Hi Nilesh,
looks like you didn't configure esp-integ-alg (it is not a good idea not to use
integrity algorithm) .
So, either configure esp-integ-alg, or use crypto algorithm that does integrity
check too, like "esp-crypto-alg aes-gcm-16 256"
Filip
From:
Hi Team,
I am trying to bringup IPSec session between 2 VPP.
After configuring and executing "ikev2 initiate sa-init pr1", the tunnel
ipip0 or ipsec0 is not getting created.
I see that Child SA is not getting programmed correctly.
Topology:
vpp-responder (fpeth0) (192.168.4.1)