LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 10-26-2012, 04:14 AM   #1
ikev2
LQ Newbie
 
Registered: Oct 2012
Posts: 1

Rep: Reputation: Disabled
IKEv2 - Strongswan to Cisco


Hi

I am attempting to setup an IKEv2 SA between Strongswan (Ubuntu 12.04 LTS VM) and a Cisco router (1900 vers 15.1)

I have managed to set up a tunnel between 2 Strongswan VMs back to back.

When I attempt an SA to cisco, it appears to successfully complete the IKE_SA_INIT, but then cisco reports:
"Failed to decrypt an encrypted packet"

If anyone has any ideas as to where it is going wrong that would be great

Strongswan:
conn strongswan-01-cisco
left=30.10.1.130
leftsubnet=10.2.0.0/16
right=30.10.1.51
rightsubnet=10.4.0.0/16
auto=add

Cisco:
aaa new-model
aaa authorization network MYLOCAL local
aaa session-id common
!
crypto pki token default removal timeout 0
crypto pki certificate map CERTMAP 10
subject-name co strongswan
!
crypto ikev2 name-mangler MANGLER
dn organization-unit
!
crypto ikev2 authorization policy STRONGSWAN
pool pool.strongswan
netmask 255.255.0.0
subnet-acl 199
!
crypto ikev2 proposal proposal1
encryption aes-cbc-128
integrity sha256
group 24
!
crypto ikev2 policy STRONGSWAN
proposal proposal1
!
crypto ikev2 profile STRONGSWAN
match certificate CERTMAP
identity local dn
authentication local rsa-sig
authentication remote rsa-sig
aaa authorization group MYLOCAL name-mangler MANGLER
aaa accounting psk password
!
crypto ikev2 cookie-challenge 500
!
crypto logging ikev2
!
crypto dynamic-map STRONGSWAN 100
set ikev2-profile STRONGSWAN
reverse-route
!
crypto map STATIC 20000 ipsec-isakmp dynamic STRONGSWAN
!
interface GigabitEthernet0/0
description $ETH-LAN$$ETH-SW-LAUNCH$$INTF-INFO-GE 0/0$
ip address 30.10.1.51 255.255.255.0
duplex auto
speed auto
crypto map STATIC
 
Old 05-18-2013, 12:52 PM   #2
slyone
LQ Newbie
 
Registered: May 2013
Posts: 1

Rep: Reputation: Disabled
Did you ever resolve this issue? I am getting the same problem, and it is driving me nuts.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
strongswan ikev2 issue in setting up tunnels sriram_ec Linux - Networking 2 06-19-2012 04:09 AM
strongswan ipsec related Niharika.R Linux - Networking 0 06-03-2012 10:52 PM
Strongswan IPSec problems speakerbox Linux - Networking 2 05-05-2012 02:10 AM
strongswan ipsec culin Linux - Networking 4 08-16-2011 11:31 PM
IKEV2 test---pls help me woshizhuzi Linux - Networking 0 09-09-2010 04:22 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 10:09 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration