DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Ipsec failure -Double Free for ... from this.id.name

  • routintooter
  • Topic Author
  • User
  • User
More
03 Jan 2012 19:51 #1 by routintooter
Hi.
I have an odd problem.
I am trying to get 2 drayteks to vpn using ipsec - lan to lan.
The problem is if the connection get "disturbed" - dropped in some way - it fails to reconnect.
Rebooting seems to fix the issue.

Looking at the log for router A (once "disturbed"):

Dialing Node8 (KBBSCB4) :
Initiating IKE Aggressive Mode to xx.xx.17.xx
IKE ==>, Next Payload=ISAKMP_NEXT_SA, Exchange Type = 0x4, Message ID = 0x0

(here is other info but i think it applies to another vpn - i cant disable it as it doesnt have "dial in" capability)
DOUBLE free for 819exyz0: 7azz from this.id.name
... and then starts again...

At the other end (router B) all i see is:
Responding to Aggressive mode from xx.xx.xx.xx
... over and over.

What does the "DOUBLE free" refer to - AFAIK it seems to refer to memory incorrectly freed/allocated.


Router A is the dial out machine - it has no public ip (this is the one with "the problem"):
Model Name : Vigor2920n
Firmware Version : 3.3.7
Build Date/Time : Sep 20 2011 14:48:33

Router B is the dial in machine:
Model Name : Vigor2800 series
Firmware Version : 2.8.2
Build Date/Time : Tue Jun 3 15:26:55.35 2008
ADSL Firmware Version : E.38.2.23 Annex A

Connection:
Ipsec using PSK and PeerID in format xxx@yyy.com

Dial out expects:
- Ipsec security = High(esp) AES With Authentication.
- Aggressive mode.
- DES_MD5_G1/DES_SHA1_G1/3DES_MD5_G1/3DES_SHA1_G1
- IKE phase 2 proposal AES128_SHA1/AES128_MD5
- PFS=disable

Dial In Offers:
- Ipsec security = High(esp) AES

Any help greatly appreciated.

Chris

Please Log in or Create an account to join the conversation.