Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPSec strongswan creating CHILD_SA failed in logs

Hello,

I have IPSec site to site tunnel and I need to troubleshoot why at some point tunnel goes down and or traffic stops flowing.

What means this part of log. At the moment tunnel is up and traffic is flowing. Other side has Fortinet firewall, my other tunnels xgs to xgs are working fine.

2023-07-24 08:06:55Z 15[IKE] <NAME-1|41> establishing CHILD_SA NAME-2
2023-07-24 08:06:55Z 15[ENC] <NAME-1|41> generating CREATE_CHILD_SA request 31 [ SA No KE TSi TSr ]
2023-07-24 08:06:55Z 15[NET] <NAME-1|41> sending packet: from xxx.xxx.xxx.xxx[500] to xxx.xxx.xxx.xxx[500] (448 bytes)
2023-07-24 08:06:55Z 24[NET] <NAME-1|41> received packet: from xxx.xxx.xxx.xxx[500] to xxx.xxx.xxx.xxx[500] (80 bytes)
2023-07-24 08:06:55Z 24[ENC] <NAME-1|41> parsed CREATE_CHILD_SA response 31 [ N(TS_UNACCEPT) ]
2023-07-24 08:06:55Z 24[IKE] <NAME-1|41> received TS_UNACCEPTABLE notify, no CHILD_SA built
2023-07-24 08:06:55Z 24[IKE] <NAME-1|41> creating CHILD_SA failed, trying again in 67 seconds
2023-07-24 08:07:10Z 08[IKE] <NAME-1|42> retransmit 5 of request with message ID 14
2023-07-24 08:07:10Z 08[NET] <NAME-1|42> sending packet: from xxx.xxx.xxx.xxx[500] to xxx.xxx.xxx.xxx[500] (80 bytes)
2023-07-24 08:07:10Z 09[NET] <NAME-1|42> received packet: from xxx.xxx.xxx.xxx[500] to xxx.xxx.xxx.xxx[500] (80 bytes)
2023-07-24 08:07:10Z 09[ENC] <NAME-1|42> parsed INFORMATIONAL response 14 [ ]
2023-07-24 08:07:25Z 32[IKE] <NAME-1|41> sending DPD request
2023-07-24 08:07:25Z 32[ENC] <NAME-1|41> generating INFORMATIONAL request 32 [ ]
2023-07-24 08:07:25Z 32[NET] <NAME-1|41> sending packet: from xxx.xxx.xxx.xxx[500] to xxx.xxx.xxx.xxx[500] (80 bytes)
2023-07-24 08:07:25Z 05[NET] <NAME-1|41> received packet: from xxx.xxx.xxx.xxx[500] to xxx.xxx.xxx.xxx[500] (80 bytes)
2023-07-24 08:07:25Z 05[ENC] <NAME-1|41> parsed INFORMATIONAL response 32 [ ]
2023-07-24 08:07:39Z 22[IKE] <NAME-1|42> sending DPD request
2023-07-24 08:07:39Z 22[ENC] <NAME-1|42> generating INFORMATIONAL request 15 [ ]
2023-07-24 08:07:39Z 22[NET] <NAME-1|42> sending packet: from xxx.xxx.xxx.xxx[500] to xxx.xxx.xxx.xxx[500] (80 bytes)
2023-07-24 08:07:39Z 18[NET] <NAME-1|42> received packet: from xxx.xxx.xxx.xxx[500] to xxx.xxx.xxx.xxx[500] (80 bytes)
2023-07-24 08:07:39Z 18[ENC] <NAME-1|42> parsed INFORMATIONAL response 15 [ ]
2023-07-24 08:08:02Z 16[IKE] <NAME-1|41> establishing CHILD_SA NAME-2
2023-07-24 08:08:02Z 16[ENC] <NAME-1|41> generating CREATE_CHILD_SA request 33 [ SA No KE TSi TSr ]
2023-07-24 08:08:02Z 16[NET] <NAME-1|41> sending packet: from xxx.xxx.xxx.xxx[500] to xxx.xxx.xxx.xxx[500] (448 bytes)
2023-07-24 08:08:02Z 31[NET] <NAME-1|41> received packet: from xxx.xxx.xxx.xxx[500] to xxx.xxx.xxx.xxx[500] (80 bytes)
2023-07-24 08:08:02Z 31[ENC] <NAME-1|41> parsed CREATE_CHILD_SA response 33 [ N(TS_UNACCEPT) ]
2023-07-24 08:08:02Z 31[IKE] <NAME-1|41> received TS_UNACCEPTABLE notify, no CHILD_SA built
2023-07-24 08:08:02Z 31[IKE] <NAME-1|41> creating CHILD_SA failed, trying again in 62 seconds

Thank you



This thread was automatically locked due to age.
Parents Reply Children