Hallo,
hier der komplette Ausschnitt inkl. der Meldungen, welche es nicht bis ins System Check geschafft hatten:
Code:
Feb 3 16:02:49 intranator pluto[2948]: packet from source.ip.source.ip:500: ignoring Vendor ID payload [da8e937880010000]
Feb 3 16:02:49 intranator pluto[2948]: packet from source.ip.source.ip:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03]
Feb 3 16:02:49 intranator pluto[2948]: packet from source.ip.source.ip:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n]
Feb 3 16:02:49 intranator pluto[2948]: packet from source.ip.source.ip:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]
Feb 3 16:02:49 intranator pluto[2948]: packet from source.ip.source.ip:500: received Vendor ID payload [RFC 3947]
Feb 3 16:02:49 intranator pluto[2948]: packet from source.ip.source.ip:500: received Vendor ID payload [Dead Peer Detection]
Feb 3 16:02:49 intranator pluto[2948]: packet from source.ip.source.ip:500: ignoring Vendor ID payload [NCP Client]
Feb 3 16:02:49 intranator pluto[2948]: packet from source.ip.source.ip:500: ignoring Vendor ID payload [c61baca1f1a60cc10800000000000000]
Feb 3 16:02:49 intranator pluto[2948]: packet from source.ip.source.ip:500: ignoring Vendor ID payload [FRAGMENTATION c0000000]
Feb 3 16:02:49 intranator pluto[2948]: "C8"[2] source.ip.source.ip #4: responding to Main Mode from unknown peer source.ip.source.ip
Feb 3 16:02:50 intranator pluto[2948]: "C8"[2] source.ip.source.ip #4: NAT-Traversal: Result using RFC 3947: peer is NATed
Feb 3 16:03:00 intranator connd[2639]: [connection_manager] online mode set to always online
Feb 3 16:03:00 intranator connd[2639]: [connection_manager] still use P7 as default provider
Feb 3 16:03:00 intranator connd[2639]: [connection_manager] online mode set to always online
Feb 3 16:03:01 intranator lmtpunix[7446]: Delivered: <cmu-lmtpd-7446-1328281381-0@intranator.domain.lan> to mailbox: user.cyrus
Feb 3 16:03:02 intranator pluto[2948]: ERROR: recvfrom on eth1 failed; Pluto cannot decode source sockaddr in rejection: unknown source. Errno 11: Resource temporarily unavailable
Feb 3 16:03:02 intranator pluto[2948]: ERROR: recvfrom on eth1 failed; Pluto cannot decode source sockaddr in rejection: unknown source. Errno 11: Resource temporarily unavailable
Feb 3 16:03:12 intranator pluto[2948]: ERROR: recvfrom on eth1 failed; Pluto cannot decode source sockaddr in rejection: unknown source. Errno 11: Resource temporarily unavailable
Feb 3 16:03:17 intranator pluto[2948]: ERROR: recvfrom on eth1 failed; Pluto cannot decode source sockaddr in rejection: unknown source. Errno 11: Resource temporarily unavailable
Feb 3 16:03:21 intranator pluto[2948]: ERROR: recvfrom on eth1 failed; Pluto cannot decode source sockaddr in rejection: unknown source. Errno 11: Resource temporarily unavailable
Feb 3 16:03:22 intranator sys_check[2920]: Load: 0.01 0.04 0.05 1/201, MemFree: 2325320 kB, Buff/Cache: 999652 kB, Swapped: 0 kB, SwapFree: 2047868 kB, Swap since boot: 0 pages, I/O avg: 6%, highest I/O usage: 21%
Feb 3 16:03:23 intranator pluto[2948]: ERROR: recvfrom on eth1 failed; Pluto cannot decode source sockaddr in rejection: unknown source. Errno 11: Resource temporarily unavailable
Feb 3 16:03:29 intranator pluto[2948]: "C8"[2] source.ip.source.ip #4: byte 2 of ISAKMP Hash Payload must be zero, but is not
Feb 3 16:03:29 intranator pluto[2948]: "C8"[2] source.ip.source.ip #4: malformed payload in packet
Feb 3 16:04:00 intranator connd[2639]: [connection_manager] online mode set to always online
Feb 3 16:04:00 intranator connd[2639]: [connection_manager] still use P7 as default provider
Feb 3 16:04:00 intranator connd[2639]: [connection_manager] online mode set to always online
Feb 3 16:04:00 intranator pluto[2948]: "C8"[2] source.ip.source.ip #4: max number of retransmissions (2) reached STATE_MAIN_R2
Feb 3 16:04:00 intranator pluto[2948]: "C8"[2] source.ip.source.ip: deleting connection "C8" instance with peer source.ip.source.ip {isakmp=#0/ipsec=#0}
Feb 3 16:05:00 intranator connd[2639]: [connection_manager] online mode set to always online
Feb 3 16:05:00 intranator connd[2639]: [connection_manager] still use P7 as default provider
Feb 3 16:05:00 intranator connd[2639]: [connection_manager] online mode set to always online
Zum Vergleich hier noch einmal ein Ausschnitt aus erfolgreichen Tagen...
Code:
Jan 28 05:08:18 intranator pluto[3101]: packet from source.ip.source.ip:500: ignoring Vendor ID payload [da8e937880010000]
Jan 28 05:08:18 intranator pluto[3101]: packet from source.ip.source.ip:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03]
Jan 28 05:08:18 intranator pluto[3101]: packet from source.ip.source.ip:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n]
Jan 28 05:08:18 intranator pluto[3101]: packet from source.ip.source.ip:500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-00]
Jan 28 05:08:18 intranator pluto[3101]: packet from source.ip.source.ip:500: received Vendor ID payload [RFC 3947]
Jan 28 05:08:18 intranator pluto[3101]: packet from source.ip.source.ip:500: received Vendor ID payload [Dead Peer Detection]
Jan 28 05:08:18 intranator pluto[3101]: packet from source.ip.source.ip:500: ignoring Vendor ID payload [NCP Client]
Jan 28 05:08:18 intranator pluto[3101]: packet from source.ip.source.ip:500: ignoring Vendor ID payload [c61baca1f1a60cc10800000000000000]
Jan 28 05:08:18 intranator pluto[3101]: packet from source.ip.source.ip:500: ignoring Vendor ID payload [FRAGMENTATION c0000000]
Jan 28 05:08:18 intranator pluto[3101]: "C8"[5] source.ip.source.ip #10: responding to Main Mode from unknown peer source.ip.source.ip
Jan 28 05:08:18 intranator pluto[3101]: "C8"[5] source.ip.source.ip #10: NAT-Traversal: Result using RFC 3947: peer is NATed
Jan 28 05:08:29 intranator pluto[3101]: "C8"[5] source.ip.source.ip #10: ignoring informational payload, type IPSEC_INITIAL_CONTACT
Jan 28 05:08:29 intranator pluto[3101]: "C8"[5] source.ip.source.ip #10: Peer ID is ID_DER_ASN1_DN: 'DC=local, DC=domain, OU=company, OU=city, OU=Benutzer, CN=Username, E=User-E-Mail'
Jan 28 05:08:29 intranator pluto[3101]: "C8"[5] source.ip.source.ip #10: issuer cacert not found
Jan 28 05:08:29 intranator pluto[3101]: "C8"[5] source.ip.source.ip #10: X.509 certificate rejected
Jan 28 05:08:29 intranator pluto[3101]: "C8"[5] source.ip.source.ip #10: we have a cert and are sending it upon request
Jan 28 05:08:29 intranator pluto[3101]: "C8"[5] source.ip.source.ip:4500 #10: sent MR3, ISAKMP SA established
Jan 28 05:08:29 intranator pluto[3101]: "C8"[4] source.ip.source.ip:4500 #11: responding to Quick Mode
Jan 28 05:08:29 intranator pluto[3101]: "C8"[4] source.ip.source.ip:4500 #11: IPsec SA established {ESP=>0x4b6ef6ea <0xc803a26c NATOA=0.0.0.0}
Liebe Grüße,
Jens Eberhardt