OPNsense Forum

Archive => 20.1 Legacy Series => Topic started by: nzkiwi68 on June 12, 2020, 01:33:04 AM

Title: 20.1.7 - IPSEC tunnels some P2 lost after 1 hour at rekey
Post by: nzkiwi68 on June 12, 2020, 01:33:04 AM
I've recent converted from pfSense and am now running 20.1.7 connecting to a number of IPSEC traditional VPN tunnels.


What have a done?
* I have rebooted OPNsense
* Deleted the affected OPNsense tunnels and remade them on OPNsense again
* Minutely compared settings on OPNsense to tunnels that work and never drop and those that do (no * differences detected)

See some IPSEC log entries from OPNsense;
2020-06-11T06:55:51 charon: 14[IKE] <con4|21> failed to establish CHILD_SA, keeping IKE_SA
2020-06-11T06:55:51 charon: 14[IKE] <con4|21> received NO_PROPOSAL_CHOSEN notify, no CHILD_SA built


Have a look at this whilst in failure mode:
See the last one (con6) - no P2
(http://nop2.png)


Title: Re: 20.1.7 - IPSEC tunnels some P2 lost after 1 hour at rekey
Post by: mimugmail on June 12, 2020, 06:27:30 AM
NO PROPOSAL CHOSEN means there is a mismatch in settings, like enc alg or hash digest.
You need to compare both sides one by one.
Title: Re: 20.1.7 - IPSEC tunnels some P2 lost after 1 hour at rekey
Post by: nzkiwi68 on June 13, 2020, 11:20:21 PM
Thanks.

You are right, just some very subtle differences and that was the cause.

Problem solved.