There still seem to be some issues with strongSwan, I encountered another problem now in Phase 2, it showed as up but no side could reach each other.
But I found the issue when I looked closer at the Security Association Database (SAD), both connections had the same reqid. You can also see that the peer side was not sending any data (0 bytes).
You cannot view this attachment.
After manually changing the reqid to 100 Phase 2 works perfectly and now you also see the Ikeid.
You cannot view this attachment.
By the way is it normal that an IKEv1 connection has no Ikeid (the lower pair)?
Normally strongSwan should automatically use incrementing reqids for new connections. According to this discussion on GitHub this is possibly fixed in strongSwan 6.0, our business OPNsense (25.4.3_4) is still on version 5.9.14.
https://github.com/strongswan/strongswan/discussions/2687
But I found the issue when I looked closer at the Security Association Database (SAD), both connections had the same reqid. You can also see that the peer side was not sending any data (0 bytes).
You cannot view this attachment.
After manually changing the reqid to 100 Phase 2 works perfectly and now you also see the Ikeid.
You cannot view this attachment.
By the way is it normal that an IKEv1 connection has no Ikeid (the lower pair)?
Normally strongSwan should automatically use incrementing reqids for new connections. According to this discussion on GitHub this is possibly fixed in strongSwan 6.0, our business OPNsense (25.4.3_4) is still on version 5.9.14.
https://github.com/strongswan/strongswan/discussions/2687
"