IPSec SA connect gone crazy
Hi all,
I have a perfectly normal IPsec tunnel that normaly works fine.
However, once in a while the connection gets lost and the Fortigate goes crazy.
Debug shows thousands of quickmode requests.
Here is a piece of debug after I flushed the tunnel on CLI:
:56 ike 0:p1-000300:55529767: negotiation timeout, deleting :56 ike 0:p1-000300: connection expiring due to phase1 down :56 ike 0:p1-000300: deleting :56 ike 0:p1-000300: flushing :56 ike 0:p1-000300: flushed :56 ike 0:p1-000300: deleted :56 ike 0:p1-000300:p2-000300: IPsec SA connect 6 62.177.226.236->89.146.20.81:0 :56 ike 0:p1-000300:p2-000300: config found :56 ike 0:p1-000300: created connection: 0x3a2e310 6 62.177.226.236->89.146.20.81:500. :56 ike 0:p1-000300: IPsec SA connect 6 62.177.226.236->89.146.20.81:500 negotiating :56 ike 0:p1-000300: no suitable ISAKMP SA, queuing quick-mode request and initiating ISAKMP SA negotiation :56 ike 0:p1-000300:55529796: initiator: main mode is sending 1st message... :56 ike 0:p1-000300:55529796: cookie 2e968ceaf91b81e6/0000000000000000 :56 ike 0:p1-000300:55529796: out 2E968CEAF91B81E600000000000000000110020000000000000000900D00003800000001000000010000002C010100010000002401010000800B0001800C708080010007800E01008003000180020002800400020D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D3000000148299031757A36082C6A621DE00050E18 :56 ike 0:p1-000300:55529796: sent IKE msg (ident_i1send): 62.177.226.236:500->89.146.20.81:500, len=144, id=2e968ceaf91b81e6/0000000000000000 :56 ike 0:p1-000300:p2-000300.2: IPsec SA connect 6 62.177.226.236->89.146.20.81:0 :56 ike 0:p1-000300:p2-000300.2: using existing connection :56 ike 0:p1-000300:p2-000300.2: config found :56 ike 0:p1-000300:p2-000300.2: IPsec SA connect 6 62.177.226.236->89.146.20.81:500 negotiating :56 ike 0:p1-000300:55529796:p2-000300.2:504855592: ISAKMP SA still negotiating, queuing quick-mode request :56 ike 0:p1-000300:p2-000300: IPsec SA connect 6 62.177.226.236->89.146.20.81:0 :56 ike 0:p1-000300:p2-000300: using existing connection :56 ike 0:p1-000300:p2-000300: config found :56 ike 0:p1-000300: request is on the queue :56 ike 0:p1-000300:p2-000300.2: IPsec SA connect 6 62.177.226.236->89.146.20.81:0 :56 ike 0:p1-000300:p2-000300.2: using existing connection :56 ike 0:p1-000300:p2-000300.2: config found :56 ike 0:p1-000300: request is on the queue :56 ike 0:p1-000300:p2-000300: IPsec SA connect 6 62.177.226.236->89.146.20.81:0 :56 ike 0:p1-000300:p2-000300: using existing connection :56 ike 0:p1-000300:p2-000300: config found :56 ike 0:p1-000300: request is on the queue
The last 4 lines repeat over and over as if it were a logical loop.
Obviously this makes debugging this line difficult.
I suspect however that the other side is simply offline or misconfigured.
Any help would be appreciated.
André