IPSec server debug logs
I have trouble establishing IKEv2 VPN with with another client. I suspect it could be proposal miss match in Phase 1 or Phase 2. How can I get debug logs? Device is managed by oc200 controller.
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
i don't think there is one. have you compared the phase 1 & 2?
- Copy Link
- Report Inappropriate Content
@Tedd404 comparing both sides is not an option when two devices belong to a different organizations and managed by a different administrators. Debug log is essential so one can pinpoint the problem.
- Copy Link
- Report Inappropriate Content
well, if you don't know what's the phase 1 and 2 parameters on another site, then how do you set it? isn't this counter intuitive? what you saying is that I need a debug log so I can try the parameters of phase 1 and 2?
if you are not certain if the parameters are right, then you should not even use ipsec. what should the debug log tell you? encryption isn't right? but it does not tell you what encryption you should use. there isn't anything useful from the debug log.
you wireshark and debug it on the basis of your config is right. even you have this wireshark captured, what does it help? nothing.
and phase 1 2 are not plaintext.
- Copy Link
- Report Inappropriate Content
@Tedd404 As I've mentioned, the other side is managed by another team and ofcourse parameters are known and negotiated, however you still don't have a way to validate it. Debug log should tell exactly which Phase is failing and why (PSK or encryption or hash is mismatch)- i.e if Phase 1 is sucessful, than one can start troubleshooting Phase 2. Right now IPSec operations is a complete darkness
- Copy Link
- Report Inappropriate Content
then there isn't. the only way to learn about this is to use wireshark and capture this.
- Copy Link
- Report Inappropriate Content
Information
Helpful: 0
Views: 465
Replies: 5
Voters 0
No one has voted for it yet.