Question
strongSwan on linux as IPSec VPN client
Hello.
I'm trying to connect to IPSec VPN on fortigate using strongSwan on linux OS.
My configuration on fortigate:
config vpn ipsec phase1-interface
edit "MAC"
set type dynamic
set interface "wan1"
set peertype any
set mode-cfg enable
set proposal aes256-md5 aes256-sha1
set dpd on-idle
set dhgrp 2
set wizard-type dialup-cisco
set xauthtype auto
set authusrgrp "VPN"
set net-device enable
set ipv4-start-ip 10.10.0.2
set ipv4-end-ip 10.10.0.254
set dns-mode auto
set psksecret ENC secure_enc_string
set dpd-retryinterval 5
next
config vpn ipsec phase2-interface
edit "MAC"
set phase1name "MAC"
set proposal aes256-md5 aes256-sha1
set pfs disable
set keepalive enable
set comments "VPN: MAC (Created by VPN wizard)"
next
edit "osx"
set phase1name "osx"
set proposal aes128-sha1 aes256-sha1 3des-sha1 aes128-sha256 aes256-sha256 3des-sha256
set comments "VPN: osx (Created by VPN wizard)"
next
My strongSwan config on linux:
/etc/ipsec.conf
config setup
# strictcrlpolicy=yes
# uniqueids = no
charondebug="dmn 2, mgr 2, ike 2, chd 2, job 2, cfg 2, knl 2, net 2, enc2, lib 2"
conn cisco
fragmentation = yes
keyexchange = ikev1
reauth = yes
forceencaps = no
mobike = no
rekey = yes
installpolicy = yes
type = tunnel
dpdaction = restart
dpddelay = 10s
dpdtimeout = 60s
auto = add
left = 10.10.0.100
right = IP_OF_REMOTE_VPN_SERVER
leftid = vpnuser@local
ikelifetime = 14400s
lifetime = 3600s
ike = 3des-sha1-modp1024!
esp = 3des-sha1-modp1024,3des-sha1-modp1024,3des-sha1-modp1024,3des-sha1-modp1024!
leftauth = psk
leftauth2 = xauth
rightauth = psk
rightid = vpnuser@VPNSERVER
aggressive = no
xauth_identity=vpnuser
rightsubnet = 10.10.0.0/16
leftsourceip = %config
/etc/ipsec.secrets
vpnuser : XAUTH "vpnuser_password"
vpnuser@local pgrabowski@VPNSERVER : PSK "psk-preshared-passphrase"
When I try to UP this VPN connection on console I receive:
# ipsec up cisco
initiating Main Mode IKE_SA cisco[1] to IP_OF_REMOTE_VPN_SERVER
generating ID_PROT request 0 [ SA V V V V V ]
sending packet: from 10.10.0.100[500] to IP_OF_REMOTE_VPN_SERVER[500] (176 bytes)
sending retransmit 1 of request message ID 0, seq 1
sending packet: from 10.10.0.100[500] to IP_OF_REMOTE_VPN_SERVER[500] (176 bytes)
sending retransmit 2 of request message ID 0, seq 1
sending packet: from 10.10.0.100[500] to IP_OF_REMOTE_VPN_SERVER[500] (176 bytes)
In logs I see:
Oct 22 12:18:56 myHOST charon: 04[JOB] watched FD 16 ready to read
Oct 22 12:18:56 myHOST charon: 04[JOB] watcher going to poll() 3 fds
Oct 22 12:18:56 myHOST charon: 03[CFG] received stroke: initiate 'cisco'
Oct 22 12:18:56 myHOST charon: 05[MGR] checkout IKE_SA by config
Oct 22 12:18:56 myHOST charon: 04[JOB] watcher got notification, rebuilding
Oct 22 12:18:56 myHOST charon: 04[JOB] watcher going to poll() 4 fds
Oct 22 12:18:56 myHOST charon: 05[MGR] created IKE_SA (unnamed)[2]
Oct 22 12:18:56 myHOST charon: 05[IKE] queueing ISAKMP_VENDOR task
Oct 22 12:18:56 myHOST charon: 05[IKE] queueing ISAKMP_CERT_PRE task
Oct 22 12:18:56 myHOST charon: 05[IKE] queueing MAIN_MODE task
Oct 22 12:18:56 myHOST charon: 05[IKE] queueing ISAKMP_CERT_POST task
Oct 22 12:18:56 myHOST charon: 05[IKE] queueing ISAKMP_NATD task
Oct 22 12:18:56 myHOST charon: 05[IKE] queueing QUICK_MODE task
Oct 22 12:18:56 myHOST charon: 05[IKE] activating new tasks
Oct 22 12:18:56 myHOST charon: 05[IKE] activating ISAKMP_VENDOR task
Oct 22 12:18:56 myHOST charon: 05[IKE] activating ISAKMP_CERT_PRE task
Oct 22 12:18:56 myHOST charon: 05[IKE] activating MAIN_MODE task
Oct 22 12:18:56 myHOST charon: 05[IKE] activating ISAKMP_CERT_POST task
Oct 22 12:18:56 myHOST charon: 05[IKE] activating ISAKMP_NATD task
Oct 22 12:18:56 myHOST charon: 05[IKE] sending XAuth vendor ID
Oct 22 12:18:56 myHOST charon: 05[ENC] added payload of type VENDOR_ID_V1 to message
Oct 22 12:18:56 myHOST charon: 05[IKE] sending DPD vendor ID
Oct 22 12:18:56 myHOST charon: 05[ENC] added payload of type VENDOR_ID_V1 to message
Oct 22 12:18:56 myHOST charon: 05[IKE] sending FRAGMENTATION vendor ID
Oct 22 12:18:56 myHOST charon: 05[ENC] added payload of type VENDOR_ID_V1 to message
Oct 22 12:18:56 myHOST charon: 05[IKE] sending NAT-T (RFC 3947) vendor ID
Oct 22 12:18:56 myHOST charon: 05[ENC] added payload of type VENDOR_ID_V1 to message
Oct 22 12:18:56 myHOST charon: 05[IKE] sending draft-ietf-ipsec-nat-t-ike-02\n vendor ID
Oct 22 12:18:56 myHOST charon: 05[ENC] added payload of type VENDOR_ID_V1 to message
Oct 22 12:18:56 myHOST charon: 05[IKE] initiating Main Mode IKE_SA cisco[2] to IP_OF_REMOTE_VPN_SERVER
Oct 22 12:18:56 myHOST charon: 05[IKE] IKE_SA cisco[2] state change: CREATED => CONNECTING
Oct 22 12:18:56 myHOST charon: 05[CFG] configured proposals: IKE:3DES_CBC/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024
Oct 22 12:18:56 myHOST charon: 05[ENC] added payload of type SECURITY_ASSOCIATION_V1 to message
Oct 22 12:18:56 myHOST charon: 05[ENC] order payloads in message
Oct 22 12:18:56 myHOST charon: 05[ENC] added payload of type SECURITY_ASSOCIATION_V1 to message
Oct 22 12:18:56 myHOST charon: 05[ENC] added payload of type VENDOR_ID_V1 to message
Oct 22 12:18:56 myHOST charon: message repeated 4 times: [ 05[ENC] added payload of type VENDOR_ID_V1 to message]
Oct 22 12:18:56 myHOST charon: 05[ENC] generating ID_PROT request 0 [ SA V V V V V ]
Oct 22 12:18:56 myHOST charon: 05[ENC] not encrypting payloads
Oct 22 12:18:56 myHOST charon: 05[ENC] generating payload of type HEADER
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 0 IKE_SPI
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 1 IKE_SPI
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 2 U_INT_8
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 3 U_INT_4
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 4 U_INT_4
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 5 U_INT_8
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 6 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 7 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 8 FLAG
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 9 FLAG
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 10 FLAG
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 11 FLAG
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 12 FLAG
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 13 FLAG
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 14 U_INT_32
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 15 HEADER_LENGTH
Oct 22 12:18:56 myHOST charon: 05[ENC] generating HEADER payload finished
Oct 22 12:18:56 myHOST charon: 05[ENC] generating payload of type SECURITY_ASSOCIATION_V1
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 0 U_INT_8
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 1 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 2 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 3 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 4 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 5 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 6 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 7 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 8 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 9 PAYLOAD_LENGTH
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 10 U_INT_32
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 11 U_INT_32
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 12 (1259)
Oct 22 12:18:56 myHOST charon: 05[ENC] generating payload of type PROPOSAL_SUBSTRUCTURE_V1
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 0 U_INT_8
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 1 RESERVED_BYTE
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 2 PAYLOAD_LENGTH
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 3 U_INT_8
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 4 U_INT_8
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 5 SPI_SIZE
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 6 U_INT_8
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 7 SPI
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 8 (1261)
Oct 22 12:18:56 myHOST charon: 05[ENC] generating payload of type TRANSFORM_SUBSTRUCTURE_V1
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 0 U_INT_8
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 1 RESERVED_BYTE
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 2 PAYLOAD_LENGTH
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 3 U_INT_8
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 4 U_INT_8
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 5 RESERVED_BYTE
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 6 RESERVED_BYTE
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 7 (1263)
Oct 22 12:18:56 myHOST charon: 05[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 0 ATTRIBUTE_FORMAT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 1 ATTRIBUTE_TYPE
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 3 ATTRIBUTE_VALUE
Oct 22 12:18:56 myHOST charon: 05[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
Oct 22 12:18:56 myHOST charon: 05[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 0 ATTRIBUTE_FORMAT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 1 ATTRIBUTE_TYPE
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 3 ATTRIBUTE_VALUE
Oct 22 12:18:56 myHOST charon: 05[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
Oct 22 12:18:56 myHOST charon: 05[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 0 ATTRIBUTE_FORMAT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 1 ATTRIBUTE_TYPE
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 3 ATTRIBUTE_VALUE
Oct 22 12:18:56 myHOST charon: 05[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
Oct 22 12:18:56 myHOST charon: 05[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 0 ATTRIBUTE_FORMAT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 1 ATTRIBUTE_TYPE
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 3 ATTRIBUTE_VALUE
Oct 22 12:18:56 myHOST charon: 05[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
Oct 22 12:18:56 myHOST charon: 05[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 0 ATTRIBUTE_FORMAT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 1 ATTRIBUTE_TYPE
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 3 ATTRIBUTE_VALUE
Oct 22 12:18:56 myHOST charon: 05[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
Oct 22 12:18:56 myHOST charon: 05[ENC] generating payload of type TRANSFORM_ATTRIBUTE_V1
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 0 ATTRIBUTE_FORMAT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 1 ATTRIBUTE_TYPE
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 2 ATTRIBUTE_LENGTH_OR_VALUE
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 3 ATTRIBUTE_VALUE
Oct 22 12:18:56 myHOST charon: 05[ENC] generating TRANSFORM_ATTRIBUTE_V1 payload finished
Oct 22 12:18:56 myHOST charon: 05[ENC] generating TRANSFORM_SUBSTRUCTURE_V1 payload finished
Oct 22 12:18:56 myHOST charon: 05[ENC] generating PROPOSAL_SUBSTRUCTURE_V1 payload finished
Oct 22 12:18:56 myHOST charon: 05[ENC] generating SECURITY_ASSOCIATION_V1 payload finished
Oct 22 12:18:56 myHOST charon: 05[ENC] generating payload of type VENDOR_ID_V1
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 0 U_INT_8
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 1 FLAG
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 2 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 3 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 4 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 5 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 6 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 7 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 8 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 9 PAYLOAD_LENGTH
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 10 CHUNK_DATA
Oct 22 12:18:56 myHOST charon: 05[ENC] generating VENDOR_ID_V1 payload finished
Oct 22 12:18:56 myHOST charon: 05[ENC] generating payload of type VENDOR_ID_V1
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 0 U_INT_8
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 1 FLAG
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 2 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 3 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 4 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 5 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 6 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 7 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 8 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 9 PAYLOAD_LENGTH
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 10 CHUNK_DATA
Oct 22 12:18:56 myHOST charon: 05[ENC] generating VENDOR_ID_V1 payload finished
Oct 22 12:18:56 myHOST charon: 05[ENC] generating payload of type VENDOR_ID_V1
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 0 U_INT_8
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 1 FLAG
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 2 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 3 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 4 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 5 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 6 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 7 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 8 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 9 PAYLOAD_LENGTH
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 10 CHUNK_DATA
Oct 22 12:18:56 myHOST charon: 05[ENC] generating VENDOR_ID_V1 payload finished
Oct 22 12:18:56 myHOST charon: 05[ENC] generating payload of type VENDOR_ID_V1
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 0 U_INT_8
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 1 FLAG
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 2 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 3 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 4 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 5 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 6 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 7 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 8 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 9 PAYLOAD_LENGTH
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 10 CHUNK_DATA
Oct 22 12:18:56 myHOST charon: 05[ENC] generating VENDOR_ID_V1 payload finished
Oct 22 12:18:56 myHOST charon: 05[ENC] generating payload of type VENDOR_ID_V1
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 0 U_INT_8
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 1 FLAG
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 2 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 3 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 4 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 5 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 6 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 7 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 8 RESERVED_BIT
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 9 PAYLOAD_LENGTH
Oct 22 12:18:56 myHOST charon: 05[ENC] generating rule 10 CHUNK_DATA
Oct 22 12:18:56 myHOST charon: 05[ENC] generating VENDOR_ID_V1 payload finished
Oct 22 12:18:56 myHOST charon: 05[NET] sending packet: from 10.10.0.100[500] to IP_OF_REMOTE_VPN_SERVER[500] (176 bytes)
Oct 22 12:18:56 myHOST charon: 05[MGR] checkin IKE_SA cisco[2]
Oct 22 12:18:56 myHOST charon: 01[JOB] next event in 3s 999ms, waiting
Oct 22 12:18:56 myHOST charon: 05[MGR] checkin of IKE_SA successful
Oct 22 12:18:56 myHOST charon: 06[NET] sending packet: from 10.10.0.100[500] to IP_OF_REMOTE_VPN_SERVER[500]
Oct 22 12:19:00 myHOST charon: 01[JOB] got event, queuing job for execution
Oct 22 12:19:00 myHOST charon: 01[JOB] no events, waiting
Oct 22 12:19:00 myHOST charon: 12[MGR] checkout IKEv1 SA with SPIs 323c3aef2f033c01_i 0000000000000000_r
Oct 22 12:19:00 myHOST charon: 12[MGR] IKE_SA cisco[2] successfully checked out
Oct 22 12:19:00 myHOST charon: 12[IKE] sending retransmit 1 of request message ID 0, seq 1
Oct 22 12:19:00 myHOST charon: 12[NET] sending packet: from 10.10.0.100[500] to IP_OF_REMOTE_VPN_SERVER[500] (176 bytes)
Oct 22 12:19:00 myHOST charon: 12[MGR] checkin IKE_SA cisco[2]
Oct 22 12:19:00 myHOST charon: 12[MGR] checkin of IKE_SA successful
Oct 22 12:19:00 myHOST charon: 01[JOB] next event in 7s 199ms, waiting
Oct 22 12:19:00 myHOST charon: 06[NET] sending packet: from 10.10.0.100[500] to IP_OF_REMOTE_VPN_SERVER[500]
Oct 22 12:19:08 myHOST charon: 01[JOB] got event, queuing job for execution
Oct 22 12:19:08 myHOST charon: 01[JOB] no events, waiting
Oct 22 12:19:08 myHOST charon: 13[MGR] checkout IKEv1 SA with SPIs 323c3aef2f033c01_i 0000000000000000_r
Oct 22 12:19:08 myHOST charon: 13[MGR] IKE_SA cisco[2] successfully checked out
Oct 22 12:19:08 myHOST charon: 13[IKE] sending retransmit 2 of request message ID 0, seq 1
Oct 22 12:19:08 myHOST charon: 13[NET] sending packet: from 10.10.0.100[500] to IP_OF_REMOTE_VPN_SERVER[500] (176 bytes)
Oct 22 12:19:08 myHOST charon: 13[MGR] checkin IKE_SA cisco[2]
Oct 22 12:19:08 myHOST charon: 13[MGR] checkin of IKE_SA successful
Oct 22 12:19:08 myHOST charon: 06[NET] sending packet: from 10.10.0.100[500] to IP_OF_REMOTE_VPN_SERVER[500]
Oct 22 12:19:08 myHOST charon: 01[JOB] next event in 12s 959ms, waiting
The question is: What I have wrong in this setup that connection can't be established?
Thanks for your help!
