get ipsecvpn session summary on the Edge Node results in an output similar to the below:Thu May 30 2024 EDT 04:25:27.853Version SID Compliance Suite Type Auth Status Local IP Peer IP Down Reason----------------------------------------------------------------------------------------------------------------------------IKEv2 0 NONE Policy PSK Down <Local IP> <Peer IP> IKED waiting for RSS queue info from DPIKEv1 0 NONE Policy PSK Down <Local IP> <Peer IP> IKED waiting for RSS queue info from DPIKEv2 0 NONE Policy PSK Down <Local IP> <Peer IP> IKED waiting for RSS queue info from DPIKEv2 0 NONE Policy PSK Down <Local IP> <Peer IP> IKED waiting for RSS queue info from DP----------------------------------------------------------------------------------------------------------------------------
/var/dump:-rw-r--r-- 1 root root 2.0M May 30 01:03 core.iked.#.gz
/var/log/kern.log:2024-05-30T05:03:47.852Z edge01 kernel - - - [ 6277.247167] grsec: Segmentation fault occurred at 0000000000000038 in /opt/vmware/nsx-edge/bin/iked[iked:28091] uid/euid:150/150 gid/egid:150/150, parent /opt/vmware/edge/ike/entrypoint.sh[entrypoint.sh:27973] uid/euid:150/150 gid/egid:150/150
Note: The preceding log excerpts are only examples. Date, time, and environmental variables may vary depending on your environment.
VMware NSX-T Data Center
VMware NSX
Prior to NSX-T 3.2.0, any empty field in the Bypass Policy would get mapped to IP address as 0.0.0.0.
In NSX-T 3.2.0 and later, the mapping is missing, due to which the nestdb attributes for local/remote appear with NULL values, this leads to crashing while processing occurs in IKED, as the value is expected but is not present.
This issue is resolved in VMware NSX 4.2.0, available at Broadcom downloads.
If you are having difficulty finding and downloading software, please review the Download Broadcom products and software KB.
Workaround
Before Upgrade:
After Upgrade:
# docker start service_iked