Tengo una VPN por ipsec entre un Fortigate B60 (mi extremo) y un lucent del otro lado. Entre 2 técnicos nos costó mucho ponerla en marcha y finalmente lo arreglamos siguiendo el manual pero sin estar bien seguros de que es lo que nos estaba fallando.
Desde esta mañana ha dejado de funcionar y hemos repasado que ambos tenemos los mismos parámetros de configuración. He activado el debug y no veo claro en que punto está fallando:
Haciendo un reset del tunnel y un flush a mano veo
Código: Seleccionar todo
0:VpnSantiago:VpnSantiago2: IPsec SA connect 3 X.X.X.X->Y.Y.Y.Y:500, natt_mode=0
0:VpnSantiago: using existing connection, dpd_fail=1
0:VpnSantiago:VpnSantiago2: IPsec SA connect 3 X.X.X.X->Y.Y.Y.Y:500, natt_mode=0
0:VpnSantiago: using existing connection, dpd_fail=1
0:VpnSantiago: link is idle 3 X.X.X.X->Y.Y.Y.Y:500 dpd=2 seqno=8
0:VpnSantiago: link is up 3 X.X.X.X->Y.Y.Y.Y:500
0:VpnSantiago:45: sent IKE msg (P1_RETRANSMIT): X.X.X.X:500->Y.Y.Y.Y:500, len=268
0:VpnSantiago:VpnSantiago2: IPsec SA connect 3 X.X.X.X->Y.Y.Y.Y:500, natt_mode=0
0:VpnSantiago: using existing connection, dpd_fail=0
0:VpnSantiago: found phase2 VpnSantiago2
0:VpnSantiago: IPsec SA connect 3 X.X.X.X->Y.Y.Y.Y:500 negotiating
0:VpnSantiago:45:VpnSantiago2:7: ISAKMP SA still negotiating, queuing quick-mode request
0:VpnSantiago: link is idle 3 X.X.X.X->Y.Y.Y.Y:500 dpd=2 seqno=8
0:VpnSantiago:VpnSantiago2: IPsec SA connect 3 X.X.X.X->Y.Y.Y.Y:500, natt_mode=0
0:VpnSantiago: using existing connection, dpd_fail=0
0:VpnSantiago: found phase2 VpnSantiago2
0:VpnSantiago: link is idle 3 X.X.X.X->Y.Y.Y.Y:500 dpd=2 seqno=8
0:VpnSantiago:VpnSantiago2: IPsec SA connect 3 X.X.X.X->Y.Y.Y.Y:500, natt_mode=0
0:VpnSantiago: using existing connection, dpd_fail=0
0:VpnSantiago: found phase2 VpnSantiago2
0:VpnSantiago: link fail 3 X.X.X.X->Y.Y.Y.Y:500 dpd=2
0:VpnSantiago: link down 3 X.X.X.X->Y.Y.Y.Y:500
0:VpnSantiago: deleting
0:VpnSantiago: flushing
0:VpnSantiago: flushed
0:VpnSantiago: deleted
Luego se empieza a repetir
Código: Seleccionar todo
:VpnSantiago: created DPD triggered connection: 0x8c5aae8 3 X.X.X.X->Y.Y.Y.Y:500.
0:VpnSantiago: new connection.
0:VpnSantiago:77: initiator: aggressive mode is sending 1st message...
0:VpnSantiago:77: cookie c351e6d396fbd7df/0000000000000000
0:VpnSantiago:77: sent IKE msg (agg_i1send): X.X.X.X:500->Y.Y.Y.Y:500, len=268
VpnSantiago: Initiator: sent Y.Y.Y.Y aggressive mode message #1 (OK)
0:VpnSantiago:77: sent IKE msg (P1_RETRANSMIT): X.X.X.X:500->Y.Y.Y.Y:500, len=268
0:VpnSantiago:VpnSantiago2: IPsec SA connect 3 X.X.X.X->Y.Y.Y.Y:500, natt_mode=0
0:VpnSantiago: using existing connection, dpd_fail=1
0:VpnSantiago: link fail 3 X.X.X.X->Y.Y.Y.Y:500 dpd=2
0:VpnSantiago: ignore link fail, too old
0:VpnSantiago:77: sent IKE msg (P1_RETRANSMIT): X.X.X.X:500->Y.Y.Y.Y:500, len=268
0:VpnSantiago:VpnSantiago2: IPsec SA connect 3 X.X.X.X->Y.Y.Y.Y:500, natt_mode=0
0:VpnSantiago: using existing connection, dpd_fail=1
0:VpnSantiago: link fail 3 X.X.X.X->Y.Y.Y.Y:500 dpd=2
0:VpnSantiago: ignore link fail, too old
shrank heap by 126976 bytes
0:VpnSantiago:VpnSantiago2: IPsec SA connect 3 X.X.X.X->Y.Y.Y.Y:500, natt_mode=0
0:VpnSantiago: using existing connection, dpd_fail=1
0:VpnSantiago:77: sent IKE msg (P1_RETRANSMIT): X.X.X.X:500->Y.Y.Y.Y:500, len=268
0:VpnSantiago: link fail 3 X.X.X.X->Y.Y.Y.Y:500 dpd=2
0:VpnSantiago: DPD fail 3 X.X.X.X->Y.Y.Y.Y:500 send failure, resetting ...
0:VpnSantiago: deleting
0:VpnSantiago: flushing
0:VpnSantiago: flushed
0:VpnSantiago: deleted
0:VpnSantiago: created DPD triggered connection: 0x8c5aae8 3 X.X.X.X->Y.Y.Y.Y:500.
0:VpnSantiago: new connection.
Si alguien me puede echar una mano se lo agradecería