On one of my ipsec vpn I regularly receive messages like the following
16:03:26.685282 remotehost.500 > localhost.500: [udp sum ok] isakmp v1.0
exchange INFO
cookie: ddae40befdf8a5d6->d38ee14e8992fba1 msgid: f2da6538 len: 76
payload: HASH len: 24
payload: DELETE len: 16 DOI: 1(IPSEC) proto: IPSEC_ESP nspis: 1
SPI: 0x3fcc2416 [ttl 0] (id 1, len 104)
16:03:26.697136 remotehost.500 > locahost.500: [udp sum ok] isakmp v1.0
exchange INFO
cookie: ddae40befdf8a5d6->d38ee14e8992fba1 msgid: c0312a10 len: 76
payload: HASH len: 24
payload: DELETE len: 16 DOI: 1(IPSEC) proto: IPSEC_ESP nspis: 1
SPI: 0x7c6b161d [ttl 0] (id 1, len 104)
16:03:26.703921 remotehost.500 > localhost.500: [udp sum ok] isakmp v1.0
exchange INFO
cookie: ddae40befdf8a5d6->d38ee14e8992fba1 msgid: 78727922 len: 92
payload: HASH len: 24
payload: DELETE len: 28 DOI: 1(IPSEC) proto: ISAKMP nspis: 1
cookie: ddae40befdf8a5d6->d38ee14e8992fba1 [ttl 0] (id 1, len
120)
In most cases isakmpd reinitiates an id_prot exchange and the vpn is again
established. But sometimes it does not try.
What do these messages do, why are they sent? Is it a normal behaviour or is
the remote site trying to end the vpn. ( remote is a lancom ?? ).
Why is it that isakmpd sometimes tries to reestablish and sometimes it does
not?
Thanks for any hints
Mit freundlichen Gr|_en
Christoph Leser
S&P Computersysteme GmbH
Systemhaus f|r Logistik
Tel: 0711 726410
Mail: [EMAIL PROTECTED]
Amtsgericht Stuttgart HRB 11921
Geschdftsf|hrer J|rgen Probst, Horst Reichert