Re: [strongSwan] deleting half open IKE_SA after timeout

2015-03-01 Thread Denis Zinevich
Hello Volker, I tried fragmentation=yes before, but in specific connection section, not in %default, and it didn't make any effect. Now in %default section it solved my problem. Now I have enough evidence and knowledge to troubleshoot network together with hoster tech support. Thanks a lot !

Re: [strongSwan] deleting half open IKE_SA after timeout

2015-03-01 Thread Volker RĂ¼melin
Hi Denis, Hello, my previous suggestion was wrong. I've compared tcpdumps on working and non-working hosts again, and found that in broken case client continues to re-send this packed to server: 19:53:09.673551 IP (tos 0x0, ttl 57, id 0, offset 0, flags [DF], proto UDP (17), length 1212)

Re: [strongSwan] deleting half open IKE_SA after timeout

2015-02-28 Thread Denis Zinevich
Hello, my previous suggestion was wrong. I've compared tcpdumps on working and non-working hosts again, and found that in broken case client continues to re-send this packed to server: 19:53:09.673551 IP (tos 0x0, ttl 57, id 0, offset 0, flags [DF], proto UDP (17), length 1212)

Re: [strongSwan] deleting half open IKE_SA after timeout

2015-02-27 Thread Martin Willi
Hi Denis 07[ENC] generating ID_PROT response 0 [ ID CERT SIG ] 07[NET] sending packet: from 179.179.179.179[4500] to 46.211.133.122[39592] (1660 bytes) 07[ENC] generating TRANSACTION request 2234314252 [ HASH CPRQ(X_USER X_PWD) ] 07[NET] sending packet: from 179.179.179.179[4500] to

Re: [strongSwan] deleting half open IKE_SA after timeout

2015-02-27 Thread Denis Zinevich
Hello Martin, same client connects to other servers successfully, with same credentials. After I change server name - connection fails. and this happend only with one particular server, so according to your explanation either client didn't get XAuth request or server didn't get reply. I've just