[strongSwan] charon dies and leaves core file
Brad Johnson
bjohnson at ecessa.com
Thu Oct 15 21:15:27 CEST 2015
After recently upgrading to strongSwan version 5.3.2 we are seeing
charon dying when trying to connect to a Cisco ASA. Here is the (IP
addresses redacted) configuration and syslog. I have a tar ball of the
core file but was unable to successfully send the email with it
attached. Please advise how I can do that and I will send it.
conn SSATM_0_0
left=x.x.x.x
right=y.y.y.y
also=SSATM_common
conn SSATM_common
auto=start
leftupdown=/bin/ipsec_updown.sh
leftsubnet=10.1.0.0/16,10.101.0.0/16,10.102.0.0/16,10.104.0.0/16,10.106.15.0/24,10.107.15.0/24
leftid=x.x.x.x
rightsubnet=192.168.3.0/24
rightid=y.y.y.y
keyingtries=%forever
leftauth=psk
rightauth=psk
ikelifetime=8h
ike=aes256-sha1-modp1024
esp=aes256-sha1
dpddelay=15
dpdtimeout=30
dpdaction=restart
The syslog messages:
Oct 14 16:40:52 WVDC00260212 charon: 07[IKE] <SSATM_0_0|13> initiating
IKE_SA SSATM_0_0[15] to y.y.y.y
Oct 14 16:40:52 WVDC00260212 ipsec_starter[11688]: charon has died --
restart scheduled (5sec)
Oct 14 16:40:57 WVDC00260212 ipsec_starter[11688]: charon (4513) started
after 60 ms
Regards,
Brad Johnson
More information about the Users
mailing list