Hello fellows,
I' ve set up a dial-in IPSec VPN from my FG-50B to a remote FG-80C which has a fixed IP. I use aggressive mode with PSK. Both sides use interface mode.
192.168.234.1 | tunnel | (ext. 217.92.xxx.yyy, int: 192.168.10.0/24)
The tunnel comes up OK.
Now when I ping from local FG to remote FG only the very first ping packet will return (with a reasonable return time), all subsequent packets are discarded. This will only happen when the tunnel has not been up before. While the tunnel is up, no packets at all will pass.
I cannot see anything strange while debugging (' diag deb app ike' , ' diag deb flow' ). The return route gets inserted OK as far as I can tell from the flow output. Even setting a static route on the remote FG (so that the dial-in network becomes known) does not help.
It looks like in the moment the route get established the very first packet slips through; while the route exists, nothing else will pass.
Does anybody have a clue what I am missing here?
Ede
Ede Kernel panic: Aiee, killing interrupt handler!