<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>IPSec strongswan creating CHILD_SA failed in logs</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/141453/ipsec-strongswan-creating-child_sa-failed-in-logs</link><description>Hello, 
 I have IPSec site to site tunnel and I need to troubleshoot why at some point tunnel goes down and or traffic stops flowing. 
 What means this part of log. At the moment tunnel is up and traffic is flowing. Other side has Fortinet firewall, my</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: IPSec strongswan creating CHILD_SA failed in logs</title><link>https://community.sophos.com/thread/526508?ContentTypeID=1</link><pubDate>Tue, 25 Jul 2023 08:47:36 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:f9bfaa5c-e82b-41ed-b8c7-6b16cbe3f61c</guid><dc:creator>Sreenivasulu Naidu</dc:creator><description>&lt;p&gt;&amp;nbsp;&lt;a href="/members/carlo-v"&gt;Carlo&lt;/a&gt;&amp;nbsp;By default, route based IPsec VPN on SFOS chose &amp;#39;dual&amp;#39; stack, you can chose to have ipv4 only; probably you do not have ipv6 traffic selectors configured on Fortinet side, causing&amp;nbsp;TS_UNACCEPTABLE, which is fine as SFOS side is not able to create IPv6 child SA and hence you are seeing this message. This is safe to ignore or you can keep ip version as ipv4 only.&lt;/p&gt;
&lt;p&gt;On Fortinet side, you would have probably used IPv4 subnets or Range for traffic selectors. This will narrow down the traffic selectors on SFOS side.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: IPSec strongswan creating CHILD_SA failed in logs</title><link>https://community.sophos.com/thread/526495?ContentTypeID=1</link><pubDate>Tue, 25 Jul 2023 06:38:45 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:5328286f-dd5f-4976-810e-e7cee89d330a</guid><dc:creator>Carlo</dc:creator><description>&lt;p&gt;Hello. Thanks but it is route based vpn without subnets configured on profile ipsec connection. When you create tunnel interface by default is selected ip version &amp;quot;dual&amp;quot; and fields for entering subnets are disabled. I have sd-wan route that works.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;And in that moment ipsec statusall&lt;/p&gt;
&lt;p&gt;Security Associations (2 up, 0 connecting):&lt;/p&gt;
&lt;p&gt;NAME-1{775}:&amp;nbsp; &amp;nbsp;10.xxx.xxx.xxx/32 === 10.xxx.xxx.xxx/32 10.xxx.xxx.xxx/32&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: IPSec strongswan creating CHILD_SA failed in logs</title><link>https://community.sophos.com/thread/526447?ContentTypeID=1</link><pubDate>Mon, 24 Jul 2023 14:37:51 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:bcd830f6-f8b3-4f1a-8a85-20b7530350fd</guid><dc:creator>Giridhar Katti</dc:creator><description>&lt;p&gt;The SA creation is failing because of incorrect traffic selectors and retry is happening every 60 secs. The below error log says it&lt;/p&gt;
&lt;p&gt;2023-07-24 08:06:55Z 24[IKE] &amp;lt;NAME-1|41&amp;gt; creating CHILD_SA failed, trying again in 67 seconds&lt;/p&gt;
&lt;p&gt;Maybe you need to check the traffic selector&amp;nbsp;config in the ipsec profile.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: IPSec strongswan creating CHILD_SA failed in logs</title><link>https://community.sophos.com/thread/526428?ContentTypeID=1</link><pubDate>Mon, 24 Jul 2023 12:29:50 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:7ec04b05-4e9a-4380-9052-abfd05a092d1</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;SFOS uses Strongswan. You can check the Strongswan Community for more insights:&amp;nbsp;&lt;a id="" href="https://wiki.strongswan.org/issues/2833"&gt;https://wiki.strongswan.org/issues/2833&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;tldr: seems to be a config issue.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: IPSec strongswan creating CHILD_SA failed in logs</title><link>https://community.sophos.com/thread/526414?ContentTypeID=1</link><pubDate>Mon, 24 Jul 2023 09:46:14 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:88498c44-abbc-40ac-8a70-15523da4dba8</guid><dc:creator>Carlo</dc:creator><description>&lt;p&gt;This post is not about guessing what is wrong.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I want to understand what this means&lt;/p&gt;
&lt;p&gt;2023-07-24 08:08:02Z 31[ENC] &amp;lt;NAME-1|41&amp;gt; parsed CREATE_CHILD_SA response 33 [ N(TS_UNACCEPT) ]&lt;br /&gt;2023-07-24 08:08:02Z 31[IKE] &amp;lt;NAME-1|41&amp;gt; received TS_UNACCEPTABLE notify, no CHILD_SA built&lt;br /&gt;2023-07-24 08:08:02Z 31[IKE] &amp;lt;NAME-1|41&amp;gt; creating CHILD_SA failed, trying again in 62 seconds&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;And why I am getting this every 60 sec even when tunnel is up and working&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: IPSec strongswan creating CHILD_SA failed in logs</title><link>https://community.sophos.com/thread/526410?ContentTypeID=1</link><pubDate>Mon, 24 Jul 2023 09:12:53 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:a675eb31-ad94-413c-a52d-1bdb148a6cc0</guid><dc:creator>Bharat J</dc:creator><description>&lt;h2 id="tunnel-established-but-traffic-stops-later"&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;Sophos Firewall only supports time-based rekeying.&lt;/span&gt;IPsec connection is established between a Sophos Firewall device and a third-party firewall. Traffic stops flowing after some time or getting logs as shared.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Sign in to the CLI and click&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;strong&gt;5&lt;/strong&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;for&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Device management&lt;/strong&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;and then click&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;strong&gt;3&lt;/strong&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;for&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Advanced shell&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Enter the following command:&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;code&gt;ipsec statusall&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;The output shows that IPSec SAs have been established.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Enter the following command:&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;code&gt;ip xfrm state&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;The output shows the transform sets for the VPN exist, that is, the SAs match.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;To prevent key exchange collisions, follow these guidelines:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Set the initiator&amp;#39;s phase 1 and phase 2 key life values lower than the responder&amp;#39;s.&lt;/li&gt;
&lt;li&gt;Set the phase 2 key life lower than the phase 1 value in both firewalls.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Example values are as follows:&lt;/p&gt;
&lt;div&gt;
&lt;div&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;strong&gt;Key life&lt;/strong&gt;&lt;/th&gt;
&lt;th&gt;&lt;strong&gt;Firewall 1&lt;/strong&gt;&lt;/th&gt;
&lt;th&gt;&lt;strong&gt;Firewall 2&lt;/strong&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Phase 1&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;12600 seconds&lt;/td&gt;
&lt;td&gt;10800 seconds&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Phase 2&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;5400 seconds&lt;/td&gt;
&lt;td&gt;3600 seconds&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Sophos Firewall only supports time-based rekeying. If you configured traffic-based rekeying on the third-party remote firewall, change it to time-based rekeying.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Please add local-id and remote-id on the IPsec VPN tunnel on both sides as agreed.&lt;/p&gt;
&lt;p&gt;Regards&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: IPSec strongswan creating CHILD_SA failed in logs</title><link>https://community.sophos.com/thread/526405?ContentTypeID=1</link><pubDate>Mon, 24 Jul 2023 08:51:39 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:6988943f-f124-4560-a4aa-66a485995b25</guid><dc:creator>Carlo</dc:creator><description>&lt;pre id="tw-target-text" dir="ltr" data-placeholder="Prijevod"&gt;&lt;span lang="en"&gt;Perhaps it is worth mentioning that the tunnel is up, traffic is flowing, it just gets re-keyed again. Then why do I see it in the logs.&lt;/span&gt;&lt;/pre&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: IPSec strongswan creating CHILD_SA failed in logs</title><link>https://community.sophos.com/thread/526398?ContentTypeID=1</link><pubDate>Mon, 24 Jul 2023 08:28:03 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:2e85da06-6667-41ce-aaa8-e9677162ee8b</guid><dc:creator>Carlo</dc:creator><description>&lt;p&gt;Not really. I asked what does this line mean&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;pre class="ui-code" data-mode="text"&gt;creating CHILD_SA failed&lt;/pre&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: IPSec strongswan creating CHILD_SA failed in logs</title><link>https://community.sophos.com/thread/526395?ContentTypeID=1</link><pubDate>Mon, 24 Jul 2023 08:23:30 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:2142ab1e-dac6-4884-ad42-0b56ff81cc01</guid><dc:creator>Bharat J</dc:creator><description>&lt;p&gt;Hi Carlo&lt;/p&gt;
&lt;p&gt;Hope below link might help to fix the issue&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://support.sophos.com/support/s/article/KB-000038566?language=en_US"&gt;Sophos Firewall: IPsec troubleshooting and most common errors&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Regards&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>