[strongSwan] IPv6 IKEv2 Road Warrior Part 2

Martin Willi martin at strongswan.org
Thu Oct 9 15:12:17 CEST 2014


Randy,

> 14[ENC] generating IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) N(MULT_AUTH) ]
> 14[NET] sending packet: from serveripv6v1[500] to clientipv61[500] (312 bytes)
> 15[JOB] deleting half open IKE_SA after timeout

After sending the IKE_SA_INIT response message, the gateway does not
receive the next IKE_AUTH message from the client. Most likely that
message gets lost on your path, but you may check that with a network
sniffer on the client. Possible causes for IKE_AUTH losses are either
fragmentation or firewalling issues on your path.

Regards
Martin



More information about the Users mailing list