Доброго времени суток, имею счастье настраивать впн впервые. Суть проблемы такова, что при включении выдачи виртуальных ипов strongswan'ом он не может пройти вторую фазу. Если отключить выдачу ипов то обе фазы проходят нормально и идет обращение к xl2tpd. Хоть убей не могу понять почему при согласовании 2ой фазы он использует выданый ип, а согласовывает внешним.
Может кто сталкивался с таким и может намекнуть куда копать?
Логи
Jan 23 20:36:51 16[MGR] <vpn|2> checkin of IKE_SA successful
Jan 23 20:36:51 16[MGR] checkout IKEv1 SA with SPIs f875f64f89fcafee_i ffc013f2db7ffc34_r
Jan 23 20:36:51 16[MGR] IKE_SA vpn[2] successfully checked out
Jan 23 20:36:51 16[IKE] <vpn|2> queueing MODE_CONFIG task
Jan 23 20:36:51 16[IKE] <vpn|2> activating new tasks
Jan 23 20:36:51 16[IKE] <vpn|2> activating MODE_CONFIG task
Jan 23 20:36:51 16[CFG] <vpn|2> assigning new lease to '10.15.18.2zz'
Jan 23 20:36:51 16[IKE] <vpn|2> assigning virtual IP 172.17.0.2 to peer '10.15.18.2zz'
Jan 23 20:36:51 16[ENC] <vpn|2> generating TRANSACTION request 277472174 [ HASH CPS(ADDR) ]
Jan 23 20:36:51 16[NET] <vpn|2> sending packet: from 37.230.209.xx[4500] to 217.76.41.2yy[5516] (76 bytes)
Jan 23 20:36:51 16[IKE] <vpn|2> delaying task initiation, TRANSACTION exchange in progress
Jan 23 20:36:51 16[MGR] <vpn|2> checkin IKE_SA vpn[2]
Jan 23 20:36:51 16[MGR] <vpn|2> checkin of IKE_SA successful
Jan 23 20:36:51 11[MGR] checkout IKEv1 SA by message with SPIs f875f64f89fcafee_i ffc013f2db7ffc34_r
Jan 23 20:36:51 11[MGR] IKE_SA vpn[2] successfully checked out
Jan 23 20:36:51 11[NET] <vpn|2> received packet: from 217.76.41.2yy[5516] to 37.230.209.xx[4500] (220 bytes)
Jan 23 20:36:51 11[ENC] <vpn|2> parsed QUICK_MODE request 1 [ HASH SA No ID ID NAT-OA NAT-OA ]
Jan 23 20:36:51 11[IKE] <vpn|2> changing received traffic selectors 10.15.18.2zz/32[udp/l2tp]=== 37.230.209.хх/32[udp/l2tp] due to NAT
Jan 23 20:36:51 11[CFG] <vpn|2> looking for a child config for 37.230.209.xx/32[udp/l2tp] === 217.76.41.2уу/32[udp/l2tp]
Jan 23 20:36:51 11[CFG] <vpn|2> proposing traffic selectors for us:
Jan 23 20:36:51 11[CFG] <vpn|2> 37.230.209.хх/32[udp/l2tp]
Jan 23 20:36:51 11[CFG] <vpn|2> proposing traffic selectors for other:
Jan 23 20:36:51 11[CFG] <vpn|2> 172.17.0.2/32[udp/l2tp]
Jan 23 20:36:51 11[IKE] <vpn|2> no matching CHILD_SA config found for 217.76.41.2yy/32[udp/l2tp] === 37.230.209.xx/32[udp/l2tp]
Jan 23 20:36:51 11[IKE] <vpn|2> queueing INFORMATIONAL task
Jan 23 20:36:51 11[IKE] <vpn|2> delaying task initiation, TRANSACTION exchange in progress
Jan 23 20:36:51 11[MGR] <vpn|2> checkin IKE_SA vpn[2]
Jan 23 20:36:51 11[MGR] <vpn|2> checkin of IKE_SA successful
Jan 23 20:36:52 09[MGR] checkout IKEv1 SA by message with SPIs f875f64f89fcafee_i ffc013f2db7ffc34_r
Jan 23 20:36:52 09[MGR] IKE_SA vpn[2] successfully checked out
Jan 23 20:36:52 09[NET] <vpn|2> received packet: from 217.76.41.2yy[5516] to 37.230.209.хх[4500] (220 bytes)
Jan 23 20:36:52 09[IKE] <vpn|2> received retransmit of request with ID 1, but no response to retransmit
Jan 23 20:36:52 09[MGR] <vpn|2> checkin IKE_SA vpn[2]
Jan 23 20:36:52 09[MGR] <vpn|2> checkin of IKE_SA successful
Jan 23 20:36:53 08[MGR] checkout IKEv1 SA by message with SPIs f875f64f89fcafee_i ffc013f2db7ffc34_r
Jan 23 20:36:53 08[MGR] IKE_SA vpn[2] successfully checked out
Jan 23 20:36:53 08[NET] <vpn|2> received packet: from 217.76.41.2yy[5516] to 37.230.209.хх[4500] (220 bytes)
Jan 23 20:36:53 08[IKE] <vpn|2> received retransmit of request with ID 1, but no response to retransmit
Jan 23 20:36:53 08[MGR] <vpn|2> checkin IKE_SA vpn[2]
Jan 23 20:36:53 08[MGR] <vpn|2> checkin of IKE_SA successful
Jan 23 20:36:53 06[MGR] checkout IKEv1 SA by message with SPIs f875f64f89fcafee_i ffc013f2db7ffc34_r
Jan 23 20:36:53 06[MGR] IKE_SA vpn[2] successfully checked out
Jan 23 20:36:53 06[NET] <vpn|2> received packet: from 217.76.41.2yy[5516] to 37.230.209.xx[4500] (92 bytes)
Jan 23 20:36:53 06[ENC] <vpn|2> parsed INFORMATIONAL_V1 request 2526817518 [ HASH D ]
Jan 23 20:36:53 06[IKE] <vpn|2> received DELETE for IKE_SA vpn[2]
Jan 23 20:36:53 06[IKE] <vpn|2> deleting IKE_SA vpn[2] between 37.230.209.xx[37.230.209.xx]...217.76.41.2yy[10.15.18.2zz]
Jan 23 20:36:53 06[IKE] <vpn|2> IKE_SA vpn[2] state change: ESTABLISHED => DELETING
Jan 23 20:36:53 06[IKE] <vpn|2> IKE_SA vpn[2] state change: DELETING => DELETING
и настройки swanctl
connections {
vpn {
version = 0
proposals = aes256-sha1-modp2048,aes256-sha256-modp2048,aes256-sha256-ecp384,aes256-aes128-sha256-sha1-modp3072-modp2048-modp1024
rekey_time = 0s
dpd_delay = 30s
dpd_timeout = 90s
local_addrs = 37.230.209.хх
local_port = 500
mobike = no
pools = 123
pull = no
fragmentation = yes
local {
auth = psk
}
remote {
auth = psk
}
children {
net-net {
mode = transport
local_ts = dynamic[udp/l2tp]
remote_ts = dynamic[udp/l2tp]
rekey_time = 0s
updown = /etc/nat_updown
dpd_action = clear
start_action = start
esp_proposals = aes128-sha256-modp3072,default
}
}
}
}
pools {
123 {
addrs = 172.17.0.2-172.17.0.10
}
}
secrets {
ike {
secret = мойключ
}
}