Apr 18 14:42:17 charon: 04[CFG] rereading crls from '/usr/local/etc/ipsec.d/crls'Apr 18 14:42:17 charon: 04[CFG] rereading attribute certificates from '/usr/local/etc/ipsec.d/acerts'Apr 18 14:42:17 charon: 04[CFG] rereading ocsp signer certificates from '/usr/local/etc/ipsec.d/ocspcerts'Apr 18 14:42:17 charon: 04[CFG] rereading aa certificates from '/usr/local/etc/ipsec.d/aacerts'Apr 18 14:42:17 charon: 04[CFG] loaded ca certificate "CN=Fake LE Intermediate X1" from '/usr/local/etc/ipsec.d/cacerts/0a3654cf.0.crt'Apr 18 14:42:17 charon: 04[CFG] loaded ca certificate "C=US, O=Let's Encrypt, CN=Let's Encrypt Authority X3" from '/usr/local/etc/ipsec.d/cacerts/4f06f81d.0.crt'Apr 18 14:42:17 charon: 04[CFG] loaded ca certificate "C=DE, ST=Deutschland, L=XXXX, O=XXXXXX, E=XXXXXXXX, CN=internal-sslvpn-ca" from '/usr/local/etc/ipsec.d/cacerts/4e5ba7dc.0.crt'Apr 18 14:42:17 charon: 04[CFG] rereading ca certificates from '/usr/local/etc/ipsec.d/cacerts'Apr 18 14:42:17 charon: 04[CFG] loaded IKE secret for [REMOTE IP ADDRESS]Apr 18 14:42:17 charon: 04[CFG] loading secrets from '/usr/local/etc/ipsec.secrets'Apr 18 14:42:17 charon: 04[CFG] rereading secretsApr 18 14:42:17 charon: 00[JOB] spawning 16 worker threadsApr 18 14:42:17 charon: 00[LIB] loaded plugins: charon aes des blowfish rc2 sha2 sha1 md4 md5 random nonce x509 revocation constraints pubkey pkcs1 pkcs7 pkcs8 pkcs12 pgp dnskey sshkey pem openssl fips-prf curve25519 xcbc cmac hmac gcm attr kernel-pfkey kernel-pfroute resolve socket-default stroke vici updown eap-identity eap-md5 eap-mschapv2 eap-radius eap-tls eap-ttls eap-peap xauth-generic xauth-eap xauth-pam whitelist addrblock countersApr 18 14:42:17 charon: 00[CFG] loaded 0 RADIUS server configurationsApr 18 14:42:17 charon: 00[CFG] loaded IKE secret for [REMOTE IP ADDRESS]Apr 18 14:42:17 charon: 00[CFG] loading secrets from '/usr/local/etc/ipsec.secrets'Apr 18 14:42:17 charon: 00[CFG] loading crls from '/usr/local/etc/ipsec.d/crls'Apr 18 14:42:17 charon: 00[CFG] loading attribute certificates from '/usr/local/etc/ipsec.d/acerts'Apr 18 14:42:17 charon: 00[CFG] loading ocsp signer certificates from '/usr/local/etc/ipsec.d/ocspcerts'Apr 18 14:42:17 charon: 00[CFG] loading aa certificates from '/usr/local/etc/ipsec.d/aacerts'Apr 18 14:42:17 charon: 00[CFG] loaded ca certificate "CN=Fake LE Intermediate X1" from '/usr/local/etc/ipsec.d/cacerts/0a3654cf.0.crt'Apr 18 14:42:17 charon: 00[CFG] loaded ca certificate "C=US, O=Let's Encrypt, CN=Let's Encrypt Authority X3" from '/usr/local/etc/ipsec.d/cacerts/4f06f81d.0.crt'Apr 18 14:42:17 charon: 00[CFG] loaded ca certificate "C=DE, ST=Deutschland, L=XXXX, O=XXXXX, E=XXXXXXX, CN=internal-sslvpn-ca" from '/usr/local/etc/ipsec.d/cacerts/4e5ba7dc.0.crt'Apr 18 14:42:17 charon: 00[CFG] loading ca certificates from '/usr/local/etc/ipsec.d/cacerts'Apr 18 14:42:17 charon: 00[NET] enabling UDP decapsulation for IPv6 on port 4500 failedApr 18 14:42:17 charon: 00[KNL] unable to set UDP_ENCAP: Invalid argumentApr 18 14:42:17 charon: 00[DMN] Starting IKE charon daemon (strongSwan 5.7.2, FreeBSD 11.2-RELEASE-p9-HBSD, amd64)Apr 18 14:42:15 charon: 00[DMN] signal of type SIGINT received. Shutting downApr 18 14:42:13 charon: 05[CFG] rereading crls from '/usr/local/etc/ipsec.d/crls'Apr 18 14:42:13 charon: 05[CFG] rereading attribute certificates from '/usr/local/etc/ipsec.d/acerts'Apr 18 14:42:13 charon: 05[CFG] rereading ocsp signer certificates from '/usr/local/etc/ipsec.d/ocspcerts'Apr 18 14:42:13 charon: 05[CFG] rereading aa certificates from '/usr/local/etc/ipsec.d/aacerts'Apr 18 14:42:13 charon: 05[CFG] loaded ca certificate "CN=Fake LE Intermediate X1" from '/usr/local/etc/ipsec.d/cacerts/0a3654cf.0.crt'Apr 18 14:42:13 charon: 05[CFG] loaded ca certificate "C=US, O=Let's Encrypt, CN=Let's Encrypt Authority X3" from '/usr/local/etc/ipsec.d/cacerts/4f06f81d.0.crt'Apr 18 14:42:13 charon: 05[CFG] loaded ca certificate "C=DE, ST=Deutschland, L=XXXX, O=XXXX, E=XXXXXX, CN=internal-sslvpn-ca" from '/usr/local/etc/ipsec.d/cacerts/4e5ba7dc.0.crt'Apr 18 14:42:13 charon: 05[CFG] rereading ca certificates from '/usr/local/etc/ipsec.d/cacerts'Apr 18 14:42:13 charon: 05[CFG] loaded IKE secret for [REMOTE IP ADDRESS]Apr 18 14:42:13 charon: 05[CFG] loading secrets from '/usr/local/etc/ipsec.secrets'Apr 18 14:42:13 charon: 05[CFG] rereading secrets
ich hätte aber noch eine zweite opnsense die ich als failover mit carp laufen lassen will, und da klemmt's leider mit pppoe. Oder gibts da Lösungsanzätze