Unaccounted IPSec Errors
Posted: Tue Mar 27, 2018 12:36 am
It seems recently I have been getting a lot of IPSec errors. Currently, IPSec is only used for a PPP tunnel between two MikroTik sites.
Looking at the log it seems to be trying to make a connection to an IP address in Japan. The address is not one that I recognize or within my local vicinity. The errors seem to have happened for well over a day.
Not sure what may be causing this error but the first one I can think of is a possible attack attempt on the PPP.
Does anyone have anymore detail on the errors?
I have attached an excerpt of the log below with my own IP masked for security.
Looking at the log it seems to be trying to make a connection to an IP address in Japan. The address is not one that I recognize or within my local vicinity. The errors seem to have happened for well over a day.
Not sure what may be causing this error but the first one I can think of is a possible attack attempt on the PPP.
Does anyone have anymore detail on the errors?
I have attached an excerpt of the log below with my own IP masked for security.
Code: Select all
03:32:52 ipsec,error 121.108.245.39 failed to get valid proposal.
03:32:52 ipsec,error 121.108.245.39 failed to pre-process ph1 packet (side: 1, status 1).
03:32:52 ipsec,error 121.108.245.39 phase1 negotiation failed.
03:32:52 ipsec,error no suitable proposal found.
03:32:52 ipsec,info respond new phase 1 (Identity Protection): xxx.x.xxx.xxx[500]<=>121.108.245.39[500]
03:32:55 ipsec,error 121.108.245.39 failed to get valid proposal.
03:32:55 ipsec,error 121.108.245.39 failed to pre-process ph1 packet (side: 1, status 1).
03:32:55 ipsec,error 121.108.245.39 phase1 negotiation failed.
03:32:55 ipsec,error no suitable proposal found.
03:32:55 ipsec,info respond new phase 1 (Identity Protection): xxx.x.xxx.xxx[500]<=>121.108.245.39[500]
03:32:58 ipsec,error 121.108.245.39 failed to get valid proposal.
03:32:58 ipsec,error 121.108.245.39 failed to pre-process ph1 packet (side: 1, status 1).
03:32:58 ipsec,error 121.108.245.39 phase1 negotiation failed.
03:32:58 ipsec,error no suitable proposal found.
03:32:58 ipsec,info respond new phase 1 (Identity Protection): xxx.x.xxx.xxx[500]<=>121.108.245.39[500]
03:33:01 ipsec,error 121.108.245.39 failed to get valid proposal.
03:33:01 ipsec,error 121.108.245.39 failed to pre-process ph1 packet (side: 1, status 1).
03:33:01 ipsec,error 121.108.245.39 phase1 negotiation failed.
03:33:01 ipsec,error no suitable proposal found.
03:33:01 ipsec,info respond new phase 1 (Identity Protection): xxx.x.xxx.xxx[500]<=>121.108.245.39[500]
03:33:04 ipsec,error 121.108.245.39 failed to get valid proposal.
03:33:04 ipsec,error 121.108.245.39 failed to pre-process ph1 packet (side: 1, status 1).
03:33:04 ipsec,error 121.108.245.39 phase1 negotiation failed.
03:33:04 ipsec,error no suitable proposal found.
03:33:04 ipsec,info respond new phase 1 (Identity Protection): xxx.x.xxx.xxx[500]<=>121.108.245.39[500]
03:33:07 ipsec,error 121.108.245.39 failed to get valid proposal.
03:33:07 ipsec,error 121.108.245.39 failed to pre-process ph1 packet (side: 1, status 1).
03:33:07 ipsec,error 121.108.245.39 phase1 negotiation failed.
03:33:07 ipsec,error no suitable proposal found.
03:33:07 ipsec,info respond new phase 1 (Identity Protection): xxx.x.xxx.xxx[500]<=>121.108.245.39[500]
03:33:10 ipsec,error 121.108.245.39 failed to get valid proposal.
03:33:10 ipsec,error 121.108.245.39 failed to pre-process ph1 packet (side: 1, status 1).
03:33:10 ipsec,error 121.108.245.39 phase1 negotiation failed.
03:33:10 ipsec,error no suitable proposal found.
03:33:10 ipsec,info respond new phase 1 (Identity Protection): xxx.x.xxx.xxx[500]<=>121.108.245.39[500]
03:33:13 ipsec,error 121.108.245.39 failed to get valid proposal.
03:33:13 ipsec,error 121.108.245.39 failed to pre-process ph1 packet (side: 1, status 1).
03:33:13 ipsec,error 121.108.245.39 phase1 negotiation failed.
03:33:13 ipsec,error no suitable proposal found.
03:33:13 ipsec,info respond new phase 1 (Identity Protection): xxx.x.xxx.xxx[500]<=>121.108.245.39[500]
03:33:16 ipsec,error 121.108.245.39 failed to get valid proposal.
03:33:16 ipsec,error 121.108.245.39 failed to pre-process ph1 packet (side: 1, status 1).
03:33:16 ipsec,error 121.108.245.39 phase1 negotiation failed.
03:33:16 ipsec,error no suitable proposal found.
03:33:16 ipsec,info respond new phase 1 (Identity Protection): xxx.x.xxx.xxx[500]<=>121.108.245.39[500]
03:33:19 ipsec,error 121.108.245.39 failed to get valid proposal.
03:33:19 ipsec,error 121.108.245.39 failed to pre-process ph1 packet (side: 1, status 1).
03:33:19 ipsec,error 121.108.245.39 phase1 negotiation failed.
03:33:19 ipsec,error no suitable proposal found.
03:33:19 ipsec,info respond new phase 1 (Identity Protection): xxx.x.xxx.xxx[500]<=>121.108.245.39[500]