On one of my ipsec vpn I regularly receive messages like the following

16:03:26.685282 remotehost.500 > localhost.500: [udp sum ok] isakmp v1.0
exchange INFO
        cookie: ddae40befdf8a5d6->d38ee14e8992fba1 msgid: f2da6538 len: 76
        payload: HASH len: 24
        payload: DELETE len: 16 DOI: 1(IPSEC) proto: IPSEC_ESP nspis: 1
            SPI: 0x3fcc2416 [ttl 0] (id 1, len 104)
16:03:26.697136 remotehost.500 > locahost.500: [udp sum ok] isakmp v1.0
exchange INFO
        cookie: ddae40befdf8a5d6->d38ee14e8992fba1 msgid: c0312a10 len: 76
        payload: HASH len: 24
        payload: DELETE len: 16 DOI: 1(IPSEC) proto: IPSEC_ESP nspis: 1
            SPI: 0x7c6b161d [ttl 0] (id 1, len 104)
16:03:26.703921 remotehost.500 > localhost.500: [udp sum ok] isakmp v1.0
exchange INFO
        cookie: ddae40befdf8a5d6->d38ee14e8992fba1 msgid: 78727922 len: 92
        payload: HASH len: 24
        payload: DELETE len: 28 DOI: 1(IPSEC) proto: ISAKMP nspis: 1
            cookie: ddae40befdf8a5d6->d38ee14e8992fba1 [ttl 0] (id 1, len
120)

In most cases isakmpd reinitiates an id_prot exchange and the vpn is again
established. But sometimes it does not try.

What do these messages do, why are they sent? Is it a normal behaviour or is
the remote site trying to end the vpn. ( remote is a lancom ?? ).

Why is it that isakmpd sometimes tries to reestablish and sometimes it does
not?

Thanks for any hints

Mit freundlichen Gr|_en

Christoph Leser


S&P Computersysteme GmbH
Systemhaus f|r Logistik

Tel: 0711 726410
Mail: [EMAIL PROTECTED]


Amtsgericht Stuttgart HRB 11921
Geschdftsf|hrer J|rgen Probst, Horst Reichert

Reply via email to