LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 09-15-2017, 06:06 PM   #1
vwtech
Member
 
Registered: Dec 2007
Distribution: Fedora, Oracle Linux & Centos
Posts: 197

Rep: Reputation: 26
Fedora 26 - L2tp stopped working


About 10 days ago my L2tp VPN was working without issue.
Now I just get - "Connection fail" notification from Gnome.

Results from #sudo ipsec verify
PHP Code:
Verifying installed system and configuration files

Version check 
and ipsec on-path                       [OK]
Libreswan 3.21 (netkeyon 4.12.12-300.fc26.x86_64
Checking 
for IPsec support in kernel                  [OK]
 
NETKEYTesting XFRM related proc values
         ICMP 
default/send_redirects                  [OK]
         
ICMP default/accept_redirects                [OK]
         
XFRM larval drop                             [OK]
Pluto ipsec.conf syntax                               [OK]
Two or more interfaces foundchecking IP forwarding    [OK]
Checking rp_filter                                    [OK]
Checking that pluto is running                        [OK]
 
Pluto listening for IKE on udp 500                   [OK]
 
Pluto listening for IKE/NAT-T on udp 4500            [OK]
 
Pluto ipsec.secret syntax                            [OK]
Checking 'ip' command                                 [OK]
Checking 'iptables' command                           [OK]
Checking 'prelink' command does not interfere with FIPS    [OK]
Checking for obsolete ipsec.conf options              [OK
Only thing worth noting in /var/log/pluto.log
PHP Code:
Sep 15 01:44:12: | ISAKMP Notification Payload
Sep 15 01
:44:12: |   00 00 00 1c  00 00 00 01  01 10 00 0e
Sep 15 01
:44:12"0b1d16dd-599f-4e3c-a322-258733d8e5e8" #11: received and ignored informational message
Sep 15 01:44:43"0b1d16dd-599f-4e3c-a322-258733d8e5e8" #11: max number of retransmissions (8) reached STATE_MAIN_I1.  No response (or no acceptable response) to our first IKEv1 message
Sep 15 01:44:43"0b1d16dd-599f-4e3c-a322-258733d8e5e8" #11: starting keying attempt 12 of an unlimited number
Sep 15 01:44:43"0b1d16dd-599f-4e3c-a322-258733d8e5e8" #12: initiating Main Mode to replace #11
Sep 15 01:44:43"0b1d16dd-599f-4e3c-a322-258733d8e5e8" #11: deleting state (STATE_MAIN_I1)
Sep 15 01:44:44"0b1d16dd-599f-4e3c-a322-258733d8e5e8" #12: ignoring informational payload NO_PROPOSAL_CHOSEN, msgid=00000000, length=28 

Any help would be appreciated.
 
Old 09-16-2017, 09:58 AM   #2
John VV
LQ Muse
 
Registered: Aug 2005
Location: A2 area Mi.
Posts: 17,624

Rep: Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651
this is fedora so there ARE bugs

find a fix and submit a bugreport

this IS LIFE with fedora , bugs do get into the release updates

it is possible that some update messed things up

have you reinstalled "NetworkManager-l2tp" ?

and WHAT repos are installed ?
please post the output of
Code:
su -
dnf repolist all
 
Old 09-16-2017, 05:43 PM   #3
vwtech
Member
 
Registered: Dec 2007
Distribution: Fedora, Oracle Linux & Centos
Posts: 197

Original Poster
Rep: Reputation: 26
I have using Fedora for some years now and somehow I didn't upgrade my test system and test VPN before updating my main laptop.
Fedora 26 is my daily for all my work. I've had VPN stop on me in Fedora 26 and if was a bug in a package with I was able to downgrade and continue about my marry way.
This is more than likely the same type of issue.

Running kernel: 4.12.12-300.fc26.x86_64
I did reinstall the NetworkManager-l2tp before posting.

These are the repo's I have installed:
PHP Code:
repo id                     repo name                                     status
*fedora                     Fedora 26 x86_64                            53,912
fedora
-cisco-openh264       Fedora 26 openh264 (From Cisco) - x86_64           7
google
-chrome               google-chrome                                      3
*rpmfusion-free             RPM Fusion for Fedora 26 Free                  536
*rpmfusion-free-updates     RPM Fusion for Fedora 26 Free Updates        102
*rpmfusion-nonfree          RPM Fusion for Fedora 26 Nonfree               202
*rpmfusion-nonfree-updates  RPM Fusion for Fedora 26 Nonfree Updates      12
skype
-stable                skype (stable)                                     2
*updates                    Fedora 26 x86_64 Updates                   8,060
virtualbox                  Fedora 26 
x86_64 VirtualBox                   10 
These are current packages related to NetworkManager:
PHP Code:
NetworkManager.x86_64                      1:1.8.2-1.fc26              @updates 
NetworkManager
-adsl.x86_64                 1:1.8.2-1.fc26              @updates 
NetworkManager
-bluetooth.x86_64            1:1.8.2-1.fc26              @updates 
NetworkManager
-config-connectivity-fedora.noarch
NetworkManager
-glib.x86_64                 1:1.8.2-1.fc26              @updates 
NetworkManager
-l2tp.x86_64                 1.2.8-1.fc26                @updates 
NetworkManager
-l2tp-gnome.x86_64           1.2.8-1.fc26                @updates 
NetworkManager
-libnm.x86_64                1:1.8.2-1.fc26              @updates 
NetworkManager
-openconnect.x86_64          1.2.4-4.fc26                @fedora  
NetworkManager
-openvpn.x86_64              1:1.2.10-1.fc26             @fedora  
NetworkManager
-openvpn-gnome.x86_64        1:1.2.10-1.fc26             @fedora  
NetworkManager
-pptp.x86_64                 1:1.2.4-2.fc26              @fedora  
NetworkManager
-pptp-gnome.x86_64           1:1.2.4-2.fc26              @fedora  
NetworkManager
-strongswan.x86_64           1.4.0-3.fc26                @fedora  
NetworkManager
-strongswan-gnome.x86_64     1.4.0-3.fc26                @fedora  
NetworkManager
-team.x86_64                 1:1.8.2-1.fc26              @updates 
NetworkManager
-vpnc.x86_64                 1:1.2.4-2.fc26              @fedora  
NetworkManager
-vpnc-gnome.x86_64           1:1.2.4-2.fc26              @fedora  
NetworkManager
-wifi.x86_64                 1:1.8.2-1.fc26              @updates 
NetworkManager
-wwan.x86_64                 1:1.8.2-1.fc26              @updates 
 
Old 09-18-2017, 08:26 PM   #4
vwtech
Member
 
Registered: Dec 2007
Distribution: Fedora, Oracle Linux & Centos
Posts: 197

Original Poster
Rep: Reputation: 26
Yes; I was able to fix the issue by downgrading libreswan:
libreswan.x86_64 3.21-1.fc26 @updates (Doesn't work - https://bugzilla.redhat.com/show_bug.cgi?id=1486604)
libreswan.x86_64 3.18-1.fc26 @fedora (Stable)

Problem Packages:
Since I've spent a larger amount of time troubleshooting this issue so I'm going to submit my very first bug report to Fedora (after maintenance-see attachment).
I tested too different systems to confirm the issue and "bug", so yes - I'm very happy about getting it working.

The following line was added to /etc/dnf/dnf.conf in order to guard myself against running updates and braking it. I'll test future updates of those for sure.
excludepkgs=libreswan
Attached Thumbnails
Click image for larger version

Name:	Bugreport.png
Views:	61
Size:	30.7 KB
ID:	25903  
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Bluetooth mouse stopped working on Fedora 18 Mountain Dev Linux - Hardware 2 03-05-2013 08:26 PM
[SOLVED] Keyboard(s) suddenly stopped working - Fedora 15 enzym Linux - Hardware 6 08-31-2011 01:23 PM
Fedora 3 mouse stopped working Chris.Aiken Linux - General 2 02-21-2005 03:13 AM
Audio CDs stopped working on Fedora C1!? Skorp Linux - Hardware 0 04-21-2004 07:35 PM
Apache 1.3 (w oracle) stopped working. Fedora Core 1 Bjorkli Linux - Software 2 04-16-2004 10:06 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 05:29 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration