'error identity not found for server:server.example.com peer: FQDN: iphone.
Here is the full ipsec log from the Mikrotik router:
Code: Select all
17:35:12 ipsec -> ike2 request, exchange: SA_INIT:0 1.1.1.1[63155] e4aa6fd2a5f9106a:0000000000000000
17:35:12 ipsec ike2 respond
17:35:12 ipsec payload seen: SA
17:35:12 ipsec payload seen: KE
17:35:12 ipsec payload seen: NONCE
17:35:12 ipsec payload seen: NOTIFY
17:35:12 ipsec payload seen: NOTIFY
17:35:12 ipsec payload seen: NOTIFY
17:35:12 ipsec payload seen: NOTIFY
17:35:12 ipsec processing payload: NONCE
17:35:12 ipsec processing payload: SA
17:35:12 ipsec IKE Protocol: IKE
17:35:12 ipsec proposal #1
17:35:12 ipsec enc: aes256-cbc
17:35:12 ipsec prf: hmac-sha256
17:35:12 ipsec auth: sha256
17:35:12 ipsec dh: modp2048
17:35:12 ipsec proposal #2
17:35:12 ipsec enc: aes256-cbc
17:35:12 ipsec prf: hmac-sha256
17:35:12 ipsec auth: sha256
17:35:12 ipsec dh: ecp256
17:35:12 ipsec proposal #3
17:35:12 ipsec enc: aes256-cbc
17:35:12 ipsec prf: hmac-sha256
17:35:12 ipsec auth: sha256
17:35:12 ipsec dh: modp1536
17:35:12 ipsec proposal #4
17:35:12 ipsec enc: aes128-cbc
17:35:12 ipsec prf: hmac-sha1
17:35:12 ipsec auth: sha1
17:35:12 ipsec dh: modp1024
17:35:12 ipsec proposal #5
17:35:12 ipsec enc: 3des-cbc
17:35:12 ipsec prf: hmac-sha1
17:35:12 ipsec auth: sha1
17:35:12 ipsec dh: modp1024
17:35:12 ipsec matched proposal:
17:35:12 ipsec proposal #1
17:35:12 ipsec enc: aes256-cbc
17:35:12 ipsec prf: hmac-sha256
17:35:12 ipsec auth: sha256
17:35:12 ipsec dh: modp2048
17:35:12 ipsec processing payload: KE
17:35:13 ipsec adding payload: SA
17:35:13 ipsec adding payload: KE
17:35:13 ipsec adding payload: NONCE
17:35:13 ipsec adding notify: NAT_DETECTION_SOURCE_IP
17:35:13 ipsec adding notify: NAT_DETECTION_DESTINATION_IP
17:35:13 ipsec adding payload: CERTREQ
17:35:13 ipsec <- ike2 reply, exchange: SA_INIT:0 1.1.1.1[63155] e4aa6fd2a5f9106a:7ee7068a627f88f7
17:35:13 ipsec,info new ike2 SA (R): 2.2.2.2[500]-1.1.1.1[63155] spi:7ee7068a627f88f7:e4aa6fd2a5f9106a
17:35:13 ipsec processing payloads: VID (none found)
17:35:13 ipsec processing payloads: NOTIFY
17:35:13 ipsec notify: REDIRECT_SUPPORTED
17:35:13 ipsec notify: NAT_DETECTION_SOURCE_IP
17:35:13 ipsec notify: NAT_DETECTION_DESTINATION_IP
17:35:13 ipsec notify: IKEV2_FRAGMENTATION_SUPPORTED
17:35:13 ipsec (NAT-T) REMOTE
17:35:13 ipsec KA list add: 2.2.2.2[4500]->1.1.1.1[63155]
17:35:13 ipsec -> ike2 request, exchange: AUTH:1 1.1.1.1[46261] e4aa6fd2a5f9106a:7ee7068a627f88f7
17:35:13 ipsec peer ports changed: 63155 -> 46261
17:35:13 ipsec KA remove: 2.2.2.2[4500]->1.1.1.1[63155]
17:35:13 ipsec KA list add: 2.2.2.2[4500]->1.1.1.1[46261]
17:35:13 ipsec payload seen: ENC
17:35:13 ipsec processing payload: ENC
17:35:13 ipsec payload seen: ID_I
17:35:13 ipsec payload seen: NOTIFY
17:35:13 ipsec payload seen: ID_R
17:35:13 ipsec payload seen: CONFIG
17:35:13 ipsec payload seen: NOTIFY
17:35:13 ipsec payload seen: NOTIFY
17:35:13 ipsec payload seen: SA
17:35:13 ipsec payload seen: TS_I
17:35:13 ipsec payload seen: TS_R
17:35:13 ipsec payload seen: NOTIFY
17:35:13 ipsec processing payloads: NOTIFY
17:35:13 ipsec notify: INITIAL_CONTACT
17:35:13 ipsec notify: ESP_TFC_PADDING_NOT_SUPPORTED
17:35:13 ipsec notify: NON_FIRST_FRAGMENTS_ALSO
17:35:13 ipsec notify: MOBIKE_SUPPORTED
17:35:13 ipsec ike auth: respond
17:35:13 ipsec processing payload: ID_I
17:35:13 ipsec ID_I (FQDN): iphone
17:35:13 ipsec processing payload: ID_R
17:35:13 ipsec ID_R (FQDN): server.example.com
17:35:13 ipsec processing payload: AUTH (not found)
17:35:13 ipsec requested server id: server.example.com
17:35:13 ipsec,error identity not found for server:server.example.com peer: FQDN: iphone
17:35:13 ipsec reply notify: AUTHENTICATION_FAILED
17:35:13 ipsec adding notify: AUTHENTICATION_FAILED
17:35:13 ipsec <- ike2 reply, exchange: AUTH:1 1.1.1.1[46261] e4aa6fd2a5f9106a:7ee7068a627f88f7
17:35:13 ipsec,info killing ike2 SA: 2.2.2.2[4500]-1.1.1.1[46261] spi:7ee7068a627f88f7:e4aa6fd2a5f9106a
17:35:13 ipsec KA remove: 2.2.2.2[4500]->1.1.1.1[46261]
- 1.1.1.1 = Public IP adress from my 4G cellphone provider
- 2.2.2.2 = Public IP address from my Mikrotik router (FQDN = server.example.com)
Code: Select all
[admin@MikroTik] /ip ipsec identity> print
Flags: D - dynamic, X - disabled
0 peer=vpn-rw auth-method=digital-signature mode-config=vpnrw my-id=fqdn:server.example.com match-by=certificate certificate=servercert remote-certificate=iphonecert generate-policy=port-strict
I checked all certificates: Common Names and SAN's are all the same as specified in 'my-id=' and 'remote-id'.
The Mikrotik router (RB750Gr3) is running OS version 6.46.1 (latest stable as of this moment). The iPhone runs IOS 13.3.
Anyone have a clue where I should look at to make this setup work?