Quantcast
Channel: MikroTik
Viewing all articles
Browse latest Browse all 23620

General • How to setup ikev2 psk on sub routeros behind NAT and main router is routeros?

$
0
0
My network like this:
Android 15 phone with ikev2 client built in(192.168.88.10) ----> routeros (192.168.88.1, 192.168.2.3) ----->Routing----->main routeros (192.168.4.4, 192.168.5.1) ----->sub routeros (192.168.5.4).
the main and sub routeros has no any firewall rules
the main routeros was set dnat all to 192.168.5.4,and masquerade src address 192.168.5.4.
the sub routeros was set ikev2 success.
android phone dial iken2psk to 192.168.4.4.
If the network like before,the ikev2 dial was fail.

if change the sub routeros IP 192.168.5.4 to 192.168.4.4 and remove main routeros,the ikev2 dial was ok,the network like below:
Android 15 phone with ikev2 client built in(192.168.88.10) ----> routeros (192.168.88.1, 192.168.2.3) ----->Routing----->sub routeros (192.168.4.4)。
how can i fix the problem?thanks!

the dial fail log:
Mar/16/2025 21:31:37 ipsec,debug ===== received 1072 bytes from 192.168.2.3[44422] to 192.168.5.4[500]
Mar/16/2025 21:31:37 ipsec -> ike2 request, exchange: SA_INIT:0 192.168.2.3[44422] 6395763e3678ad58:0000000000000000
Mar/16/2025 21:31:37 ipsec ike2 respond
Mar/16/2025 21:31:37 ipsec payload seen: SA (408 bytes)
Mar/16/2025 21:31:37 ipsec payload seen: KE (520 bytes)
Mar/16/2025 21:31:37 ipsec payload seen: NONCE (36 bytes)
Mar/16/2025 21:31:37 ipsec payload seen: NOTIFY (28 bytes)
Mar/16/2025 21:31:37 ipsec payload seen: NOTIFY (28 bytes)
Mar/16/2025 21:31:37 ipsec payload seen: NOTIFY (8 bytes)
Mar/16/2025 21:31:37 ipsec payload seen: NOTIFY (16 bytes)
Mar/16/2025 21:31:37 ipsec processing payload: SA
Mar/16/2025 21:31:37 ipsec,debug unknown auth: #5
Mar/16/2025 21:31:37 ipsec,debug unknown auth: #8
Mar/16/2025 21:31:37 ipsec,debug unknown PRF: #4
Mar/16/2025 21:31:37 ipsec,debug unknown PRF: #8
Mar/16/2025 21:31:37 ipsec,debug unknown enc: #19
Mar/16/2025 21:31:37 ipsec,debug unknown enc: #18
Mar/16/2025 21:31:37 ipsec,debug unknown enc: #19
Mar/16/2025 21:31:37 ipsec,debug unknown enc: #18
Mar/16/2025 21:31:37 ipsec,debug unknown enc: #19
Mar/16/2025 21:31:37 ipsec,debug unknown enc: #18
Mar/16/2025 21:31:37 ipsec,debug unknown PRF: #4
Mar/16/2025 21:31:37 ipsec,debug unknown PRF: #8
Mar/16/2025 21:31:37 ipsec IKE Protocol: IKE
Mar/16/2025 21:31:37 ipsec proposal #1
Mar/16/2025 21:31:37 ipsec enc: aes256-ctr
Mar/16/2025 21:31:37 ipsec enc: aes256-cbc
Mar/16/2025 21:31:37 ipsec enc: aes192-ctr
Mar/16/2025 21:31:37 ipsec enc: aes192-cbc
Mar/16/2025 21:31:37 ipsec enc: aes128-ctr
Mar/16/2025 21:31:37 ipsec enc: aes128-cbc
Mar/16/2025 21:31:37 ipsec prf: hmac-sha1
Mar/16/2025 21:31:37 ipsec prf: unknown
Mar/16/2025 21:31:37 ipsec prf: hmac-sha256
Mar/16/2025 21:31:37 ipsec prf: hmac-sha384
Mar/16/2025 21:31:37 ipsec prf: hmac-sha512
Mar/16/2025 21:31:37 ipsec prf: unknown
Mar/16/2025 21:31:37 ipsec auth: sha512
Mar/16/2025 21:31:37 ipsec auth: sha384
Mar/16/2025 21:31:37 ipsec auth: sha256
Mar/16/2025 21:31:37 ipsec auth: unknown
Mar/16/2025 21:31:37 ipsec auth: unknown
Mar/16/2025 21:31:37 ipsec dh: modp4096
Mar/16/2025 21:31:37 ipsec dh: x25519
Mar/16/2025 21:31:37 ipsec dh: modp3072
Mar/16/2025 21:31:37 ipsec dh: modp2048
Mar/16/2025 21:31:37 ipsec proposal #2
Mar/16/2025 21:31:37 ipsec enc: chcha20poly1305
Mar/16/2025 21:31:37 ipsec enc: aes256-gcm
Mar/16/2025 21:31:37 ipsec enc: unknown
Mar/16/2025 21:31:37 ipsec enc: unknown
Mar/16/2025 21:31:37 ipsec enc: aes192-gcm
Mar/16/2025 21:31:37 ipsec enc: unknown
Mar/16/2025 21:31:37 ipsec enc: unknown
Mar/16/2025 21:31:37 ipsec enc: aes128-gcm
Mar/16/2025 21:31:37 ipsec enc: unknown
Mar/16/2025 21:31:37 ipsec enc: unknown
Mar/16/2025 21:31:37 ipsec prf: hmac-sha1
Mar/16/2025 21:31:37 ipsec prf: unknown
Mar/16/2025 21:31:37 ipsec prf: hmac-sha256
Mar/16/2025 21:31:37 ipsec prf: hmac-sha384
Mar/16/2025 21:31:37 ipsec prf: hmac-sha512
Mar/16/2025 21:31:37 ipsec prf: unknown
Mar/16/2025 21:31:37 ipsec dh: modp4096
Mar/16/2025 21:31:37 ipsec dh: x25519
Mar/16/2025 21:31:37 ipsec dh: modp3072
Mar/16/2025 21:31:37 ipsec dh: modp2048
Mar/16/2025 21:31:37 ipsec matched proposal:
Mar/16/2025 21:31:37 ipsec proposal #1
Mar/16/2025 21:31:37 ipsec enc: aes256-cbc
Mar/16/2025 21:31:37 ipsec prf: hmac-sha512
Mar/16/2025 21:31:37 ipsec auth: sha512
Mar/16/2025 21:31:37 ipsec dh: modp4096
Mar/16/2025 21:31:37 ipsec processing payload: KE
Mar/16/2025 21:31:38 ipsec,debug ===== received 1072 bytes from 192.168.2.3[44422] to 192.168.5.4[500]
Mar/16/2025 21:31:38 ipsec -> ike2 request, exchange: SA_INIT:0 192.168.2.3[44422] 6395763e3678ad58:0000000000000000
Mar/16/2025 21:31:38 ipsec ike2 respond
Mar/16/2025 21:31:38 ipsec payload seen: SA (408 bytes)
Mar/16/2025 21:31:38 ipsec payload seen: KE (520 bytes)
Mar/16/2025 21:31:38 ipsec payload seen: NONCE (36 bytes)
Mar/16/2025 21:31:38 ipsec payload seen: NOTIFY (28 bytes)
Mar/16/2025 21:31:38 ipsec payload seen: NOTIFY (28 bytes)
Mar/16/2025 21:31:38 ipsec payload seen: NOTIFY (8 bytes)
Mar/16/2025 21:31:38 ipsec payload seen: NOTIFY (16 bytes)
Mar/16/2025 21:31:38 ipsec processing payload: SA
Mar/16/2025 21:31:38 ipsec,debug unknown auth: #5
Mar/16/2025 21:31:38 ipsec,debug unknown auth: #8
Mar/16/2025 21:31:38 ipsec,debug unknown PRF: #4
Mar/16/2025 21:31:38 ipsec,debug unknown PRF: #8
Mar/16/2025 21:31:38 ipsec,debug unknown enc: #19
Mar/16/2025 21:31:38 ipsec,debug unknown enc: #18
Mar/16/2025 21:31:38 ipsec,debug unknown enc: #19
Mar/16/2025 21:31:38 ipsec,debug unknown enc: #18
Mar/16/2025 21:31:38 ipsec,debug unknown enc: #19
Mar/16/2025 21:31:38 ipsec,debug unknown enc: #18
Mar/16/2025 21:31:38 ipsec,debug unknown PRF: #4
Mar/16/2025 21:31:38 ipsec,debug unknown PRF: #8
Mar/16/2025 21:31:38 ipsec IKE Protocol: IKE
Mar/16/2025 21:31:38 ipsec proposal #1
Mar/16/2025 21:31:38 ipsec enc: aes256-ctr
Mar/16/2025 21:31:38 ipsec enc: aes256-cbc
Mar/16/2025 21:31:38 ipsec enc: aes192-ctr
Mar/16/2025 21:31:38 ipsec enc: aes192-cbc
Mar/16/2025 21:31:38 ipsec enc: aes128-ctr
Mar/16/2025 21:31:38 ipsec enc: aes128-cbc
Mar/16/2025 21:31:38 ipsec prf: hmac-sha1
Mar/16/2025 21:31:38 ipsec prf: unknown
Mar/16/2025 21:31:38 ipsec prf: hmac-sha256
Mar/16/2025 21:31:38 ipsec prf: hmac-sha384
Mar/16/2025 21:31:38 ipsec prf: hmac-sha512
Mar/16/2025 21:31:38 ipsec prf: unknown
Mar/16/2025 21:31:38 ipsec auth: sha512
Mar/16/2025 21:31:38 ipsec auth: sha384
Mar/16/2025 21:31:38 ipsec auth: sha256
Mar/16/2025 21:31:38 ipsec auth: unknown
Mar/16/2025 21:31:38 ipsec auth: unknown
Mar/16/2025 21:31:38 ipsec dh: modp4096
Mar/16/2025 21:31:38 ipsec dh: x25519
Mar/16/2025 21:31:38 ipsec dh: modp3072
Mar/16/2025 21:31:38 ipsec dh: modp2048
Mar/16/2025 21:31:38 ipsec proposal #2
Mar/16/2025 21:31:38 ipsec enc: chcha20poly1305
Mar/16/2025 21:31:38 ipsec enc: aes256-gcm
Mar/16/2025 21:31:38 ipsec enc: unknown
Mar/16/2025 21:31:38 ipsec enc: unknown
Mar/16/2025 21:31:38 ipsec enc: aes192-gcm
Mar/16/2025 21:31:38 ipsec enc: unknown
Mar/16/2025 21:31:38 ipsec enc: unknown
Mar/16/2025 21:31:38 ipsec enc: aes128-gcm
Mar/16/2025 21:31:38 ipsec enc: unknown
Mar/16/2025 21:31:38 ipsec enc: unknown
Mar/16/2025 21:31:38 ipsec prf: hmac-sha1
Mar/16/2025 21:31:38 ipsec prf: unknown
Mar/16/2025 21:31:38 ipsec prf: hmac-sha256
Mar/16/2025 21:31:38 ipsec prf: hmac-sha384
Mar/16/2025 21:31:38 ipsec prf: hmac-sha512
Mar/16/2025 21:31:38 ipsec prf: unknown
Mar/16/2025 21:31:38 ipsec dh: modp4096
Mar/16/2025 21:31:38 ipsec dh: x25519
Mar/16/2025 21:31:38 ipsec dh: modp3072
Mar/16/2025 21:31:38 ipsec dh: modp2048
Mar/16/2025 21:31:38 ipsec matched proposal:
Mar/16/2025 21:31:38 ipsec proposal #1
Mar/16/2025 21:31:38 ipsec enc: aes256-cbc
Mar/16/2025 21:31:38 ipsec prf: hmac-sha512
Mar/16/2025 21:31:38 ipsec auth: sha512
Mar/16/2025 21:31:38 ipsec dh: modp4096
Mar/16/2025 21:31:38 ipsec processing payload: KE
Mar/16/2025 21:31:39 ipsec,debug ===== received 1072 bytes from 192.168.2.3[44422] to 192.168.5.4[500]
Mar/16/2025 21:31:39 ipsec -> ike2 request, exchange: SA_INIT:0 192.168.2.3[44422] 6395763e3678ad58:0000000000000000
Mar/16/2025 21:31:39 ipsec ike2 respond
Mar/16/2025 21:31:39 ipsec payload seen: SA (408 bytes)
Mar/16/2025 21:31:39 ipsec payload seen: KE (520 bytes)
Mar/16/2025 21:31:39 ipsec payload seen: NONCE (36 bytes)
Mar/16/2025 21:31:39 ipsec payload seen: NOTIFY (28 bytes)
Mar/16/2025 21:31:39 ipsec payload seen: NOTIFY (28 bytes)
Mar/16/2025 21:31:39 ipsec payload seen: NOTIFY (8 bytes)
Mar/16/2025 21:31:39 ipsec payload seen: NOTIFY (16 bytes)
Mar/16/2025 21:31:39 ipsec processing payload: SA
Mar/16/2025 21:31:39 ipsec,debug unknown auth: #5
Mar/16/2025 21:31:39 ipsec,debug unknown auth: #8
Mar/16/2025 21:31:39 ipsec,debug unknown PRF: #4
Mar/16/2025 21:31:39 ipsec,debug unknown PRF: #8
Mar/16/2025 21:31:39 ipsec,debug unknown enc: #19
Mar/16/2025 21:31:39 ipsec,debug unknown enc: #18
Mar/16/2025 21:31:39 ipsec,debug unknown enc: #19
Mar/16/2025 21:31:39 ipsec,debug unknown enc: #18
Mar/16/2025 21:31:39 ipsec,debug unknown enc: #19
Mar/16/2025 21:31:39 ipsec,debug unknown enc: #18
Mar/16/2025 21:31:39 ipsec,debug unknown PRF: #4
Mar/16/2025 21:31:39 ipsec,debug unknown PRF: #8
Mar/16/2025 21:31:39 ipsec IKE Protocol: IKE
Mar/16/2025 21:31:39 ipsec proposal #1
Mar/16/2025 21:31:39 ipsec enc: aes256-ctr
Mar/16/2025 21:31:39 ipsec enc: aes256-cbc
Mar/16/2025 21:31:39 ipsec enc: aes192-ctr
Mar/16/2025 21:31:39 ipsec enc: aes192-cbc
Mar/16/2025 21:31:39 ipsec enc: aes128-ctr
Mar/16/2025 21:31:39 ipsec enc: aes128-cbc
Mar/16/2025 21:31:39 ipsec prf: hmac-sha1
Mar/16/2025 21:31:39 ipsec prf: unknown
Mar/16/2025 21:31:39 ipsec prf: hmac-sha256
Mar/16/2025 21:31:39 ipsec prf: hmac-sha384
Mar/16/2025 21:31:39 ipsec prf: hmac-sha512
Mar/16/2025 21:31:39 ipsec prf: unknown
Mar/16/2025 21:31:39 ipsec auth: sha512
Mar/16/2025 21:31:39 ipsec auth: sha384
Mar/16/2025 21:31:39 ipsec auth: sha256
Mar/16/2025 21:31:39 ipsec auth: unknown
Mar/16/2025 21:31:39 ipsec auth: unknown
Mar/16/2025 21:31:39 ipsec dh: modp4096
Mar/16/2025 21:31:39 ipsec dh: x25519
Mar/16/2025 21:31:39 ipsec dh: modp3072
Mar/16/2025 21:31:39 ipsec dh: modp2048
Mar/16/2025 21:31:39 ipsec proposal #2
Mar/16/2025 21:31:39 ipsec enc: chcha20poly1305
Mar/16/2025 21:31:39 ipsec enc: aes256-gcm
Mar/16/2025 21:31:39 ipsec enc: unknown
Mar/16/2025 21:31:39 ipsec enc: unknown
Mar/16/2025 21:31:39 ipsec enc: aes192-gcm
Mar/16/2025 21:31:39 ipsec enc: unknown
Mar/16/2025 21:31:39 ipsec enc: unknown
Mar/16/2025 21:31:39 ipsec enc: aes128-gcm
Mar/16/2025 21:31:39 ipsec enc: unknown
Mar/16/2025 21:31:39 ipsec enc: unknown
Mar/16/2025 21:31:39 ipsec prf: hmac-sha1
Mar/16/2025 21:31:39 ipsec prf: unknown
Mar/16/2025 21:31:39 ipsec prf: hmac-sha256
Mar/16/2025 21:31:39 ipsec prf: hmac-sha384
Mar/16/2025 21:31:39 ipsec prf: hmac-sha512
Mar/16/2025 21:31:39 ipsec prf: unknown
Mar/16/2025 21:31:39 ipsec dh: modp4096
Mar/16/2025 21:31:39 ipsec dh: x25519
Mar/16/2025 21:31:39 ipsec dh: modp3072
Mar/16/2025 21:31:39 ipsec dh: modp2048
Mar/16/2025 21:31:39 ipsec matched proposal:
Mar/16/2025 21:31:39 ipsec proposal #1
Mar/16/2025 21:31:39 ipsec enc: aes256-cbc
Mar/16/2025 21:31:39 ipsec prf: hmac-sha512
Mar/16/2025 21:31:39 ipsec auth: sha512
Mar/16/2025 21:31:39 ipsec dh: modp4096
Mar/16/2025 21:31:39 ipsec processing payload: KE
Mar/16/2025 21:31:39 ipsec,debug => shared secret (first 0x100 of 0x200)
Mar/16/2025 21:31:39 ipsec,debug d87b765d 0f14a2c1 cf2aa9f3 42f9a6d8 013fc586 d786ee5d ac95a775 7f7233e3
Mar/16/2025 21:31:39 ipsec,debug ef94f605 f3366ae3 bbf39f85 1bd93166 a017b577 ff717da4 3be0b04e c8c709eb
Mar/16/2025 21:31:39 ipsec,debug 4b248537 a859c11a a33a7c20 852b08f3 981a711d f6c65847 7badf94e 12eddce8
Mar/16/2025 21:31:39 ipsec,debug 2726bc0d aab72165 e2113bb0 01c35401 23f423d7 b04e8559 ab748bc2 7aeb6fe8
Mar/16/2025 21:31:39 ipsec,debug 2e4f2ff8 ba9b5940 89823532 0727a113 4305f65f 652c0577 80ed6094 7e452097
Mar/16/2025 21:31:39 ipsec,debug 13ede756 2029233c 804454e0 f8cbaec6 52519299 2cbf32c7 2c95680f 25aa1824
Mar/16/2025 21:31:39 ipsec,debug 5998ad7a 8e736367 72daa24f d5616e68 da358ac5 c1cff5a3 e744f31b 81ad3e3c
Mar/16/2025 21:31:39 ipsec,debug 7e351ca6 cea59065 5405456f eb8b49a2 368fa453 559c0a35 8a06f437 2df15a61
Mar/16/2025 21:31:39 ipsec ike2 respond finish: request, exchange: SA_INIT:0 192.168.2.3[44422] 6395763e3678ad58:0000000000000000
Mar/16/2025 21:31:39 ipsec processing payload: NONCE
Mar/16/2025 21:31:39 ipsec adding payload: SA
Mar/16/2025 21:31:39 ipsec,debug => (size 0x30)
Mar/16/2025 21:31:39 ipsec,debug 00000030 0000002c 01010004 0300000c 0100000c 800e0100 03000008 02000007
Mar/16/2025 21:31:39 ipsec,debug 03000008 0300000e 00000008 04000010
Mar/16/2025 21:31:39 ipsec adding payload: KE
Mar/16/2025 21:31:39 ipsec,debug => (first 0x100 of 0x208)
Mar/16/2025 21:31:39 ipsec,debug 00000208 00100000 253a29bd 01f553c2 6c91c2aa 8a2e79c4 768ed5c6 1957e5ab
Mar/16/2025 21:31:39 ipsec,debug 3dc03e88 36655ec3 ba31c3fe 9f0223b4 43ff38bc 23acb1e8 62223c51 084c098d
Mar/16/2025 21:31:39 ipsec,debug 82ed24e8 4e501d9e bb0889a6 68d694e0 828a12ec 8c2133d5 213daf89 d83c9edf
Mar/16/2025 21:31:39 ipsec,debug c5cd2ed5 7fbdb0cd c41a63a1 320f0c09 0f35d8c1 a73cdc5e b755e985 cd30549d
Mar/16/2025 21:31:39 ipsec,debug 2e9310f9 aaeb78d7 ee25af3a 314ed8dd 7c33d5b4 5eb13db2 cfe8b6cb 4d36738e
Mar/16/2025 21:31:39 ipsec,debug dc32092d 4ed1d963 727895e3 17f9f36a 4783c0d9 b82cf98f 72d4851e e877e0ec
Mar/16/2025 21:31:39 ipsec,debug 7f851c5e 18bcab12 c9b71d41 92fba37e c9e51196 3660ba0c e56e0ec3 4bd0e6b3
Mar/16/2025 21:31:39 ipsec,debug aadf4c52 984e10ec d02c7ffa 88ba8eeb ee8318ba 3fa1fefd dbd22585 0bb2924f
Mar/16/2025 21:31:39 ipsec adding payload: NONCE
Mar/16/2025 21:31:39 ipsec,debug => (size 0x1c)
Mar/16/2025 21:31:39 ipsec,debug 0000001c ae4d3496 5497bc78 54dcfbdc 923508e1 4472ef66 3fda629f
Mar/16/2025 21:31:39 ipsec adding notify: NAT_DETECTION_SOURCE_IP
Mar/16/2025 21:31:39 ipsec,debug => (size 0x1c)
Mar/16/2025 21:31:39 ipsec,debug 0000001c 00004004 c087096e bc9f9f9b 1b80124c eaebd3fd b4722b0e
Mar/16/2025 21:31:39 ipsec adding notify: NAT_DETECTION_DESTINATION_IP
Mar/16/2025 21:31:39 ipsec,debug => (size 0x1c)
Mar/16/2025 21:31:39 ipsec,debug 0000001c 00004005 2c0e6d30 f4075107 883f0d75 fa378cc3 4d9bfe9f
Mar/16/2025 21:31:39 ipsec adding notify: IKEV2_FRAGMENTATION_SUPPORTED
Mar/16/2025 21:31:39 ipsec,debug => (size 0x8)
Mar/16/2025 21:31:39 ipsec,debug 00000008 0000402e
Mar/16/2025 21:31:39 ipsec adding payload: CERTREQ
Mar/16/2025 21:31:39 ipsec,debug => (size 0x5)
Mar/16/2025 21:31:39 ipsec,debug 00000005 04
Mar/16/2025 21:31:39 ipsec <- ike2 reply, exchange: SA_INIT:0 192.168.2.3[44422] 6395763e3678ad58:a1aa5430fd51375f
Mar/16/2025 21:31:39 ipsec,debug ===== sending 693 bytes from 192.168.5.4[500] to 192.168.2.3[44422]
Mar/16/2025 21:31:39 ipsec,debug 1 times of 693 bytes message will be sent to 192.168.2.3[44422]
Mar/16/2025 21:31:39 ipsec,debug => skeyseed (size 0x40)
Mar/16/2025 21:31:39 ipsec,debug 2f7be50f c5ea1bb6 ec4beb5e 37ec7ddb 6789c54d 9f360ead dc24300e b06f2981
Mar/16/2025 21:31:39 ipsec,debug 5b5b3087 c900c605 b18977f1 169a7b22 e21f94a5 779d4fae 7a05c1f1 695c0af0
Mar/16/2025 21:31:39 ipsec,debug => keymat (size 0x40)
Mar/16/2025 21:31:39 ipsec,debug e4a62df5 852f3c1f 38ae61a2 7a180786 444f7c8c 01b4789f 7f1b76b0 162ca43c
Mar/16/2025 21:31:39 ipsec,debug 9063b5de 5d3e691e b58f74db 67cd8042 97012309 d713b2f9 cec6e9f7 837c6a9b
Mar/16/2025 21:31:39 ipsec,debug => SK_ai (size 0x40)
Mar/16/2025 21:31:39 ipsec,debug a0462399 f25b2e22 abf987b4 cc39bffd e5b6826f aee650fc 2d5943b1 27009a30
Mar/16/2025 21:31:39 ipsec,debug a064a6e9 1964eb59 f49405c8 395c9855 22701677 5e57110b 5389916e d907773f
Mar/16/2025 21:31:39 ipsec,debug => SK_ar (size 0x40)
Mar/16/2025 21:31:39 ipsec,debug e7a699b5 c9b86ed8 02efaa18 1f4644a3 477f1e35 3b17f868 ba789762 eb07e003
Mar/16/2025 21:31:39 ipsec,debug 7d3b785b b9267cc5 d797503e 002486ed ca8206be b9251ddf eca37be0 f7aa0b3a
Mar/16/2025 21:31:39 ipsec,debug => SK_ei (size 0x20)
Mar/16/2025 21:31:39 ipsec,debug 0984871a 4d598ed5 8652330b 9514e89b 683cd0ff 00ca5371 b28b987f db33693a
Mar/16/2025 21:31:39 ipsec,debug => SK_er (size 0x20)
Mar/16/2025 21:31:39 ipsec,debug 56a46cc0 34cbce3e 9e57d118 d90ba67d f5da8e25 90b62762 fe4aec9d 201f5555
Mar/16/2025 21:31:39 ipsec,debug => SK_pi (size 0x40)
Mar/16/2025 21:31:39 ipsec,debug beec77eb 02d59617 7b22263a 12bc9e29 561506a1 7116eabc 062d3b1a cd213042
Mar/16/2025 21:31:39 ipsec,debug 3688c15a a9fe0d88 214d9c1b 5f4c891a b8b1a24e efee7fcc 7fff6144 549bf4d9
Mar/16/2025 21:31:39 ipsec,debug => SK_pr (size 0x40)
Mar/16/2025 21:31:39 ipsec,debug 4c195f9d 1e1a47f4 fabd1e3b dd258f52 a6f4e090 6a5addcb da7a77c2 b4191636
Mar/16/2025 21:31:39 ipsec,debug 2a311254 735274f0 e893be9b 62315c28 6c9cfab2 0338550b b758caa2 55f1dd16
Mar/16/2025 21:31:39 ipsec,info new ike2 SA (R): ikev2-peer 192.168.5.4[500]-192.168.2.3[44422] a1aa5430fd51375f:6395763e3678ad58
Mar/16/2025 21:31:39 ipsec processing payloads: VID (none found)
Mar/16/2025 21:31:39 ipsec processing payloads: NOTIFY
Mar/16/2025 21:31:39 ipsec notify: NAT_DETECTION_SOURCE_IP
Mar/16/2025 21:31:39 ipsec notify: NAT_DETECTION_DESTINATION_IP
Mar/16/2025 21:31:39 ipsec notify: IKEV2_FRAGMENTATION_SUPPORTED
Mar/16/2025 21:31:39 ipsec notify: SIGNATURE_HASH_ALGORITHMS
Mar/16/2025 21:31:39 ipsec,debug 0001000200030004
Mar/16/2025 21:31:39 ipsec (NAT-T) REMOTE LOCAL
Mar/16/2025 21:31:39 ipsec KA list add: 192.168.5.4[4500]->192.168.2.3[44422]
Mar/16/2025 21:31:39 ipsec fragmentation negotiated
Mar/16/2025 21:31:39 ipsec,debug ===== received 624 bytes from 192.168.2.3[41057] to 192.168.5.4[4500]
Mar/16/2025 21:31:39 ipsec -> ike2 request, exchange: AUTH:1 192.168.2.3[41057] 6395763e3678ad58:a1aa5430fd51375f
Mar/16/2025 21:31:39 ipsec peer ports changed: 44422 -> 41057
Mar/16/2025 21:31:39 ipsec KA remove: 192.168.5.4[4500]->192.168.2.3[44422]
Mar/16/2025 21:31:39 ipsec,debug KA tree dump: 192.168.5.4[4500]->192.168.2.3[44422] (in_use=1)
Mar/16/2025 21:31:39 ipsec,debug KA removing this one...
Mar/16/2025 21:31:39 ipsec KA list add: 192.168.5.4[4500]->192.168.2.3[41057]
Mar/16/2025 21:31:39 ipsec payload seen: ENC (596 bytes)
Mar/16/2025 21:31:39 ipsec processing payload: ENC
Mar/16/2025 21:31:39 ipsec,debug => iv (size 0x10)
Mar/16/2025 21:31:39 ipsec,debug 450ac677 a321893b 39fe910c 86e81217
Mar/16/2025 21:31:39 ipsec,debug decrypted packet
Mar/16/2025 21:31:39 ipsec payload seen: ID_I (9 bytes)
Mar/16/2025 21:31:39 ipsec payload seen: ID_R (12 bytes)
Mar/16/2025 21:31:39 ipsec payload seen: NOTIFY (8 bytes)
Mar/16/2025 21:31:39 ipsec payload seen: AUTH (72 bytes)
Mar/16/2025 21:31:39 ipsec payload seen: SA (272 bytes)
Mar/16/2025 21:31:39 ipsec payload seen: TS_I (64 bytes)
Mar/16/2025 21:31:39 ipsec payload seen: TS_R (64 bytes)
Mar/16/2025 21:31:39 ipsec payload seen: CONFIG (32 bytes)
Mar/16/2025 21:31:39 ipsec processing payloads: NOTIFY
Mar/16/2025 21:31:39 ipsec notify: MOBIKE_SUPPORTED
Mar/16/2025 21:31:39 ipsec ike auth: respond
Mar/16/2025 21:31:39 ipsec processing payload: ID_I
Mar/16/2025 21:31:39 ipsec ID_I (FQDN): i
Mar/16/2025 21:31:39 ipsec processing payload: ID_R
Mar/16/2025 21:31:39 ipsec ID_R (ADDR4): 192.168.4.4
Mar/16/2025 21:31:39 ipsec processing payload: AUTH
Mar/16/2025 21:31:39 ipsec requested server id: 192.168.4.4
Mar/16/2025 21:31:39 ipsec processing payloads: NOTIFY
Mar/16/2025 21:31:39 ipsec notify: MOBIKE_SUPPORTED
Mar/16/2025 21:31:39 ipsec processing payload: AUTH
Mar/16/2025 21:31:39 ipsec requested auth method: SKEY
Mar/16/2025 21:31:39 ipsec,debug => peer's auth (size 0x40)
Mar/16/2025 21:31:39 ipsec,debug a8142ac6 6f73139a 86cc3156 4fae7a7d 3ca6fc08 ce339fa0 ba226662 03ace171
Mar/16/2025 21:31:39 ipsec,debug f805f99d f050260e 18824908 6c76f2a2 0e6d1cfc fb4f8c4c ca6cc855 972e3844
Mar/16/2025 21:31:39 ipsec,debug => auth nonce (size 0x18)
Mar/16/2025 21:31:39 ipsec,debug ae4d3496 5497bc78 54dcfbdc 923508e1 4472ef66 3fda629f
Mar/16/2025 21:31:39 ipsec,debug => SK_p (size 0x40)
Mar/16/2025 21:31:39 ipsec,debug beec77eb 02d59617 7b22263a 12bc9e29 561506a1 7116eabc 062d3b1a cd213042
Mar/16/2025 21:31:39 ipsec,debug 3688c15a a9fe0d88 214d9c1b 5f4c891a b8b1a24e efee7fcc 7fff6144 549bf4d9
Mar/16/2025 21:31:39 ipsec,debug => idhash (size 0x40)
Mar/16/2025 21:31:39 ipsec,debug bb024671 9aac6f3a 278d72d4 3814e2dc 9cf36cf3 83360355 bca34b83 bee40f3b
Mar/16/2025 21:31:39 ipsec,debug c0dd25cf 3502a6e3 d0257029 77f69e9b e37846e3 a36158db b6e7bc9c eb87f540
Mar/16/2025 21:31:39 ipsec,debug => calculated peer's AUTH (size 0x40)
Mar/16/2025 21:31:39 ipsec,debug a8142ac6 6f73139a 86cc3156 4fae7a7d 3ca6fc08 ce339fa0 ba226662 03ace171
Mar/16/2025 21:31:39 ipsec,debug f805f99d f050260e 18824908 6c76f2a2 0e6d1cfc fb4f8c4c ca6cc855 972e3844
Mar/16/2025 21:31:39 ipsec,info,account peer authorized: ikev2-peer 192.168.5.4[4500]-192.168.2.3[41057] a1aa5430fd51375f:6395763e3678ad58
Mar/16/2025 21:31:39 ipsec processing payloads: NOTIFY
Mar/16/2025 21:31:39 ipsec notify: MOBIKE_SUPPORTED
Mar/16/2025 21:31:39 ipsec peer wants tunnel mode
Mar/16/2025 21:31:39 ipsec processing payload: CONFIG
Mar/16/2025 21:31:39 ipsec attribute: internal IPv4 address
Mar/16/2025 21:31:39 ipsec attribute: internal IPv6 address
Mar/16/2025 21:31:39 ipsec attribute: internal IPv4 DNS
Mar/16/2025 21:31:39 ipsec attribute: internal IPv6 DNS
Mar/16/2025 21:31:39 ipsec attribute: internal IPv4 netmask
Mar/16/2025 21:31:39 ipsec attribute: application version
Mar/16/2025 21:31:39 ipsec,info acquired 192.168.59.19 address for 192.168.2.3, i
Mar/16/2025 21:31:39 ipsec processing payload: SA
Mar/16/2025 21:31:39 ipsec,debug unknown auth: #5
Mar/16/2025 21:31:39 ipsec,debug unknown auth: #8
Mar/16/2025 21:31:39 ipsec,debug unknown enc: #19
Mar/16/2025 21:31:39 ipsec,debug unknown enc: #18
Mar/16/2025 21:31:39 ipsec,debug unknown enc: #19
Mar/16/2025 21:31:39 ipsec,debug unknown enc: #18
Mar/16/2025 21:31:39 ipsec,debug unknown enc: #19
Mar/16/2025 21:31:39 ipsec,debug unknown enc: #18
Mar/16/2025 21:31:39 ipsec IKE Protocol: ESP
Mar/16/2025 21:31:39 ipsec proposal #1
Mar/16/2025 21:31:39 ipsec enc: aes256-ctr
Mar/16/2025 21:31:39 ipsec enc: aes256-cbc
Mar/16/2025 21:31:39 ipsec enc: aes192-ctr
Mar/16/2025 21:31:39 ipsec enc: aes192-cbc
Mar/16/2025 21:31:39 ipsec enc: aes128-ctr
Mar/16/2025 21:31:39 ipsec enc: aes128-cbc
Mar/16/2025 21:31:39 ipsec auth: sha512
Mar/16/2025 21:31:39 ipsec auth: sha384
Mar/16/2025 21:31:39 ipsec auth: sha256
Mar/16/2025 21:31:39 ipsec auth: unknown
Mar/16/2025 21:31:39 ipsec auth: unknown
Mar/16/2025 21:31:39 ipsec proposal #2
Mar/16/2025 21:31:39 ipsec enc: chcha20poly1305
Mar/16/2025 21:31:39 ipsec enc: aes256-gcm
Mar/16/2025 21:31:39 ipsec enc: unknown
Mar/16/2025 21:31:39 ipsec enc: unknown
Mar/16/2025 21:31:39 ipsec enc: aes192-gcm
Mar/16/2025 21:31:39 ipsec enc: unknown
Mar/16/2025 21:31:39 ipsec enc: unknown
Mar/16/2025 21:31:39 ipsec enc: aes128-gcm
Mar/16/2025 21:31:39 ipsec enc: unknown
Mar/16/2025 21:31:39 ipsec enc: unknown
Mar/16/2025 21:31:39 ipsec processing payload: TS_I
Mar/16/2025 21:31:39 ipsec 0.0.0.0/0
Mar/16/2025 21:31:39 ipsec [::/0]
Mar/16/2025 21:31:39 ipsec processing payload: TS_R
Mar/16/2025 21:31:39 ipsec 0.0.0.0/0
Mar/16/2025 21:31:39 ipsec [::/0]
Mar/16/2025 21:31:39 ipsec TSi in tunnel mode replaced with config address: 192.168.59.0/24
Mar/16/2025 21:31:39 ipsec candidate selectors: 0.0.0.0/0 <=> 192.168.59.19
Mar/16/2025 21:31:39 ipsec candidate selectors: [::/0] <=> [::/0]
Mar/16/2025 21:31:39 ipsec searching for policy for selector: 0.0.0.0/0 <=> 192.168.59.19
Mar/16/2025 21:31:39 ipsec generating policy
Mar/16/2025 21:31:39 ipsec matched proposal:
Mar/16/2025 21:31:39 ipsec proposal #1
Mar/16/2025 21:31:39 ipsec enc: aes256-cbc
Mar/16/2025 21:31:39 ipsec auth: sha512
Mar/16/2025 21:31:39 ipsec acquired spi 0xecf7001: ikev2-peer 192.168.5.4[4500]-192.168.2.3[41057] a1aa5430fd51375f:6395763e3678ad58
Mar/16/2025 21:31:39 ipsec ike auth: finish
Mar/16/2025 21:31:39 ipsec ID_R (ADDR4): 192.168.5.4
Mar/16/2025 21:31:39 ipsec,debug => auth nonce (size 0x20)
Mar/16/2025 21:31:39 ipsec,debug c55e30d7 582f99f9 41097792 5d03b77a 814a18c1 841e1646 707dff23 d7a98adf
Mar/16/2025 21:31:39 ipsec,debug => SK_p (size 0x40)
Mar/16/2025 21:31:39 ipsec,debug 4c195f9d 1e1a47f4 fabd1e3b dd258f52 a6f4e090 6a5addcb da7a77c2 b4191636
Mar/16/2025 21:31:39 ipsec,debug 2a311254 735274f0 e893be9b 62315c28 6c9cfab2 0338550b b758caa2 55f1dd16
Mar/16/2025 21:31:39 ipsec,debug => idhash (size 0x40)
Mar/16/2025 21:31:39 ipsec,debug f503d4ff 4c98b633 294a8553 dd2dfb07 f2f2eb27 0023a500 819c022d 874ed439
Mar/16/2025 21:31:39 ipsec,debug b8497ced 6beabd91 c947d891 912eb303 ead209c9 71625729 0913a4a8 05a9a24a
Mar/16/2025 21:31:39 ipsec,debug => my auth (size 0x40)
Mar/16/2025 21:31:39 ipsec,debug dc4876f7 18bb160e f26a4ec3 12c5518e 869f4731 b586bd5c d68b9678 a61ace49
Mar/16/2025 21:31:39 ipsec,debug fe342a9f 05b937dd 16a7cc6c f930d839 0c6a3c21 7c8380ff 805f932c ee4c826c
Mar/16/2025 21:31:39 ipsec adding payload: ID_R
Mar/16/2025 21:31:39 ipsec,debug => (size 0xc)
Mar/16/2025 21:31:39 ipsec,debug 0000000c 01000000 c0a80504
Mar/16/2025 21:31:39 ipsec adding payload: AUTH
Mar/16/2025 21:31:39 ipsec,debug => (size 0x48)
Mar/16/2025 21:31:39 ipsec,debug 00000048 02000000 dc4876f7 18bb160e f26a4ec3 12c5518e 869f4731 b586bd5c
Mar/16/2025 21:31:39 ipsec,debug d68b9678 a61ace49 fe342a9f 05b937dd 16a7cc6c f930d839 0c6a3c21 7c8380ff
Mar/16/2025 21:31:39 ipsec,debug 805f932c ee4c826c
Mar/16/2025 21:31:39 ipsec preparing internal IPv4 address
Mar/16/2025 21:31:39 ipsec preparing internal IPv4 netmask
Mar/16/2025 21:31:39 ipsec preparing internal IPv4 DNS
Mar/16/2025 21:31:39 ipsec preparing internal IPv4 DNS
Mar/16/2025 21:31:39 ipsec adding payload: CONFIG
Mar/16/2025 21:31:39 ipsec,debug => (size 0x28)
Mar/16/2025 21:31:39 ipsec,debug 00000028 02000000 00010004 c0a83b13 00020004 ffffff00 00030004 c0a86201
Mar/16/2025 21:31:39 ipsec,debug 00030004 72727272
Mar/16/2025 21:31:39 ipsec initiator selector: 192.168.59.19
Mar/16/2025 21:31:39 ipsec adding payload: TS_I
Mar/16/2025 21:31:39 ipsec,debug => (size 0x18)
Mar/16/2025 21:31:39 ipsec,debug 00000018 01000000 07000010 0000ffff c0a83b13 c0a83b13
Mar/16/2025 21:31:39 ipsec responder selector: 0.0.0.0/0
Mar/16/2025 21:31:39 ipsec adding payload: TS_R
Mar/16/2025 21:31:39 ipsec,debug => (size 0x18)
Mar/16/2025 21:31:39 ipsec,debug 00000018 01000000 07000010 0000ffff 00000000 ffffffff
Mar/16/2025 21:31:39 ipsec adding payload: SA
Mar/16/2025 21:31:39 ipsec,debug => (size 0x2c)
Mar/16/2025 21:31:39 ipsec,debug 0000002c 00000028 01030403 0ecf7001 0300000c 0100000c 800e0100 03000008
Mar/16/2025 21:31:39 ipsec,debug 0300000e 00000008 05000000
Mar/16/2025 21:31:39 ipsec <- ike2 reply, exchange: AUTH:1 192.168.2.3[41057] 6395763e3678ad58:a1aa5430fd51375f
Mar/16/2025 21:31:39 ipsec,debug ===== sending 528 bytes from 192.168.5.4[4500] to 192.168.2.3[41057]
Mar/16/2025 21:31:39 ipsec,debug 1 times of 532 bytes message will be sent to 192.168.2.3[41057]
Mar/16/2025 21:31:39 ipsec,debug => child keymat (size 0xc0)
Mar/16/2025 21:31:39 ipsec,debug bea08a15 acca8862 eb11d757 bbcb3492 fe75a355 3355395f 940978c1 85e7eb33
Mar/16/2025 21:31:39 ipsec,debug d324f0e7 e79c507b f3085c5f 5c1248c8 a046bbb1 e9510dfc d7439621 4adfe006
Mar/16/2025 21:31:39 ipsec,debug 7dcd083e f98b9af3 37935bf0 8bdb3dea b0e5a720 78676dfb e2d6f87b 639f6c1f
Mar/16/2025 21:31:39 ipsec,debug 03347790 be4f315c af16dc75 77251aac e6c3e222 c71aa751 67e55837 4dd0219f
Mar/16/2025 21:31:39 ipsec,debug 55cf85bc ad13e26d 7d01fd3a 6e1d12c5 2326f6ca bf8733fc fae01b63 258eedac
Mar/16/2025 21:31:39 ipsec,debug de290300 5b9c57e7 7328e78c c9394189 e0d6b53a d068455d bf02e8d6 e52f2bfd
Mar/16/2025 21:31:39 ipsec IPsec-SA established: 192.168.2.3[41057]->192.168.5.4[4500] spi=0xecf7001
Mar/16/2025 21:31:39 ipsec IPsec-SA established: 192.168.5.4[4500]->192.168.2.3[41057] spi=0x56fd56ad
Mar/16/2025 21:31:39 ipsec,debug ===== received 96 bytes from 192.168.2.3[41057] to 192.168.5.4[4500]
Mar/16/2025 21:31:39 ipsec -> ike2 request, exchange: INFORMATIONAL:2 192.168.2.3[41057] 6395763e3678ad58:a1aa5430fd51375f
Mar/16/2025 21:31:39 ipsec payload seen: ENC (68 bytes)
Mar/16/2025 21:31:39 ipsec processing payload: ENC
Mar/16/2025 21:31:39 ipsec,debug => iv (size 0x10)
Mar/16/2025 21:31:39 ipsec,debug 0cce99d6 4c2799d4 2c5c9610 ecb2236b
Mar/16/2025 21:31:39 ipsec,debug decrypted packet
Mar/16/2025 21:31:39 ipsec payload seen: DELETE (8 bytes)
Mar/16/2025 21:31:39 ipsec respond: info
Mar/16/2025 21:31:39 ipsec processing payloads: NOTIFY (none found)
Mar/16/2025 21:31:39 ipsec <- ike2 reply, exchange: INFORMATIONAL:2 192.168.2.3[41057] 6395763e3678ad58:a1aa5430fd51375f
Mar/16/2025 21:31:39 ipsec,debug ===== sending 160 bytes from 192.168.5.4[4500] to 192.168.2.3[41057]
Mar/16/2025 21:31:39 ipsec,debug 1 times of 164 bytes message will be sent to 192.168.2.3[41057]
Mar/16/2025 21:31:39 ipsec processing payloads: DELETE
Mar/16/2025 21:31:39 ipsec delete IKE SA
Mar/16/2025 21:31:39 ipsec,info killing ike2 SA: ikev2-peer 192.168.5.4[4500]-192.168.2.3[41057] a1aa5430fd51375f:6395763e3678ad58
Mar/16/2025 21:31:39 ipsec IPsec-SA killing: 192.168.2.3[41057]->192.168.5.4[4500] spi=0xecf7001
Mar/16/2025 21:31:39 ipsec IPsec-SA killing: 192.168.5.4[4500]->192.168.2.3[41057] spi=0x56fd56ad
Mar/16/2025 21:31:39 ipsec removing generated policy
Mar/16/2025 21:31:39 ipsec KA remove: 192.168.5.4[4500]->192.168.2.3[41057]
Mar/16/2025 21:31:39 ipsec,debug KA tree dump: 192.168.5.4[4500]->192.168.2.3[41057] (in_use=1)
Mar/16/2025 21:31:39 ipsec,debug KA removing this one...
Mar/16/2025 21:31:39 ipsec,info releasing address 192.168.59.19
Mar/16/2025 21:31:41 ipsec,debug => shared secret (first 0x100 of 0x200)
Mar/16/2025 21:31:41 ipsec,debug a8c98665 b903edac 11d66d26 cf1bcaf9 543ab784 2251ce94 1b21230a cfed3132
Mar/16/2025 21:31:41 ipsec,debug 30105811 2be67c22 c6897b37 6e2ac41e 15d9a886 1bef67da e52ceb6e c29e3f4b
Mar/16/2025 21:31:41 ipsec,debug b528c6e3 4ee17942 663c8b50 f227fbba f282e6ef b94a2e78 542cd4ed cf743df2
Mar/16/2025 21:31:41 ipsec,debug fb57a9b6 02344629 dde96d00 d7cf1e6d 93f4fd02 17773223 477c12d4 5d50b133
Mar/16/2025 21:31:41 ipsec,debug a14450c7 9ad16534 58bbbd6c f891f2e5 e19eed8f 931bad00 7f03ae3e b55598d3
Mar/16/2025 21:31:41 ipsec,debug 6e54f2d0 6c90bafb 6d3695f8 d635d76e acef922b 508f1a00 a21ae9b7 ef60e435
Mar/16/2025 21:31:41 ipsec,debug 4eb2c3ff b8913c85 d2b390ae 3ff0f41d 79dde041 06c07fb2 e91c7482 b357d4c8
Mar/16/2025 21:31:41 ipsec,debug 15aa9e65 c819fc25 982c56b1 8344b9b9 76115929 e6776c36 278873db 11535686
Mar/16/2025 21:31:43 ipsec,debug => shared secret (first 0x100 of 0x200)
Mar/16/2025 21:31:43 ipsec,debug f837da99 9234cbee 388e48e0 79fbefd3 2b239281 dac17195 552787dd a86eb8e7
Mar/16/2025 21:31:43 ipsec,debug 11aae69a e752943f 1ac5a10c b824ba9f fc63f786 61234a05 b2689add 7c1dd201
Mar/16/2025 21:31:43 ipsec,debug 00ff59eb 4c5ea669 b6a9093b 5e1f4b55 b31652f2 dfea5e4a 8f7410b5 3b3d93ed
Mar/16/2025 21:31:43 ipsec,debug 929921bd 7107412e 3aa41a5d fc9ab9c7 976095bb 7fe28ab1 6ae15549 8c5cb417
Mar/16/2025 21:31:43 ipsec,debug 46bb0423 b8205cbd 42f62186 7889e21a 5134e13b e17a83a1 a6d1117b a44b88b5
Mar/16/2025 21:31:43 ipsec,debug a3ae2f4a d8662126 36aa0279 a76dc872 9a46b0a1 1fdc9c6a dab02438 036d7b3d
Mar/16/2025 21:31:43 ipsec,debug 209ab087 9cb14c3f a21a2376 7781b3f0 a2f40e5c 0651099a fdb55002 9cea313e
Mar/16/2025 21:31:43 ipsec,debug 8abf6193 79197529 93e55825 0f35382d 12fa44fe fe531a5b 893a8120 ae31a477

Statistics: Posted by intensex — Tue Apr 22, 2025 4:31 am



Viewing all articles
Browse latest Browse all 23620

Latest Images

Trending Articles



Latest Images