14:40:15 fwmuc pluto[7126]: | last Phase 1 IV: fd 56 64 6f db 2b 40 61
2015:08:05-14:40:15 fwmuc pluto[7126]: | computed Phase 2 IV:
2015:08:05-14:40:15 fwmuc pluto[7126]: | b9 ed fd e1 b4 4f 3f 93 4e 37 d8 a8 0d 67 2e b2
2015:08:05-14:40:15 fwmuc pluto[7126]: | encrypting:
2015:08:05-14:40:15 fwmuc pluto[7126]: | 0c 00 00 14 68 00 9e 76 6f a2 d4 60 e0 39 1d ca
2015:08:05-14:40:15 fwmuc pluto[7126]: | 2f 83 4e 71 00 00 00 10 00 00 00 01 03 04 00 01
2015:08:05-14:40:15 fwmuc pluto[7126]: | 39 7a 77 19
2015:08:05-14:40:15 fwmuc pluto[7126]: | emitting 4 zero bytes of encryption padding into ISAKMP Message
2015:08:05-14:40:15 fwmuc pluto[7126]: | encrypting using 3DES_CBC
2015:08:05-14:40:15 fwmuc pluto[7126]: | next IV: 63 1a 15 5f 31 f5 94 69
2015:08:05-14:40:15 fwmuc pluto[7126]: | emitting length of ISAKMP Message: 68
2015:08:05-14:40:15 fwmuc pluto[7126]: | sending 68 bytes for delete notify through eth2 to 79.255.56.46:4500:
2015:08:05-14:40:15 fwmuc pluto[7126]: | 53 d2 aa 3e d9 c6 a2 55 49 40 53 c0 c0 c2 13 97
2015:08:05-14:40:15 fwmuc pluto[7126]: | 08 10 05 01 45 30 3e 8a 00 00 00 44 37 9a 97 d4
2015:08:05-14:40:15 fwmuc pluto[7126]: | 12 c3 f9 64 4b 70 5f 29 2b d3 6d 85 f5 e3 5c f5
2015:08:05-14:40:15 fwmuc pluto[7126]: | 83 63 0a ab 48 d7 1d 56 dc b7 93 b6 63 1a 15 5f
2015:08:05-14:40:15 fwmuc pluto[7126]: | 31 f5 94 69
2015:08:05-14:40:15 fwmuc pluto[7126]: | ICOOKIE: 53 d2 aa 3e d9 c6 a2 55
2015:08:05-14:40:15 fwmuc pluto[7126]: | RCOOKIE: 49 40 53 c0 c0 c2 13 97
2015:08:05-14:40:15 fwmuc pluto[7126]: | peer: 4f ff 38 2e
2015:08:05-14:40:15 fwmuc pluto[7126]: | state hash entry 5
2015:08:05-14:40:15 fwmuc pluto[7126]: | route owner of "S_REF_IpsSitMucffm_0"[14] 79.255.56.46:4500 unrouted: "S_REF_IpsSitMucffm_0"[1] 79.255.13.156:4500 erouted; eroute owner: "S_REF_IpsSitMucffm_0"[1] 79.255.13.156:4500 erouted
2015:08:05-14:40:15 fwmuc pluto[7126]: "S_REF_IpsSitMucffm_0"[14] 79.255.56.46:4500: deleting connection "S_REF_IpsSitMucffm_0"[14] instance with peer 79.255.56.46 {isakmp=#0/ipsec=#0}
2015:08:05-14:40:15 fwmuc pluto[7126]: | next event EVENT_RETRANSMIT in 0 seconds for #2757
2015:08:05-14:40:15 fwmuc pluto[7126]: |
2015:08:05-14:40:15 fwmuc pluto[7126]: | *time to handle event
2015:08:05-14:40:15 fwmuc pluto[7126]: | event after this is EVENT_RETRANSMIT in 0 seconds
2015:08:05-14:40:15 fwmuc pluto[7126]: | handling event EVENT_RETRANSMIT for 79.255.56.46 "S_REF_IpsSitMucffm_4" #2757
2015:08:05-14:40:15 fwmuc pluto[7126]: "S_REF_IpsSitMucffm_4"[14] 79.255.56.46:4500 #2757: max number of retransmissions (2) reached STATE_QUICK_R1
2015:08:05-14:40:15 fwmuc pluto[7126]: | **emit ISAKMP Message:
2015:08:05-14:40:15 fwmuc pluto[7126]: | initiator cookie:
2015:08:05-14:40:15 fwmuc pluto[7126]: | 53 d2 aa 3e d9 c6 a2 55
2015:08:05-14:40:15 fwmuc pluto[7126]: | responder cookie:
2015:08:05-14:40:15 fwmuc pluto[7126]: | 49 40 53 c0 c0 c2 13 97
2015:08:05-14:40:15 fwmuc pluto[7126]: | next payload type: ISAKMP_NEXT_HASH
2015:08:05-14:40:15 fwmuc pluto[7126]: | ISAKMP version: ISAKMP Version 1.0
2015:08:05-14:40:15 fwmuc pluto[7126]: | exchange type: ISAKMP_XCHG_INFO
2015:08:05-14:40:15 fwmuc pluto[7126]: | flags: ISAKMP_FLAG_ENCRYPTION
2015:08:05-14:40:15 fwmuc pluto[7126]: | message ID: a3 5e ca 35
2015:08:05-14:40:15 fwmuc pluto[7126]: | ***emit ISAKMP Hash Payload:
2015:08:05-14:40:15 fwmuc pluto[7126]: | next payload type: ISAKMP_NEXT_D
2015:08:05-14:40:15 fwmuc pluto[7126]: | emitting 16 zero bytes of HASH(1) into ISAKMP Hash Payload
2015:08:05-14:40:15 fwmuc pluto[7126]: | emitting length of ISAKMP Hash Payload: 20
2015:08:05-14:40:15 fwmuc pluto[7126]: | ***emit ISAKMP Delete Payload:
2015:08:05-14:40:15 fwmuc pluto[7126]: | next payload type: ISAKMP_NEXT_NONE
2015:08:05-14:40:15 fwmuc pluto[7126]: | DOI: ISAKMP_DOI_IPSEC
2015:08:05-14:40:15 fwmuc pluto[7126]: | protocol ID: 3
2015:08:05-14:40:15 fwmuc pluto[7126]: | SPI size: 4
2015:08:05-14:40:15 fwmuc pluto[7126]: | number of SPIs: 1
2015:08:05-14:40:15 fwmuc pluto[7126]: | emitting 4 raw bytes of delete payload into ISAKMP Delete Payload
2015:08:05-14:40:15 fwmuc pluto[7126]: | delete payload 88 b7 16 33
2015:08:05-14:40:15 fwmuc pluto[7126]: | emitting length of ISAKMP Delete Payload: 16
2015:08:05-14:40:15 fwmuc pluto[7126]: | HASH(1) computed:
2015:08:05-14:40:15 fwmuc pluto[7126]: | a5 86 57 73 11 d4 98 53 67 c6 c3 f9 43 dc 3d 92
2015:08:05-14:40:15 fwmuc pluto[7126]: | last Phase 1 IV: fd 56 64 6f db 2b 40 61
2015:08:05-14:40:15 fwmuc pluto[7126]: | computed Phase 2 IV:
2015:08:05-14:40:15 fwmuc pluto[7126]: | 39 9e 8a f6 86 51 4c 9f 94 9d 65 46 d2 a8 98 63
2015:08:05-14:40:15 fwmuc pluto[7126]: | encrypting:
2015:08:05-14:40:15 fwmuc pluto[7126]: | 0c 00 00 14 a5 86 57 73 11 d4 98 53 67 c6 c3 f9
2015:08:05-14:40:15 fwmuc pluto[7126]: | 43 dc 3d 92 00 00 00 10 00 00 00 01 03 04 00 01
2015:08:05-14:40:15 fwmuc pluto[7126]: | 88 b7 16 33
2015:08:05-14:40:15 fwmuc pluto[7126]: | emitting 4 zero bytes of encryption padding into ISAKMP Message
2015:08:05-14:40:15 fwmuc pluto[7126]: | encrypting using 3DES_CBC
2015:08:05-14:40:15 fwmuc pluto[7126]: | next IV: 6d c1 c4 ad 16 77 99 02
2015:08:05-14:40:15 fwmuc pluto[7126]: | emitting length of ISAKMP Message: 68
2015:08:05-14:40:15 fwmuc pluto[7126]: | sending 68 bytes for delete notify through eth2 to 79.255.56.46:4500:
2015:08:05-14:40:15 fwmuc pluto[7126]: | 53 d2 aa 3e d9 c6 a2 55 49 40 53 c0 c0 c2 13 97
2015:08:05-14:40:15 fwmuc pluto[7126]: | 08 10 05 01 a3 5e ca 35 00 00 00 44 04 9a 05 fb
2015:08:05-14:40:15 fwmuc pluto[7126]: | 00 13 97 e3 22 58 0d b4 ee 14 97 76 54 9c 22 4d
2015:08:05-14:40:15 fwmuc pluto[7126]: | 55 40 2b 45 03 da 17 d7 0f 67 8f 59 6d c1 c4 ad
2015:08:05-14:40:15 fwmuc pluto[7126]: | 16 77 99 02
2015:08:05-14:40:15 fwmuc pluto[7126]: | ICOOKIE: 53 d2 aa 3e d9 c6 a2 55
2015:08:05-14:40:15 fwmuc pluto[7126]: | RCOOKIE: 49 40 53 c0 c0 c2 13 97
2015:08:05-14:40:15 fwmuc pluto[7126]: | peer: 4f ff 38 2e
2015:08:05-14:40:15 fwmuc pluto[7126]: | state hash entry 5
In the forum it was mentioned to delete everything associated with the connection and redo it from scratch, which i did but it still doesn't come up on it's own if it's down.
Any ideas?
This thread was automatically locked due to age.