Basic Information
| Keywords | ipsec |
| Product | Secospace USG6650 |
| Title | USG/USG6650V500R001C60/Ipsec ike failed |
| Abstract | Customers have two USG6650, IPSec failed to establish, check found, display Ike SA. Peer address is 0.0.0.0 |
| Publication Date | 2018-04-28 06:17 |
| Associated KB | |
| Language | English |
| Application Scenario | Troubleshooting |
Application Info
| Fault Type | Operation and maintenance >> Others |
| Issue Description | version USG6650V500R001C60 Customers have two USG6650, IPSec failed to establish, check found, display Ike SA. Peer address is 0.0.0.0
|
| Alarm Information | |
| Handling Process | We opened the debug ikev1 all on the firewall and found the following alarm.
We found that packet has been retransmitting In this case, customers generally do not allow 500 ports in the security policy. We examine the customer's security policy and find that the customer simply releases the ESP protocol. |
| Root Cause | |
| Solution | In the security policy permit 500 port |

