Re: [vpp-dev] ipip0 or ipsec0 is not getting created after executing "ikev2 initiate sa-init pr1"

2022-08-26 Thread Filip Tehlar -X (ftehlar - PANTHEON TECHNOLOGIES at Cisco) via lists.fd.io
Hi Nilesh, looks like you didn't configure esp-integ-alg (it is not a good idea not to use integrity algorithm) . So, either configure esp-integ-alg, or use crypto algorithm that does integrity check too, like "esp-crypto-alg aes-gcm-16 256" Filip From:

[vpp-dev] ipip0 or ipsec0 is not getting created after executing "ikev2 initiate sa-init pr1"

2022-08-26 Thread Nilesh Inamdar
Hi Team, I am trying to bringup IPSec session between 2 VPP. After configuring and executing "ikev2 initiate sa-init pr1", the tunnel ipip0 or ipsec0 is not getting created. I see that Child SA is not getting programmed correctly. Topology: vpp-responder (fpeth0) (192.168.4.1)