We replaced yesterday a Fortigate with a RB1100AHx4, we had configured in the fortigate, an IPsec VPN with a remote PFSense wich we do not manage.
We copied the settings
We could make the policy to show "established" in "PH2 State"
The only one "Active Peer" appears as "established" too, but it shows many "Rx Packets" and "0" "Tx Packets". It seems that nothing is going out through the VPN.
Sorry, my knowledge about IPsec is poor.
Here the settings:
Code: Select all
/ip ipsec profile
add dh-group=modp1536 enc-algorithm=aes-128 name=P2P-PFsense
/ip ipsec peer
add address=RemotePublicIP/32 name=P2P-PFsense profile=P2P-PFsense
/ip ipsec proposal
add auth-algorithms=sha256 enc-algorithms=aes-128-cbc lifetime=12h name=P2P-PFsense pfs-group=modp1536
/ip ipsec identity
add peer=P2P-PFsense
/ip ipsec policy
add dst-address=10.10.10.0/24 peer=P2P-PFsense proposal=P2P-PFsense src-address=192.168.5.0/24 tunnel=yes
--------------------------------------------------------------------
18:01:11 ipsec,debug ipsec: ===== received 92 bytes from RemotePublicIP[500] to LocalPublicIP[500]
18:01:11 ipsec,debug,packet ipsec: 89cd089f cffc7173 b73b7f09 368e5799 08100501 faebf738 0000005c 2730591d
18:01:11 ipsec,debug,packet ipsec: 7a84acf2 47fa5a9c 64814e3e 03ae7f06 ca351a03 ed5e836b 8fd6ca30 d1e59804
18:01:11 ipsec,debug,packet ipsec: aad69aaa 3ba336e1 721787f4 4669a30e 0b434782 720b5372 4cc6c302
18:01:11 ipsec,debug ipsec: receive Information.
18:01:11 ipsec,debug,packet ipsec: compute IV for phase2
18:01:11 ipsec,debug,packet ipsec: phase1 last IV:
18:01:11 ipsec,debug,packet ipsec: 1121d506 8fd608ca e3397f26 7f0f3a06 faebf738
18:01:11 ipsec,debug ipsec: hash(sha1)
18:01:11 ipsec,debug,packet ipsec: encryption(aes)
18:01:11 ipsec,debug,packet ipsec: phase2 IV computed:
18:01:11 ipsec,debug,packet ipsec: e9d9aae8 063f8637 fe4a8fde 2e88e160
18:01:11 ipsec,debug,packet ipsec: encryption(aes)
18:01:11 ipsec,debug,packet ipsec: IV was saved for next processing:
18:01:11 ipsec,debug,packet ipsec: 4669a30e 0b434782 720b5372 4cc6c302
18:01:11 ipsec,debug,packet ipsec: encryption(aes)
18:01:11 ipsec,debug,packet ipsec: with key:
18:01:11 ipsec,debug,packet ipsec: a1e128b0 e6061f80 d4d79b35 c4051584
18:01:11 ipsec,debug,packet ipsec: decrypted payload by IV:
18:01:11 ipsec,debug,packet ipsec: e9d9aae8 063f8637 fe4a8fde 2e88e160
18:01:11 ipsec,debug,packet ipsec: decrypted payload, but not trimed.
18:01:11 ipsec,debug,packet ipsec: 0b000018 bcc8ac00 69517baa 5376bf2b 78e28f51 97a5e47a 00000020 00000001
18:01:11 ipsec,debug,packet ipsec: 01108d28 89cd089f cffc7173 b73b7f09 368e5799 37a251f9 00000000 00000000
18:01:11 ipsec,debug,packet ipsec: padding len=1
18:01:11 ipsec,debug,packet ipsec: skip to trim padding.
18:01:11 ipsec,debug,packet ipsec: decrypted.
18:01:11 ipsec,debug,packet ipsec: 89cd089f cffc7173 b73b7f09 368e5799 08100501 faebf738 0000005c 0b000018
18:01:11 ipsec,debug,packet ipsec: bcc8ac00 69517baa 5376bf2b 78e28f51 97a5e47a 00000020 00000001 01108d28
18:01:11 ipsec,debug,packet ipsec: 89cd089f cffc7173 b73b7f09 368e5799 37a251f9 00000000 00000000
18:01:11 ipsec,debug,packet ipsec: HASH with:
18:01:11 ipsec,debug,packet ipsec: faebf738 00000020 00000001 01108d28 89cd089f cffc7173 b73b7f09 368e5799
18:01:11 ipsec,debug,packet ipsec: 37a251f9
18:01:11 ipsec,debug,packet ipsec: hmac(hmac_sha1)
18:01:11 ipsec,debug,packet ipsec: HASH computed:
18:01:11 ipsec,debug,packet ipsec: bcc8ac00 69517baa 5376bf2b 78e28f51 97a5e47a
18:01:11 ipsec,debug ipsec: hash validated.
18:01:11 ipsec,debug ipsec: begin.
18:01:11 ipsec,debug ipsec: seen nptype=8(hash) len=24
18:01:11 ipsec,debug ipsec: seen nptype=11(notify) len=32
18:01:11 ipsec,debug ipsec: succeed.
18:01:11 ipsec,debug ipsec: RemotePublicIP notify: R_U_THERE
18:01:11 ipsec,debug ipsec: RemotePublicIP DPD R-U-There received
18:01:11 ipsec,debug,packet ipsec: compute IV for phase2
18:01:11 ipsec,debug,packet ipsec: phase1 last IV:
18:01:11 ipsec,debug,packet ipsec: 1121d506 8fd608ca e3397f26 7f0f3a06 b908a4fa
18:01:11 ipsec,debug ipsec: hash(sha1)
18:01:11 ipsec,debug,packet ipsec: encryption(aes)
18:01:11 ipsec,debug,packet ipsec: phase2 IV computed:
18:01:11 ipsec,debug,packet ipsec: ba63f470 5e07945a 6092553e f3b482a0
18:01:11 ipsec,debug,packet ipsec: HASH with:
18:01:11 ipsec,debug,packet ipsec: b908a4fa 00000020 00000001 01108d29 89cd089f cffc7173 b73b7f09 368e5799
18:01:11 ipsec,debug,packet ipsec: 37a251f9
18:01:11 ipsec,debug,packet ipsec: hmac(hmac_sha1)
18:01:11 ipsec,debug,packet ipsec: HASH computed:
18:01:11 ipsec,debug,packet ipsec: 119a28cc 02b71edd d0248005 e8fe3e9e 7b317e4b
18:01:11 ipsec,debug,packet ipsec: begin encryption.
18:01:11 ipsec,debug,packet ipsec: encryption(aes)
18:01:11 ipsec,debug,packet ipsec: pad length = 8
18:01:11 ipsec,debug,packet ipsec: 0b000018 119a28cc 02b71edd d0248005 e8fe3e9e 7b317e4b 00000020 00000001
18:01:11 ipsec,debug,packet ipsec: 01108d29 89cd089f cffc7173 b73b7f09 368e5799 37a251f9 feb3e3d4 b5c2bb07
18:01:11 ipsec,debug,packet ipsec: encryption(aes)
18:01:11 ipsec,debug,packet ipsec: with key:
18:01:11 ipsec,debug,packet ipsec: a1e128b0 e6061f80 d4d79b35 c4051584
18:01:11 ipsec,debug,packet ipsec: encrypted payload by IV:
18:01:11 ipsec,debug,packet ipsec: ba63f470 5e07945a 6092553e f3b482a0
18:01:11 ipsec,debug,packet ipsec: save IV for next:
18:01:11 ipsec,debug,packet ipsec: 77d972eb 4de0de28 2d48738c 9e5fce66
18:01:11 ipsec,debug,packet ipsec: encrypted.
18:01:11 ipsec,debug ipsec: 92 bytes from LocalPublicIP[500] to RemotePublicIP[500]
18:01:11 ipsec,debug ipsec: 1 times of 92 bytes message will be sent to RemotePublicIP[500]
18:01:11 ipsec,debug,packet ipsec: 89cd089f cffc7173 b73b7f09 368e5799 08100501 b908a4fa 0000005c a022488d
18:01:11 ipsec,debug,packet ipsec: f8d937b2 74a9572c ae02acec 8d641ac8 7d402ac5 13d423c2 ef567bb0 941063b1
18:01:11 ipsec,debug,packet ipsec: c685260f 97acc937 b3219006 77d972eb 4de0de28 2d48738c 9e5fce66
18:01:11 ipsec,debug ipsec: sendto Information notify.
18:01:11 ipsec,debug ipsec: received a valid R-U-THERE, ACK sent
--------------------------------------------------------------------
Any suggestion will be apreciated.
Thanks in advance.
Regards,
Damián