2014年6月21日 星期六

IPSec/strongswan failures and checkpoints

FAIL_CP_REQ
Add

leftsourceip=%config
leftdns=%dns

TS_UNACCEPTABLE
Check left|right subnet and proto settings.

NO_PROPOSAL_CHOSEN
check ike=XXX and esp=XXX

libopenikev2: openikev2::Payload_NOTIFY Class Reference
http://openikev2.sourceforge.net/libopenikev2_api/classopenikev2_1_1Payload__NOTIFY.html
UNSUPPORTED_CRITICAL_PAYLOAD Unsupported critical payload.
INVALID_IKE_SPI Invalid IKE SPI.
INVALID_MAJOR_VERSION Invalid Major Version.
INVALID_SYNTAX Invalid syntax.
INVALID_MESSAGE_ID Invalid message ID.
INVALID_SPI Invalid SPI.
NO_PROPOSAL_CHOSEN No proposal chosen.
INVALID_KE_PAYLOAD Invalid KE payload.
AUTHENTICATION_FAILED Authentication failed.
SINGLE_PAIR_REQUIRED Single pair required.
NO_ADDITIONAL_SAS No additional SAs.
INTERNAL_ADDRESS_FAILURE Internal address failure.
FAILED_CP_REQUIRED Failed Configuration Payload required.
TS_UNACCEPTABLE Traffic selector unacceptable.
INVALID_SELECTORS Invalid selectors.
INITIAL_CONTACT Initial contact.
SET_WINDOW_SIZE Set window size.
ADDITIONAL_TS_POSSIBLE Additional Traffic selector possible.
IPCOMP_SUPPORTED IPcomp supported.
NAT_DETECTION_SOURCE_IP NAT detection source ip.
NAT_DETECTION_DESTINATION_IP NAT detection destination ip.
COOKIE Cookie.
USE_TRANSPORT_MODE Use transport mode.
HTTP_CERT_LOOKUP_SUPPORTED HTTP certificate lookup supported.
REKEY_SA Rekey SA.
ESP_TFC_PADDING_NOT_SUPPORTED ESP TFC padding not supported.
NON_FIRST_FRAGMENT_ALSO Non first fragment also.

沒有留言: