You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Libreswan连接WatchGuard IKEv1隧道时出现无效对等体ID问题

WatchGuard远程访问VPN(Libreswan)配置排障

问题概述

Windows下ShrewSoft可正常连接WatchGuard VPN,但Linux无GUI版ShrewSoft存在路由bug,改用Libreswan配置后,IKEv1第一阶段出现ID不匹配错误,修改对等IP后又触发哈希不匹配问题。

当前Libreswan配置

conn VPN
    authby=secret
    keyexchange=ike
    ikev2=no
    auto=add
    aggressive=yes
    fragmentation=no

    ike=aes256-sha2;modp2048
    phase2=esp
    phase2alg=aes256-sha2;modp2048

    right=SERVER_IP
    left=%defaultroute

    leftid=@USERNAME
    rightid=%any
    rightnexthop=%defaultroute
    rightsubnet=192.168.170.89/32

    leftmodecfgclient=yes
    modecfgpull=yes
    nat-keepalive=yes

    leftxauthclient=yes
    leftxauthusername=XAUTH_USER
    rightxauthserver=yes 

初始错误日志

002 "VPN" #1: initiating IKEv1 Aggressive Mode connection
110 "VPN" #1: sent Aggressive Mode request
002 "VPN" #1: Peer ID is ID_IPV4_ADDR: 'NOT_SERVER_IP'
003 "VPN" #1: Peer ID 'NOT_SERVER_IP' mismatched on first found connection and no better connection found
003 "VPN" #1: initial Aggressive Mode packet claiming to be from SERVER_IP on SERVER_IP:500 but no connection has been authorized
218 "VPN" #1: sending notification INVALID_ID_INFORMATION to SERVER_IP:500

(SERVER_IP为VPN网关IP,NOT_SERVER_IP为随机IPv4地址)

修改后错误日志

将right改为上述随机IP后,出现哈希不匹配:

received Hash Payload does not match computed value
223 "VPN" #1: sending notification INVALID_HASH_INFORMATION to SERVER_IP:500

排障方案

1. 修复Peer ID匹配

WatchGuard在Aggressive模式下返回的ID可能并非网关IP,需调整rightid配置:

  • 查看ShrewSoft配置中的远程ID设置,将Libreswan的rightid改为对应值(可能是WatchGuard的主机名、内网IP或预定义ID)
  • 若ShrewSoft允许任意远程ID,替换rightid=%any为:
    rightid=%frompeer
    
    该参数会接受对等方发送的任何ID,绕过ID匹配检查

2. 验证预共享密钥

哈希不匹配90%以上是预共享密钥(PSK)不一致导致:

  • 确保/etc/ipsec.secrets中的密钥与ShrewSoft完全一致,注意大小写、特殊字符、空格(包括前后空格)
  • 密钥格式示例:SERVER_IP @USERNAME : PSK "your_exact_secret_key"

3. 补充NAT穿越配置

如果VPN网关处于NAT环境后,添加以下配置:

nat_traversal=yes
forceencaps=yes

4. 对齐IKE协商参数

对比ShrewSoft的IKE参数,确保Libreswan配置完全匹配:

  • 检查ShrewSoft中的IKE版本、加密算法、哈希算法、DH组
  • 若ShrewSoft使用SHA-1而非SHA-2,修改ike和phase2alg为:
    ike=aes256-sha1;modp2048
    phase2alg=aes256-sha1;modp2048
    

5. 临时跳过ID严格检查

若上述方案无效,可临时添加以下配置测试:

rightid=%ignore

内容的提问来源于stack exchange,提问作者Anfaenger

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 06:40:19