Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

(libreswan)Problems caused by low version #25042

Open
wbxnewboy opened this issue Sep 26, 2024 · 0 comments
Open

(libreswan)Problems caused by low version #25042

wbxnewboy opened this issue Sep 26, 2024 · 0 comments

Comments

@wbxnewboy
Copy link

libreswan/libreswan#1816

Tue Sep 24 15:00:03 2024 authpriv.warn pluto[24873]: "SRXJUNOS1/1x2" #1: sent IKE_SA_INIT request to 119.112.11.6:500
Tue Sep 24 15:00:03 2024 authpriv.warn pluto[24873]: "SRXJUNOS1/1x2" #1: switching CHILD #4 to pending connection "SRXJUNOS1/1x1"
Tue Sep 24 15:00:03 2024 authpriv.warn pluto[24873]: "SRXJUNOS1/1x2" #1: sent IKE_AUTH request {cipher=AES_CBC_256 integ=HMAC_SHA1_96 prf=HMAC_SHA1 group=MODP2048}
Tue Sep 24 15:00:03 2024 authpriv.warn pluto[24873]: "SRXJUNOS1/1x2" #1: initiator established IKE SA; authenticated peer using authby=secret and ID_IPV4_ADDR '119.112.11.6'
Tue Sep 24 15:00:03 2024 authpriv.warn pluto[24873]: "SRXJUNOS1/1x1" #4: initiator established Child SA using #1; IPsec tunnel [192.168.18.0-192.168.18.255:0-65535 0] -> [172.16.1.0-172.16.1.255:0-65535 0] {ESP=>0x86c232ec <0x0935486d xfrm=AES_CBC_256-HMAC_SHA2_256_128 DPD=active}
Tue Sep 24 15:00:03 2024 authpriv.warn pluto[24873]: "SRXJUNOS1/1x2" #6: initiating Child SA using IKE SA #1
Tue Sep 24 15:00:03 2024 authpriv.warn pluto[24873]: "SRXJUNOS1/1x2" #6: Child SA proposals (new child):
Tue Sep 24 15:00:03 2024 authpriv.warn pluto[24873]: "SRXJUNOS1/1x2" #6: 1:ESP=AES_CBC_256-HMAC_SHA2_256_128-MODP2048-ENABLED+DISABLED
Tue Sep 24 15:00:03 2024 authpriv.warn pluto[24873]: "SRXJUNOS1/1x2" #9: Child SA proposals (new child):
Tue Sep 24 15:00:03 2024 authpriv.warn pluto[24873]: "SRXJUNOS1/1x2" #9: 1:ESP=AES_CBC_256-HMAC_SHA2_256_128-MODP2048-ENABLED+DISABLED
Tue Sep 24 15:00:03 2024 authpriv.warn pluto[24873]: "SRXJUNOS1/1x2" #9: no local proposal matches remote proposals 1:ESP:ENCR=AES_CBC_256;INTEG=HMAC_SHA2_256_128;ESN=DISABLED
Tue Sep 24 15:00:03 2024 authpriv.warn pluto[24873]: "SRXJUNOS1/1x2" #9: CREATE_CHILD_SA request failed, responder SA processing returned NO_PROPOSAL_CHOSEN
Tue Sep 24 15:00:03 2024 authpriv.warn pluto[24873]: "SRXJUNOS1/1x2" #1: responding to CREATE_CHILD_SA message (ID 0) from 119.112.11.6:500 with encrypted notification NO_PROPOSAL_CHOSEN
Tue Sep 24 15:00:03 2024 authpriv.warn pluto[24873]: "SRXJUNOS1/1x2" #6: sent CREATE_CHILD_SA request for new IPsec SA
Tue Sep 24 15:00:03 2024 authpriv.warn pluto[24873]: "SRXJUNOS1/1x2" #6: CREATE_CHILD_SA failed with error notification NO_PROPOSAL_CHOSEN
Tue Sep 24 15:00:03 2024 authpriv.warn pluto[24873]: "SRXJUNOS1/1x2" #6: state transition 'initiate create Child SA (CREATE_CHILD_SA)' failed
Tue Sep 24 15:00:03 2024 authpriv.warn pluto[24873]: "SRXJUNOS1/1x2" #10: Child SA proposals (new child):
Tue Sep 24 15:00:03 2024 authpriv.warn pluto[24873]: "SRXJUNOS1/1x2" #10: 1:ESP=AES_CBC_256-HMAC_SHA2_256_128-MODP2048-ENABLED+DISABLED
Tue Sep 24 15:00:03 2024 authpriv.warn pluto[24873]: "SRXJUNOS1/1x2" #10: no local proposal matches remote proposals 1:ESP:ENCR=AES_CBC_256;INTEG=HMAC_SHA2_256_128;ESN=DISABLED
Tue Sep 24 15:00:03 2024 authpriv.warn pluto[24873]: "SRXJUNOS1/1x2" #10: CREATE_CHILD_SA request failed, responder SA processing returned NO_PROPOSAL_CHOSEN
Tue Sep 24 15:00:03 2024 authpriv.warn pluto[24873]: "SRXJUNOS1/1x2" #1: responding to CREATE_CHILD_SA message (ID 1) from 119.112.11.6:500 with encrypted notification NO_PROPOSAL_CHOSEN

conn SRXJUNOS1
auto=start
authby=secret
ikev2=yes
left=201.75.26.55
leftid=201.75.26.55

    leftsubnets={192.168.18.0/24}
    right=119.112.11.6
    rightid=119.112.11.6

    rightsubnets={172.16.1.0/24,172.16.3.0/24}
    dpdaction=restart
    dpdtimeout=150
    dpddelay=30
    ikelifetime=8h
    rekey=no
    rekeymargin=9m

    phase2=esp
    ike=aes256-sha1;modp2048
    phase2alg=aes256-sha256

    mark-in=0x64
    mark-out=0x64
    vti-interface=vti3
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant