Mikrotik IPSec Tunnels not working after RouterOS upgradeOpenSwan IPSec phase #2 complicationspfSense IPsec VPN setup (Log error: racoon: INFO: unsupported PF_KEY message REGISTER)Pfsense 2.02 unstable ipsec vpn.Tunnels will come up upon restarting racconSonicOS Enhanced 5.8.1.2 L2TP VPN Authentication FailedHow can I connect to a Cisco ASA5540 from Windows Server 2012 over IPSEC?Windows 10 built in VPNSite to Site IPSec between pfSense and Cisco ASAConfiguring L2TP/IPSec on Cisco Router 2911L2TP over IPsec VPN between ZyWALL USG 100 and iPhone NO_PROPOSAL_CHOSENHow to configure strongswan peer-to-peer vpn tunnel using public IP as encryption domain?

Why is unzipped directory exactly 4.0K (much smaller than zipped file)?

What could be my risk mitigation strategies if my client wants to contract UAT?

Paired t-test means that the variances of the 2 samples are the same?

Why is the Eisenstein ideal paper so great?

Could a rotating ring space station have a bolo-like extension?

Why does the painters tape have to be blue?

Merge pdfs sequentially

Is it safe to redirect stdout and stderr to the same file without file descriptor copies?

What is Orcus doing with Mind Flayers in the art on the last page of Volo's Guide to Monsters?

Ribbon Cable Cross Talk - Is there a fix after the fact?

EU rights when flight delayed so much that return is missed

Have any humans orbited the Earth in anything other than a prograde orbit?

Split into three!

ifconfig shows UP while ip link shows DOWN

Is superuser the same as root?

Testing using real data of the customer

What is the limit to a Glyph of Warding's trigger?

Piping the output of comand columns

Why was this character made Grand Maester?

How did the Allies achieve air superiority on Sicily?

Are cells guaranteed to get at least one mitochondrion when they divide?

How to teach an undergraduate course without having taken that course formally before?

Can attacking players use activated abilities after blockers have been declared?

Toxic, harassing lab environment



Mikrotik IPSec Tunnels not working after RouterOS upgrade


OpenSwan IPSec phase #2 complicationspfSense IPsec VPN setup (Log error: racoon: INFO: unsupported PF_KEY message REGISTER)Pfsense 2.02 unstable ipsec vpn.Tunnels will come up upon restarting racconSonicOS Enhanced 5.8.1.2 L2TP VPN Authentication FailedHow can I connect to a Cisco ASA5540 from Windows Server 2012 over IPSEC?Windows 10 built in VPNSite to Site IPSec between pfSense and Cisco ASAConfiguring L2TP/IPSec on Cisco Router 2911L2TP over IPsec VPN between ZyWALL USG 100 and iPhone NO_PROPOSAL_CHOSENHow to configure strongswan peer-to-peer vpn tunnel using public IP as encryption domain?






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








0















We upgraded our RB1100AH2x yesterday from 6.19 to 6.22 and lost our L2TP / IPSec tunnels in the process. The logs are now littered with IPSec errors stating



failed to pre-process ph2 packet.


In the change log for 6.21 I notice that you can no longer employ a blank value for the Policy Group in the Peer policy. We had originally configured our tunnel this way and I suspect that this is the cause of the errors.



Can anyone point me in the right direction on how to resolve this issue?



See relevant config below (note that the first entry in the ipsec peer is note relevant - entry "1" is the one I am most concerned about



/ip ipsec peer> print
Flags: X - disabled, D - dynamic
0 X address=xx.xx.xx.xx/32 local-address=0.0.0.0 passive=no
port=500 auth-method=pre-shared-key secret="redacted"
generate-policy=no policy-template-group=*FFFFFFFF
exchange-mode=main send-initial-contact=yes
nat-traversal=no proposal-check=obey hash-algorithm=md5
enc-algorithm=3des dh-group=modp1024 lifetime=1d
lifebytes=0 dpd-interval=disable-dpd dpd-maximum-failures=1

1 D address=0.0.0.0/0 local-address=0.0.0.0 passive=yes port=500
auth-method=pre-shared-key secret="redacted"
generate-policy=port-strict policy-template-group=default
exchange-mode=main-l2tp send-initial-contact=yes
nat-traversal=yes hash-algorithm=sha1
enc-algorithm=3des,aes-128,aes-192,aes-256
dh-group=modp1024 lifetime=1d dpd-interval=2m
dpd-maximum-failures=5


/ip ipsec proposal> print
Flags: X - disabled, * - default
0 * name="default" auth-algorithms=sha1
enc-algorithms=3des,aes-256-cbc lifetime=30m
pfs-group=modp1024









share|improve this question




























    0















    We upgraded our RB1100AH2x yesterday from 6.19 to 6.22 and lost our L2TP / IPSec tunnels in the process. The logs are now littered with IPSec errors stating



    failed to pre-process ph2 packet.


    In the change log for 6.21 I notice that you can no longer employ a blank value for the Policy Group in the Peer policy. We had originally configured our tunnel this way and I suspect that this is the cause of the errors.



    Can anyone point me in the right direction on how to resolve this issue?



    See relevant config below (note that the first entry in the ipsec peer is note relevant - entry "1" is the one I am most concerned about



    /ip ipsec peer> print
    Flags: X - disabled, D - dynamic
    0 X address=xx.xx.xx.xx/32 local-address=0.0.0.0 passive=no
    port=500 auth-method=pre-shared-key secret="redacted"
    generate-policy=no policy-template-group=*FFFFFFFF
    exchange-mode=main send-initial-contact=yes
    nat-traversal=no proposal-check=obey hash-algorithm=md5
    enc-algorithm=3des dh-group=modp1024 lifetime=1d
    lifebytes=0 dpd-interval=disable-dpd dpd-maximum-failures=1

    1 D address=0.0.0.0/0 local-address=0.0.0.0 passive=yes port=500
    auth-method=pre-shared-key secret="redacted"
    generate-policy=port-strict policy-template-group=default
    exchange-mode=main-l2tp send-initial-contact=yes
    nat-traversal=yes hash-algorithm=sha1
    enc-algorithm=3des,aes-128,aes-192,aes-256
    dh-group=modp1024 lifetime=1d dpd-interval=2m
    dpd-maximum-failures=5


    /ip ipsec proposal> print
    Flags: X - disabled, * - default
    0 * name="default" auth-algorithms=sha1
    enc-algorithms=3des,aes-256-cbc lifetime=30m
    pfs-group=modp1024









    share|improve this question
























      0












      0








      0








      We upgraded our RB1100AH2x yesterday from 6.19 to 6.22 and lost our L2TP / IPSec tunnels in the process. The logs are now littered with IPSec errors stating



      failed to pre-process ph2 packet.


      In the change log for 6.21 I notice that you can no longer employ a blank value for the Policy Group in the Peer policy. We had originally configured our tunnel this way and I suspect that this is the cause of the errors.



      Can anyone point me in the right direction on how to resolve this issue?



      See relevant config below (note that the first entry in the ipsec peer is note relevant - entry "1" is the one I am most concerned about



      /ip ipsec peer> print
      Flags: X - disabled, D - dynamic
      0 X address=xx.xx.xx.xx/32 local-address=0.0.0.0 passive=no
      port=500 auth-method=pre-shared-key secret="redacted"
      generate-policy=no policy-template-group=*FFFFFFFF
      exchange-mode=main send-initial-contact=yes
      nat-traversal=no proposal-check=obey hash-algorithm=md5
      enc-algorithm=3des dh-group=modp1024 lifetime=1d
      lifebytes=0 dpd-interval=disable-dpd dpd-maximum-failures=1

      1 D address=0.0.0.0/0 local-address=0.0.0.0 passive=yes port=500
      auth-method=pre-shared-key secret="redacted"
      generate-policy=port-strict policy-template-group=default
      exchange-mode=main-l2tp send-initial-contact=yes
      nat-traversal=yes hash-algorithm=sha1
      enc-algorithm=3des,aes-128,aes-192,aes-256
      dh-group=modp1024 lifetime=1d dpd-interval=2m
      dpd-maximum-failures=5


      /ip ipsec proposal> print
      Flags: X - disabled, * - default
      0 * name="default" auth-algorithms=sha1
      enc-algorithms=3des,aes-256-cbc lifetime=30m
      pfs-group=modp1024









      share|improve this question














      We upgraded our RB1100AH2x yesterday from 6.19 to 6.22 and lost our L2TP / IPSec tunnels in the process. The logs are now littered with IPSec errors stating



      failed to pre-process ph2 packet.


      In the change log for 6.21 I notice that you can no longer employ a blank value for the Policy Group in the Peer policy. We had originally configured our tunnel this way and I suspect that this is the cause of the errors.



      Can anyone point me in the right direction on how to resolve this issue?



      See relevant config below (note that the first entry in the ipsec peer is note relevant - entry "1" is the one I am most concerned about



      /ip ipsec peer> print
      Flags: X - disabled, D - dynamic
      0 X address=xx.xx.xx.xx/32 local-address=0.0.0.0 passive=no
      port=500 auth-method=pre-shared-key secret="redacted"
      generate-policy=no policy-template-group=*FFFFFFFF
      exchange-mode=main send-initial-contact=yes
      nat-traversal=no proposal-check=obey hash-algorithm=md5
      enc-algorithm=3des dh-group=modp1024 lifetime=1d
      lifebytes=0 dpd-interval=disable-dpd dpd-maximum-failures=1

      1 D address=0.0.0.0/0 local-address=0.0.0.0 passive=yes port=500
      auth-method=pre-shared-key secret="redacted"
      generate-policy=port-strict policy-template-group=default
      exchange-mode=main-l2tp send-initial-contact=yes
      nat-traversal=yes hash-algorithm=sha1
      enc-algorithm=3des,aes-128,aes-192,aes-256
      dh-group=modp1024 lifetime=1d dpd-interval=2m
      dpd-maximum-failures=5


      /ip ipsec proposal> print
      Flags: X - disabled, * - default
      0 * name="default" auth-algorithms=sha1
      enc-algorithms=3des,aes-256-cbc lifetime=30m
      pfs-group=modp1024






      ipsec l2tp mikrotik routeros






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Nov 23 '14 at 16:01









      DKNUCKLESDKNUCKLES

      3,42333858




      3,42333858




















          1 Answer
          1






          active

          oldest

          votes


















          0














          You have to delete the group, which is in the IP/ipsec groups.



          Then it will say unknown in the peer tab. After that, it should work.






          share|improve this answer

























            Your Answer








            StackExchange.ready(function()
            var channelOptions =
            tags: "".split(" "),
            id: "2"
            ;
            initTagRenderer("".split(" "), "".split(" "), channelOptions);

            StackExchange.using("externalEditor", function()
            // Have to fire editor after snippets, if snippets enabled
            if (StackExchange.settings.snippets.snippetsEnabled)
            StackExchange.using("snippets", function()
            createEditor();
            );

            else
            createEditor();

            );

            function createEditor()
            StackExchange.prepareEditor(
            heartbeatType: 'answer',
            autoActivateHeartbeat: false,
            convertImagesToLinks: true,
            noModals: true,
            showLowRepImageUploadWarning: true,
            reputationToPostImages: 10,
            bindNavPrevention: true,
            postfix: "",
            imageUploader:
            brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
            contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
            allowUrls: true
            ,
            onDemand: true,
            discardSelector: ".discard-answer"
            ,immediatelyShowMarkdownHelp:true
            );



            );













            draft saved

            draft discarded


















            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f646466%2fmikrotik-ipsec-tunnels-not-working-after-routeros-upgrade%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown

























            1 Answer
            1






            active

            oldest

            votes








            1 Answer
            1






            active

            oldest

            votes









            active

            oldest

            votes






            active

            oldest

            votes









            0














            You have to delete the group, which is in the IP/ipsec groups.



            Then it will say unknown in the peer tab. After that, it should work.






            share|improve this answer





























              0














              You have to delete the group, which is in the IP/ipsec groups.



              Then it will say unknown in the peer tab. After that, it should work.






              share|improve this answer



























                0












                0








                0







                You have to delete the group, which is in the IP/ipsec groups.



                Then it will say unknown in the peer tab. After that, it should work.






                share|improve this answer















                You have to delete the group, which is in the IP/ipsec groups.



                Then it will say unknown in the peer tab. After that, it should work.







                share|improve this answer














                share|improve this answer



                share|improve this answer








                edited May 9 '15 at 8:08









                peterh

                4,41492442




                4,41492442










                answered May 9 '15 at 3:42









                RobRob

                1




                1



























                    draft saved

                    draft discarded
















































                    Thanks for contributing an answer to Server Fault!


                    • Please be sure to answer the question. Provide details and share your research!

                    But avoid


                    • Asking for help, clarification, or responding to other answers.

                    • Making statements based on opinion; back them up with references or personal experience.

                    To learn more, see our tips on writing great answers.




                    draft saved


                    draft discarded














                    StackExchange.ready(
                    function ()
                    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f646466%2fmikrotik-ipsec-tunnels-not-working-after-routeros-upgrade%23new-answer', 'question_page');

                    );

                    Post as a guest















                    Required, but never shown





















































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown

































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown







                    Popular posts from this blog

                    Club Baloncesto Breogán Índice Historia | Pavillón | Nome | O Breogán na cultura popular | Xogadores | Adestradores | Presidentes | Palmarés | Historial | Líderes | Notas | Véxase tamén | Menú de navegacióncbbreogan.galCadroGuía oficial da ACB 2009-10, páxina 201Guía oficial ACB 1992, páxina 183. Editorial DB.É de 6.500 espectadores sentados axeitándose á última normativa"Estudiantes Junior, entre as mellores canteiras"o orixinalHemeroteca El Mundo Deportivo, 16 setembro de 1970, páxina 12Historia do BreogánAlfredo Pérez, o último canoneiroHistoria C.B. BreogánHemeroteca de El Mundo DeportivoJimmy Wright, norteamericano do Breogán deixará Lugo por ameazas de morteResultados de Breogán en 1986-87Resultados de Breogán en 1990-91Ficha de Velimir Perasović en acb.comResultados de Breogán en 1994-95Breogán arrasa al Barça. "El Mundo Deportivo", 27 de setembro de 1999, páxina 58CB Breogán - FC BarcelonaA FEB invita a participar nunha nova Liga EuropeaCharlie Bell na prensa estatalMáximos anotadores 2005Tempada 2005-06 : Tódolos Xogadores da Xornada""Non quero pensar nunha man negra, mais pregúntome que está a pasar""o orixinalRaúl López, orgulloso dos xogadores, presume da boa saúde económica do BreogánJulio González confirma que cesa como presidente del BreogánHomenaxe a Lisardo GómezA tempada do rexurdimento celesteEntrevista a Lisardo GómezEl COB dinamita el Pazo para forzar el quinto (69-73)Cafés Candelas, patrocinador del CB Breogán"Suso Lázare, novo presidente do Breogán"o orixinalCafés Candelas Breogán firma el mayor triunfo de la historiaEl Breogán realizará 17 homenajes por su cincuenta aniversario"O Breogán honra ao seu fundador e primeiro presidente"o orixinalMiguel Giao recibiu a homenaxe do PazoHomenaxe aos primeiros gladiadores celestesO home que nos amosa como ver o Breo co corazónTita Franco será homenaxeada polos #50anosdeBreoJulio Vila recibirá unha homenaxe in memoriam polos #50anosdeBreo"O Breogán homenaxeará aos seus aboados máis veteráns"Pechada ovación a «Capi» Sanmartín e Ricardo «Corazón de González»Homenaxe por décadas de informaciónPaco García volve ao Pazo con motivo do 50 aniversario"Resultados y clasificaciones""O Cafés Candelas Breogán, campión da Copa Princesa""O Cafés Candelas Breogán, equipo ACB"C.B. Breogán"Proxecto social"o orixinal"Centros asociados"o orixinalFicha en imdb.comMario Camus trata la recuperación del amor en 'La vieja música', su última película"Páxina web oficial""Club Baloncesto Breogán""C. B. Breogán S.A.D."eehttp://www.fegaba.com

                    Vilaño, A Laracha Índice Patrimonio | Lugares e parroquias | Véxase tamén | Menú de navegación43°14′52″N 8°36′03″O / 43.24775, -8.60070

                    Cegueira Índice Epidemioloxía | Deficiencia visual | Tipos de cegueira | Principais causas de cegueira | Tratamento | Técnicas de adaptación e axudas | Vida dos cegos | Primeiros auxilios | Crenzas respecto das persoas cegas | Crenzas das persoas cegas | O neno deficiente visual | Aspectos psicolóxicos da cegueira | Notas | Véxase tamén | Menú de navegación54.054.154.436928256blindnessDicionario da Real Academia GalegaPortal das Palabras"International Standards: Visual Standards — Aspects and Ranges of Vision Loss with Emphasis on Population Surveys.""Visual impairment and blindness""Presentan un plan para previr a cegueira"o orixinalACCDV Associació Catalana de Cecs i Disminuïts Visuals - PMFTrachoma"Effect of gene therapy on visual function in Leber's congenital amaurosis"1844137110.1056/NEJMoa0802268Cans guía - os mellores amigos dos cegosArquivadoEscola de cans guía para cegos en Mortágua, PortugalArquivado"Tecnología para ciegos y deficientes visuales. Recopilación de recursos gratuitos en la Red""Colorino""‘COL.diesis’, escuchar los sonidos del color""COL.diesis: Transforming Colour into Melody and Implementing the Result in a Colour Sensor Device"o orixinal"Sistema de desarrollo de sinestesia color-sonido para invidentes utilizando un protocolo de audio""Enseñanza táctil - geometría y color. Juegos didácticos para niños ciegos y videntes""Sistema Constanz"L'ocupació laboral dels cecs a l'Estat espanyol està pràcticament equiparada a la de les persones amb visió, entrevista amb Pedro ZuritaONCE (Organización Nacional de Cegos de España)Prevención da cegueiraDescrición de deficiencias visuais (Disc@pnet)Braillín, un boneco atractivo para calquera neno, con ou sen discapacidade, que permite familiarizarse co sistema de escritura e lectura brailleAxudas Técnicas36838ID00897494007150-90057129528256DOID:1432HP:0000618D001766C10.597.751.941.162C97109C0155020