Привет, у меня проблемы с настройкой L2TP+IPSec на RouterOS 6.1. Уже пару дней бьюсь над этим. Подскажите, пожалуйста, что не так с моей конфигурацией? Судя по всему, клиент не получает никаких управляющих ответов L2TP от сервера. Вот мои настройки:
`/ip ipsec peer add exchange-mode=main-l2tp generate-policy=port-strict hash-algorithm=sha1 nat-traversal=yes secret=govno send-initial-contact=no`
`/ppp profile add local-address=10.20.36.1 name=L2TP remote-address=l2tp use-encryption=no`
`/ppp secret add name=user password=test profile=L2TP service=l2tp`
`/interface l2tp-server server set authentication=chap default-profile=L2TP enabled=yes`
`/ip firewall filter add chain=input comment=L2TP dst-port=4500 protocol=udp`
`/ip firewall filter add chain=input comment=IPSEC protocol=ipsec-esp`
`/ip firewall filter add chain=input comment=l2tp port=500 protocol=udp`
`/ip firewall filter add chain=input comment=l2tp port=1701 protocol=udp`
Вот что пишет клиент в логах:
`7/23/13 6:49:59.837 PM pppd[3419]: pppd 2.4.2 (Apple version 596.13) started by vitaly, uid 501`
`7/23/13 6:49:59.878 PM pppd[3419]: L2TP connecting to server '81.92.25.1' (81.92.25.1)...`
`7/23/13 6:49:59.881 PM pppd[3419]: IPSec connection started`
`7/23/13 6:49:59.906 PM racoon[3422]: Connecting.`
`7/23/13 6:49:59.906 PM racoon[3422]: IPSec Phase1 started (Initiated by me).`
`7/23/13 6:49:59.909 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Main-Mode message 1).`
`7/23/13 6:49:59.929 PM racoon[3422]: IKE Packet: receive success. (Initiator, Main-Mode message 2).`
`7/23/13 6:49:59.936 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Main-Mode message 3).`
`7/23/13 6:49:59.982 PM racoon[3422]: IKE Packet: receive success. (Initiator, Main-Mode message 4).`
`7/23/13 6:50:00.003 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Main-Mode message 5).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Main-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Main-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Main-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:00.000 PM kernel[0]: L2TP domain init`
`7/23/13 6:50:00.000 PM kernel[0]: L2TP domain init complete`
`7/23/13 6:50:01.022 PM racoon[3422]: IPSec Phase2 started (Initiated by me).`
`7/23/13 6:50:01.023 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 1).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Main-Mode message 2).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 3).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 4).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:01.022 PM racoon[3422]: IPSec Phase2 started (Initiated by me).`
`7/23/13 6:50:01.023 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 1).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 2).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 3).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 4).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:01.022 PM racoon[3422]: IPSec Phase2 started (Initiated by me).`
`7/23/13 6:50:01.023 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 1).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 2).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 3).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 4).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:01.022 PM racoon[3422]: IPSec Phase2 started (Initiated by me).`
`7/23/13 6:50:01.023 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 1).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 2).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 3).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 4).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:01.022 PM racoon[3422]: IPSec Phase2 started (Initiated by me).`
`7/23/13 6:50:01.023 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 1).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 2).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 3).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 4).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:01.022 PM racoon[3422]: IPSec Phase2 started (Initiated by me).`
`7/23/13 6:50:01.023 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 1).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 2).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 3).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 4).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:01.022 PM racoon[3422]: IPSec Phase2 started (Initiated by me).`
`7/23/13 6:50:01.023 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 1).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 2).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 3).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 4).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:01.022 PM racoon[3422]: IPSec Phase2 started (Initiated by me).`
`7/23/13 6:50:01.023 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 2).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 3).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 5).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:01.022 PM racoon[3422]: IPSec Phase2 started (Initiated by me).`
`7/23/13 6:50:01.023 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 2).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 3).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 5).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:01.022 PM racoon[3422]: IPSec Phase2 started (Initiated by me).`
`7/23/13 6:50:01.023 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 2).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 3).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 5).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:01.022 PM racoon[3422]: IPSec Phase2 started (Initiated by me).`
`7/23/13 6:50:01.023 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 2).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 3).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 5).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
It seems you're experiencing an unusual situation where the log messages are repeating in a loop. This indicates a problem in the log output or handling. It's not a failure of the VPN itself, but rather a reporting issue.
Here are a few potential causes and how to troubleshoot them:
**1. Logging Configuration:**
* **Circular Buffer:** Your logging system (e.g., syslog, local system logs) might have a fixed-size buffer. When the buffer is full, it overwrites older entries. This would cause the repeated messages to be the most recent ones. Check the size of your log buffer in your logging configuration.
* **Logging Interval:** If you have configured logging to occur at fixed intervals, a recurring event can trigger multiple log messages within that interval. Examine your logging interval settings.
* **Log Rotation:** Ensure that your log rotation settings are configured correctly. If rotation is not occurring (or is occurring too slowly), the log file will grow, and the circular buffer will be filled.
**2. Software Bug:**
* **Rare, but Possible:** A bug in the VPN software itself could cause it to repeatedly log the same message. This is less likely, but still a possibility. Check for updates to your VPN software and see if others have reported similar issues.
**3. Event Trigger:**
* **Recurring Event:** The VPN might be repeatedly trying to perform an action that's triggering the same log message. For example, a failed authentication attempt that keeps happening. Look into what the VPN is doing to try to determine the cause of the recurring event.
**Troubleshooting Steps:**
1. **Check Your Logging Configuration:** This is the *most likely* cause.
* Determine where your VPN is logging to (e.g., syslog server, local system log).
* Inspect the configuration files for that logging destination. Look for settings like:
* `log_buffer_size` (or similar).
* `log_interval`.
* `log_rotate_interval`.
* `max_log_files` (or similar).
* Adjust these settings to provide more logging space and/or to rotate logs more frequently.
2. **Examine the VPN Configuration:** Review the VPN configuration itself to see if there are any settings that might be causing the VPN to repeatedly attempt the same action.
3. **Temporarily Disable Logging:** If possible, temporarily disable logging and see if the repeating messages stop. This would help confirm that the issue is directly related to the logging system.
4. **Update VPN Software:** Ensure that you are running the latest version of your VPN software. Bug fixes in newer versions might address the problem.
5. **Check VPN Logs Earlier:** If possible, look at logs from an earlier time to see if the repeating messages started after a specific change.
6. **Review System Resources:** Check CPU, memory, and disk usage on the VPN server. High resource utilization can sometimes lead to unexpected behavior.
**In summary, the most probable cause is a logging configuration issue.** By adjusting the size of your log buffer, log rotation settings, or logging interval, you should be able to resolve the repeating messages. If that doesn't work, investigate the VPN configuration and software itself for potential problems.
`/ip ipsec peer add exchange-mode=main-l2tp generate-policy=port-strict hash-algorithm=sha1 nat-traversal=yes secret=govno send-initial-contact=no`
`/ppp profile add local-address=10.20.36.1 name=L2TP remote-address=l2tp use-encryption=no`
`/ppp secret add name=user password=test profile=L2TP service=l2tp`
`/interface l2tp-server server set authentication=chap default-profile=L2TP enabled=yes`
`/ip firewall filter add chain=input comment=L2TP dst-port=4500 protocol=udp`
`/ip firewall filter add chain=input comment=IPSEC protocol=ipsec-esp`
`/ip firewall filter add chain=input comment=l2tp port=500 protocol=udp`
`/ip firewall filter add chain=input comment=l2tp port=1701 protocol=udp`
Вот что пишет клиент в логах:
`7/23/13 6:49:59.837 PM pppd[3419]: pppd 2.4.2 (Apple version 596.13) started by vitaly, uid 501`
`7/23/13 6:49:59.878 PM pppd[3419]: L2TP connecting to server '81.92.25.1' (81.92.25.1)...`
`7/23/13 6:49:59.881 PM pppd[3419]: IPSec connection started`
`7/23/13 6:49:59.906 PM racoon[3422]: Connecting.`
`7/23/13 6:49:59.906 PM racoon[3422]: IPSec Phase1 started (Initiated by me).`
`7/23/13 6:49:59.909 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Main-Mode message 1).`
`7/23/13 6:49:59.929 PM racoon[3422]: IKE Packet: receive success. (Initiator, Main-Mode message 2).`
`7/23/13 6:49:59.936 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Main-Mode message 3).`
`7/23/13 6:49:59.982 PM racoon[3422]: IKE Packet: receive success. (Initiator, Main-Mode message 4).`
`7/23/13 6:50:00.003 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Main-Mode message 5).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Main-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Main-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Main-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:00.000 PM kernel[0]: L2TP domain init`
`7/23/13 6:50:00.000 PM kernel[0]: L2TP domain init complete`
`7/23/13 6:50:01.022 PM racoon[3422]: IPSec Phase2 started (Initiated by me).`
`7/23/13 6:50:01.023 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 1).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Main-Mode message 2).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 3).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 4).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:01.022 PM racoon[3422]: IPSec Phase2 started (Initiated by me).`
`7/23/13 6:50:01.023 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 1).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 2).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 3).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 4).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:01.022 PM racoon[3422]: IPSec Phase2 started (Initiated by me).`
`7/23/13 6:50:01.023 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 1).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 2).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 3).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 4).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:01.022 PM racoon[3422]: IPSec Phase2 started (Initiated by me).`
`7/23/13 6:50:01.023 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 1).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 2).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 3).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 4).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:01.022 PM racoon[3422]: IPSec Phase2 started (Initiated by me).`
`7/23/13 6:50:01.023 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 1).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 2).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 3).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 4).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:01.022 PM racoon[3422]: IPSec Phase2 started (Initiated by me).`
`7/23/13 6:50:01.023 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 1).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 2).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 3).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 4).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:01.022 PM racoon[3422]: IPSec Phase2 started (Initiated by me).`
`7/23/13 6:50:01.023 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 1).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 2).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 3).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 4).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:01.022 PM racoon[3422]: IPSec Phase2 started (Initiated by me).`
`7/23/13 6:50:01.023 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 2).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 3).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 5).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:01.022 PM racoon[3422]: IPSec Phase2 started (Initiated by me).`
`7/23/13 6:50:01.023 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 2).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 3).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 5).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:01.022 PM racoon[3422]: IPSec Phase2 started (Initiated by me).`
`7/23/13 6:50:01.023 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 2).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 3).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 5).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Quick-Mode Message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
`7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Quick-Mode).`
`7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).`
`7/23/13 6:50:01.022 PM racoon[3422]: IPSec Phase2 started (Initiated by me).`
`7/23/13 6:50:01.023 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 2).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 3).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 5).`
`7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 6).`
It seems you're experiencing an unusual situation where the log messages are repeating in a loop. This indicates a problem in the log output or handling. It's not a failure of the VPN itself, but rather a reporting issue.
Here are a few potential causes and how to troubleshoot them:
**1. Logging Configuration:**
* **Circular Buffer:** Your logging system (e.g., syslog, local system logs) might have a fixed-size buffer. When the buffer is full, it overwrites older entries. This would cause the repeated messages to be the most recent ones. Check the size of your log buffer in your logging configuration.
* **Logging Interval:** If you have configured logging to occur at fixed intervals, a recurring event can trigger multiple log messages within that interval. Examine your logging interval settings.
* **Log Rotation:** Ensure that your log rotation settings are configured correctly. If rotation is not occurring (or is occurring too slowly), the log file will grow, and the circular buffer will be filled.
**2. Software Bug:**
* **Rare, but Possible:** A bug in the VPN software itself could cause it to repeatedly log the same message. This is less likely, but still a possibility. Check for updates to your VPN software and see if others have reported similar issues.
**3. Event Trigger:**
* **Recurring Event:** The VPN might be repeatedly trying to perform an action that's triggering the same log message. For example, a failed authentication attempt that keeps happening. Look into what the VPN is doing to try to determine the cause of the recurring event.
**Troubleshooting Steps:**
1. **Check Your Logging Configuration:** This is the *most likely* cause.
* Determine where your VPN is logging to (e.g., syslog server, local system log).
* Inspect the configuration files for that logging destination. Look for settings like:
* `log_buffer_size` (or similar).
* `log_interval`.
* `log_rotate_interval`.
* `max_log_files` (or similar).
* Adjust these settings to provide more logging space and/or to rotate logs more frequently.
2. **Examine the VPN Configuration:** Review the VPN configuration itself to see if there are any settings that might be causing the VPN to repeatedly attempt the same action.
3. **Temporarily Disable Logging:** If possible, temporarily disable logging and see if the repeating messages stop. This would help confirm that the issue is directly related to the logging system.
4. **Update VPN Software:** Ensure that you are running the latest version of your VPN software. Bug fixes in newer versions might address the problem.
5. **Check VPN Logs Earlier:** If possible, look at logs from an earlier time to see if the repeating messages started after a specific change.
6. **Review System Resources:** Check CPU, memory, and disk usage on the VPN server. High resource utilization can sometimes lead to unexpected behavior.
**In summary, the most probable cause is a logging configuration issue.** By adjusting the size of your log buffer, log rotation settings, or logging interval, you should be able to resolve the repeating messages. If that doesn't work, investigate the VPN configuration and software itself for potential problems.