[ previous ] [ next ] [ threads ]
 
 From:  DLStrout <dstrout at maine dot rr dot com>
 To:  m0n0wall at lists dot m0n0 dot ch
 Subject:  Unfamiliar IPsec (racoon) message ....
 Date:  Sat, 19 Mar 2005 00:07:59 -0500
All,
I am a bit purplexed w/ the two WARNING messages I keep getting in my 
"system" logs ....


Mar 18 19:30:34 	racoon: INFO: pfkey.c:1420:pk_recvadd(): IPsec-SA 
established: ESP/Tunnel X.X.X.X->X.X.X.X spi=152344527(0x93e864569)
Mar 18 19:30:34 	racoon: INFO: pfkey.c:1197:pk_recvupdate(): IPsec-SA 
established: ESP/Tunnel x.x.x.x->x.x.x.x spi=602473511(0x5caDCA)
Mar 18 19:30:34 	racoon: INFO: isakmp.c:1059:isakmp_ph2begin_r(): 
respond new phase 2 negotiation: x.x.x.x[0]<=>x.x.x.x[0]
Mar 18 19:30:34 	racoon: INFO: isakmp.c:2459:log_ph1established(): 
ISAKMP-SA established x.x.x.x[500]-x.x.x.x[500] spi:Smhfrt8seker5b9:4445I
Mar 18 19:30:33 	racoon: NOTIFY: oakley.c:2084:oakley_skeyid(): couldn't 
find the proper pskey, try to get one by the peer's address.
Mar 18 19:30:33 	racoon: WARNING: ipsec_doi.c:3079:ipsecdoi_checkid1(): 
ID value mismatched.
Mar 18 19:30:33 	racoon: WARNING: ipsec_doi.c:3064:ipsecdoi_checkid1(): 
ID type mismatched.
Mar 18 19:30:33 	racoon: INFO: isakmp.c:909:isakmp_ph1begin_r(): begin 
Aggressive mode.
Mar 18 19:30:33 	racoon: INFO: isakmp.c:904:isakmp_ph1begin_r(): respond 
new phase 1 negotiation: x.x.x.x[500]<=>[500]
Mar 18 19:30:32 	racoon: INFO: pfkey.c:1466:pk_recvexpire(): IPsec-SA 
expired: ESP/Tunnel x.x.x.x->x.x.x.x spi=1174476416(0x7005612)
Mar 18 19:30:32 	racoon: INFO: pfkey.c:1466:pk_recvexpire(): IPsec-SA 
expired: ESP/Tunnel x.x.x.x->x.x.x.x spi=2134984321(0xca19a6d)


I have scoured the NET to find an answer but come up w/ very little on 
these warnings.  There are some general discussions about the setup of a 
"pre-shared key" to address this warning ...... Do I need a PSK ????

BTW: The tunnel comes up great and as far as the branch office .. it is 
running A++ ... I have had no issues with the tunnel AT ALL!

1. Any direction as to what is causing this error?
2. If I set up a pre-shared key and take care of this warning?