[vpn-help] Header verification failed

Kevin VPN kvpn at live.com
Tue Apr 16 21:54:47 CDT 2013


On 04/13/2013 03:25 PM, Tiago Vasconcelos wrote:
>
> On 21-03-2013 02:11, Kevin VPN wrote:
>  > My guess would be that the Shrew client configuration settings are not
>  > correct for your strongSwan gateway.
>
> Here's the VPN Trace for the connection. My guess is that the right side
> is using IKEv2 while Shrew only supports IKEv1.
>
> 13/04/13 20:15:28 ## : IKE Daemon, ver 2.2.0

<snip>

> 13/04/13 20:16:14 -> : send IKE packet 192.168.0.100:500 ->
> 63.254.211.50:500 ( 460 bytes )
> 13/04/13 20:16:14 DB : phase1 resend event scheduled ( ref count = 2 )
> 13/04/13 20:16:19 -> : resend 1 phase1 packet(s) [0/2] 192.168.0.100:500
> -> 63.254.211.50:500
> 13/04/13 20:16:24 -> : resend 1 phase1 packet(s) [1/2] 192.168.0.100:500
> -> 63.254.211.50:500
> 13/04/13 20:16:29 -> : resend 1 phase1 packet(s) [2/2] 192.168.0.100:500
> -> 63.254.211.50:500
> 13/04/13 20:16:34 ii : resend limit exceeded for phase1 exchange

<snip>

>

Hi Tiago,

This is where it is going wrong - you're sending packets to the gateway, 
but it is not responding.  You will need to look at the strongSwan logs 
to see what it says about the connection attempts.  Most gateways simple 
drop connection requests that they do not like (in other words, that do 
not match their settings).

It could be as you say, an IKE version mismatch.



More information about the vpn-help mailing list