Community discussions

MikroTik App
 
amode
newbie
Topic Author
Posts: 31
Joined: Fri Feb 23, 2007 1:28 pm

os3.15 message: length in isakmp header too big

Mon Nov 03, 2008 12:49 pm

Hey,

anyone managed to setup Mikrotik as vpn gateway for latest iphones using l2tp/ipsec?

I tried a setup and ipsec debug messages produces this output (nat-t enabled btw):

02:42:56 ipsec,ike IPsec-SA established: ESP/Transport xxx.xxx.xxx.xx[4500]->yy.yy.yyy.yy[4500] spi=44661093(0x2a97965)
02:42:56 ipsec,ike IPsec-SA established: ESP/Transport yy.yy.yyy.yy[4500]->xxx.xxx.xxx.xx[4500] spi=166580145(0x9edcfb1)

02:42:56 ipsec,ike the length in the isakmp header is too big.
02:42:57 ipsec,ike the length in the isakmp header is too big.
02:42:57 ipsec,ike the length in the isakmp header is too big.
02:42:57 ipsec,ike the length in the isakmp header is too big.

This does not sound too bad, but connection does not work (no l2tp connection shows up).

Does anyone have some ideas or comments about this?

Thanks,
Amode
 
cooldude
just joined
Posts: 3
Joined: Thu Feb 01, 2007 9:23 pm

Re: os3.15 message: length in isakmp header too big

Mon Nov 03, 2008 10:04 pm

Hi,

I can confirm the same issue. We use RouterOS for all kind of purposes and now we would like to add another box to setup l2tp/ipsec for IPhone useres...

After a couple of failed attempts I found this post which is exactly our problem...

Could please anybody confirm this ether

a.) as a bug (which will get fixed next release or so...)

b.) or as something we apparently both do wrong to get this to work ?

thanks a lot!

Who is online

Users browsing this forum: raiser and 91 guests