Strongswan Check: Unterschied zwischen den Versionen
Zur Navigation springen
Zur Suche springen
Thomas (Diskussion | Beiträge) |
Thomas (Diskussion | Beiträge) |
||
| Zeile 34: | Zeile 34: | ||
==Verschiedene Phase2 Proposals== | ==Verschiedene Phase2 Proposals== | ||
| − | Es fehlt das selected proposal bei | + | Es fehlt das selected proposal bei ESP |
*tail -f /var/log/strongswan/charon.log | egrep "$CONN.*proposal.*ESP" | *tail -f /var/log/strongswan/charon.log | egrep "$CONN.*proposal.*ESP" | ||
Nov 16 20:29:38 15[CFG] <s2s|4> received proposals: ESP:AES_CBC_256/HMAC_SHA2_256_128/MODP_1024/NO_EXT_SEQ | Nov 16 20:29:38 15[CFG] <s2s|4> received proposals: ESP:AES_CBC_256/HMAC_SHA2_256_128/MODP_1024/NO_EXT_SEQ | ||
Version vom 17. November 2017, 09:20 Uhr
VPN Check
- CONN=s2s
- CHECK="(CHILD_SA|failed|error|could not)"
- PATTERN=${CONN}.*$CHECK
Verbindung erfolgreich
- tail -f /var/log/strongswan/charon.log | egrep "$PATTERN"
Nov 16 11:26:44 15[IKE] <s2s|6> CHILD_SA s2s{3} established with SPIs cbe2c3f8_i c64ca73c_o and TS 10.83.33.0/24 === 10.83.32.0/24
PSK falsch
- tail -f /var/log/strongswan/charon.log | egrep "$PATTERN"
Nov 16 12:11:47 13[ENC] <s2s|102> invalid HASH_V1 payload length, decryption failed? Nov 16 12:11:47 13[ENC] <s2s|102> could not decrypt payloads Nov 16 12:11:47 13[IKE] <s2s|102> message parsing failed Nov 16 12:11:47 13[IKE] <s2s|102> INFORMATIONAL_V1 request with message ID 1439430924 processing failed
PHASE1 oder PHASE2 Proposals
PHASE1 und PHASE2 ok
- tail -f /var/log/strongswan/charon.log | egrep "$CONN.*proposal"
Nov 17 10:12:35 05[CFG] <s2s|2> received proposals: IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_2048 Nov 17 10:12:35 05[CFG] <s2s|2> configured proposals: IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_2048 Nov 17 10:12:35 05[CFG] <s2s|2> selected proposal: IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_2048 ... Nov 17 10:12:35 01[CFG] <s2s|2> received proposals: ESP:AES_CBC_256/HMAC_SHA2_256_128/MODP_2048/NO_EXT_SEQ Nov 17 10:12:35 01[CFG] <s2s|2> configured proposals: ESP:AES_CBC_256/HMAC_SHA2_256_128/MODP_2048/NO_EXT_SEQ Nov 17 10:12:35 01[CFG] <s2s|2> selected proposal: ESP:AES_CBC_256/HMAC_SHA2_256_128/MODP_2048/NO_EXT_SEQ
PHASE1 oder PHASE2 error
- tail -f /var/log/strongswan/charon.log | egrep "$PATTERN"
Nov 16 12:24:57 05[IKE] <s2s|10> received NO_PROPOSAL_CHOSEN error notify
PHASE1 Proposals werden nicht beantwortet
Es fehlt das selected proposal bei IKE
- tail -f /var/log/strongswan/charon.log | egrep "$CONN.*proposal.*IKE"
Nov 16 21:51:19 12[CFG] <s2s|7> configured proposals: IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_2048
Verschiedene Phase2 Proposals
Es fehlt das selected proposal bei ESP
- tail -f /var/log/strongswan/charon.log | egrep "$CONN.*proposal.*ESP"
Nov 16 20:29:38 15[CFG] <s2s|4> received proposals: ESP:AES_CBC_256/HMAC_SHA2_256_128/MODP_1024/NO_EXT_SEQ Nov 16 20:29:38 15[CFG] <s2s|4> configured proposals: ESP:AES_CBC_256/HMAC_SHA2_256_128/MODP_2048/NO_EXT_SEQ
Falsches Netz
- tail -f /var/log/strongswan/charon.log | egrep "$PATTERN"
Nov 16 20:00:41 01[IKE] <s2s|6> received INVALID_ID_INFORMATION error notify
Falsche ID
- tail -f /var/log/strongswan/charon.log | egrep "$PATTERN"
Nov 16 20:12:55 12[IKE] <s2s|2> received AUTHENTICATION_FAILED error notify
Angebotene IKE Lifetime
- tail -f /var/log/strongswan/charon.log | egrep "$CONN.*time"
Nov 16 22:19:51 12[IKE] <s2s|5> maximum IKE_SA lifetime 3375s