root@cp-strongswan:~# ipsec up vpn_smb initiating IKE_SA vpn_smb[1] to X.X.X.X generating IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) N(HASH_ALG) N(REDIR_SUP) ] sending packet: from 10.182.0.12[500] to X.X.X.X[500] (1236 bytes) received packet: from X.X.X.X[500] to 10.182.0.12[500] (449 bytes) parsed IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_S_IP) N(NATD_S_IP) N(NATD_S_IP) N(NATD_S_IP) N(NATD_D_IP) CERTREQ ] selected proposal: IKE:AES_CBC_256/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024 local host is behind NAT, sending keep alives received cert request for "O=00:1C:7F:B1:9C:48..ng4uc4" received 1 cert requests for an unknown ca sending cert request for "O=00:1C:7F:B1:9C:48..ng4uc4" no IDi configured, fall back on IP address establishing CHILD_SA vpn_smb{1} generating IKE_AUTH request 1 [ IDi N(INIT_CONTACT) CERTREQ IDr CPRQ(ADDR DNS) SA TSi TSr N(MOBIKE_SUP) N(NO_ADD_ADDR) N(EAP_ONLY) N(MSG_ID_SYN_SUP) ] sending packet: from 10.182.0.12[4500] to X.X.X.X[4500] (412 bytes) received packet: from X.X.X.X[4500] to 10.182.0.12[4500] (76 bytes) parsed IKE_AUTH response 1 [ N(INVAL_SYN) ] received INVALID_SYNTAX notify error establishing connection 'vpn_smb' failed root@cp-strongswan:~#