I have a problem with ipsec and xauth. If the xauth user name is longer than 30 characters, in the log you can see “Trimming Xauth user name”. The Xauth login fail. If I cut the Xauth name to 30 characters or less, the Xauth login succeed. The original Xauth user name was “Luedenscheid_luedenscheid-aussenstellen”.
With RouterOS 6.37.4 there is no problem.
11:15:58 ipsec,info respond new phase 1 (Identity Protection): 111.11.56.87[500]<=>99.231.204.198[500]
11:15:58 ipsec,info ISAKMP-SA established 111.11.56.87[4500]-99.231.204.198[4500] spi:6a36407b8d013957:e691c0e0be04100d
11:15:58 ipsec,error Trimming Xauth user name
11:15:58 ipsec,info No mode-cfg configured
11:15:58 ipsec,info XAuth login failed for user: Luedenscheid_luedenscheid-auss
11:16:02 ipsec,info respond new phase 1 (Identity Protection): 111.11.56.87[500]<=>99.231.204.198[500]
11:16:02 ipsec,info ISAKMP-SA established 111.11.56.87[4500]-99.231.204.198[4500] spi:436a58d94cf6c650:75a152295ad122d1
11:16:02 ipsec,info XAuth login succeeded for user: Luedenscheid_luedenscheid-a
11:21:18 system,info device added by admin
Changes since previous version:
!) pppoe - added fastpath support when MRRU and MLPPP are enabled;
*) tr069-client - added basic support for “/ip firewall filters”;
If you experience version related issues, then please send supout file from your router to support@mikrotik.com. File must be generated while router is not working as suspected or after crash.
In RouterOS 6.39rc41 we have still the problem with ipsec and xauth. If the xauth user name is longer than 30 characters, in the log you can see “Trimming Xauth user name”. The Xauth login fail. If I cut the Xauth name to 30 characters or less, the Xauth login succeed. The original Xauth user name was “Luedenscheid_luedenscheid-aussenstellen”. With RouterOS 6.37.4 and before there is no problem.
11:15:58 ipsec,info respond new phase 1 (Identity Protection): 111.11.56.87[500]<=>99.231.204.198[500]
11:15:58 ipsec,info ISAKMP-SA established 111.11.56.87[4500]-99.231.204.198[4500] spi:6a36407b8d013957:e691c0e0be04100d
11:15:58 ipsec,error Trimming Xauth user name
11:15:58 ipsec,info No mode-cfg configured
11:15:58 ipsec,info XAuth login failed for user: Luedenscheid_luedenscheid-auss
11:16:02 ipsec,info respond new phase 1 (Identity Protection): 111.11.56.87[500]<=>99.231.204.198[500]
11:16:02 ipsec,info ISAKMP-SA established 111.11.56.87[4500]-99.231.204.198[4500] spi:436a58d94cf6c650:75a152295ad122d1
11:16:02 ipsec,info XAuth login succeeded for user: Luedenscheid_luedenscheid-a
11:21:18 system,info device added by admin
“If you experience version related issues, then please send supout file from your router to support@mikrotik.com. File must be generated while router is not working as suspected or after crash.”
Please report your issue to support, no need to repost here every N days. Support usually responds within a few business days.
Changes since previous version:
!) firewall - discontinued support for p2p matcher (old rules will become invalid);
*) hotspot - fixed redirect to URL where escape characters are used (requires newly generated HTML files);
*) l2tp-client - fixed IPSec policy generation after reboot;
*) l2tp-client - require working IPSec encryption if “use-ipsec=yes”;
*) l2tp-server - added “use-ipsec=required” option;
*) lcd - show fan2 speed only if it is available;
*) tr069-client - added basic support for “/ip firewall filters”;
*) tr069-client - fixed “AddObjectResponse” “InstanceNumber†value;
*) tr069-client - set CHR license ID as “.SerialNumber” value to avoid “no serial number” error in ACS;
If you experience version related issues, then please send supout file from your router to support@mikrotik.com. File must be generated while router is not working as suspected or after crash.