Got it

IPSec SA negociation missmatch

Latest reply: Dec 15, 2018 15:21:34 930 1 0 0 0

Hello everyone,

IPSec tunnel on the customer's site is not coming up and finding remote SA.

So an IPSec debug was done and it reflected no information coming out at all.
So the first step is verifying connectivity, once we noticed that it was working fine, then the next step is to verify the IPsec proposal information to find out if everything is matching ad compatible.
On one peer, the customer had:

#

ike proposal 1

 encryption-algorithm 3des-cbc

 dh group 14

#


However, in the other peer, it was

#

ike proposal 1

 encryption-algorithm 3des-cbc

 dh group 2

#


So, a DH group is indeed in use, nevertheless, by default, it is set to 2, therefore, the solution for this was to make them match, by just modifying the first peer to dh group 2 (since it was a hub, so all of the other spokes needed to match to dh2).

The main point in this is that the first point to verify after testing connectivity is to look for everything to match in the IPSec proposal.


That is all I want to share with you!

Good job
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.