Community discussions

MikroTik App
 
jaxed8
Member Candidate
Member Candidate
Topic Author
Posts: 195
Joined: Tue Jul 27, 2021 8:25 pm

IKEV2 IPsec "payload missing: SA" error

Wed Jan 05, 2022 4:45 pm

Hello everyone
I recently setup a new IKEV2 server on Ubuntu and try to connect to it with RB4011 v6.49 but I got this error payload missing: SA.
I connect to that server from my cellphone which is connected to that RB4011 so the internet connection and server are working (I guess).
My question is in what cases and scenarios we get this error? If I know why I'm getting this error it will be a lot easier to troubleshot.
Any help will be highly appreciated
 
jaxed8
Member Candidate
Member Candidate
Topic Author
Posts: 195
Joined: Tue Jul 27, 2021 8:25 pm

Re: IKEV2 IPsec "payload missing: SA" error

Wed Jan 05, 2022 7:52 pm

What does this error means?
Screenshot 2022-01-05 212208.png
Screenshot 2022-01-05 212145.png
You do not have the required permissions to view the files attached to this post.
 
User avatar
own3r1138
Forum Veteran
Forum Veteran
Posts: 728
Joined: Sun Feb 14, 2021 12:33 am
Location: Pleiades
Contact:

Re: IKEV2 IPsec "payload missing: SA" error  [SOLVED]

Wed Jan 05, 2022 7:57 pm

would you send a full log? for the connection looks like the wrong ph1 or ph2 config.
 
jaxed8
Member Candidate
Member Candidate
Topic Author
Posts: 195
Joined: Tue Jul 27, 2021 8:25 pm

Re: IKEV2 IPsec "payload missing: SA" error

Wed Jan 05, 2022 8:40 pm

would you send a full log? for the connection looks like the wrong ph1 or ph2 config.
What do you mean by full log? there is only this error in the logs.
 
User avatar
sindy
Forum Guru
Forum Guru
Posts: 11266
Joined: Mon Dec 04, 2017 9:19 pm

Re: IKEV2 IPsec "payload missing: SA" error

Wed Jan 05, 2022 9:21 pm

What do you mean by full log?
See this: viewtopic.php?p=903062#p903062

In your case, the l2tp part is irrelevant of course.
 
jaxed8
Member Candidate
Member Candidate
Topic Author
Posts: 195
Joined: Tue Jul 27, 2021 8:25 pm

Re: IKEV2 IPsec "payload missing: SA" error

Wed Jan 12, 2022 3:25 am

The problem was with ph1 or ph2 configurations on the server as @own3r1138 said, after changing the IKE and ESP suits on the /etc/ipsec.conf the problem solved.
Thanks @own3r1138 and Thanks @sindy for the tip.
 
User avatar
own3r1138
Forum Veteran
Forum Veteran
Posts: 728
Joined: Sun Feb 14, 2021 12:33 am
Location: Pleiades
Contact:

Re: IKEV2 IPsec "payload missing: SA" error

Wed Jan 12, 2022 6:23 am

@jaxed8
yvw
 
Keang2424
just joined
Posts: 1
Joined: Sun Jun 25, 2023 3:13 am

Re: IKEV2 IPsec "payload missing: SA" error

Mon Jun 26, 2023 8:59 am

@jaxed8
I'm having the same problem. You can share point example edit?
 
gutekpl
Frequent Visitor
Frequent Visitor
Posts: 94
Joined: Wed Feb 20, 2019 6:31 pm

Re: IKEV2 IPsec "payload missing: SA" error

Wed Jul 26, 2023 3:26 pm

Got the same. I have VPN set up on my hap ac2 and certificates expiry was set to 1yr, I was renewing them some time ago and problem probably occurred somewhere around that but I am not sure. What should I check?
 
ZigaK
just joined
Posts: 1
Joined: Wed Aug 21, 2024 2:42 am

Re: IKEV2 IPsec "payload missing: SA" error

Wed Aug 21, 2024 10:39 am

I would like to add something here for anyone having the same issue.
Our IPSec tunel between two sites was working fine for 200 days. Then it suddenly dropped and couldn't reestablish. Ipsec log showed that Site B was getting payload missing: SA error.
The solution was to add Firewall filter rule on input chain to accept udp port 4500.