Hello to all.....
We recently set up an L2L VPN tunnel with another company.
The issue is that - even though both the phase I & phase II tunnels came (and remain) up, we also continue to see VPN error messages indicating that there is an IKE negotiation problem with the remote peer.
I confess to being a bit mystified. I don't understand how both the Phase I & Phase II SAs can be up - even though (ostensibly) we have an ongoing problem with the IKE negotiation!
Our firewall is an SRX240H. It is running firmware version 12.1X46-D35.1.
Here is the output with respect to the status of the phase I and phase II SAs - as well as the VPN error messages..........
root@fw-srx01b> show security ike security-associations
node1:
--------------------------------------------------------------------------
Index State Initiator cookie Responder cookie Mode Remote Address
9662568 UP abbbbf100d327490 1e8b2bc76253b71a Main 200.49.160.170
9663234 UP ae5fef57c805401c e184d499361a303b Main 187.141.14.114
9662919 UP 17e0586991601667 0e502d85d008a341 Main 190.127.254.36
9662740 UP 8f24e91688b5b9fb c37e53f8c5cb287a Main 205.251.233.121
9662498 UP de84e24e58998143 8e6e7a4ebe52232a Main 200.108.35.50
9661888 UP e150f3a25bee3996 bc1ce9d80b9155eb Main 190.13.110.66
9662852 UP 36ef50b7d5125e75 eced2e567d48b803 Main 205.251.233.122
9663297 UP 0915ea3e890bbfa4 4db0758ded19679c Main 200.95.161.2
9663248 UP ea205a0d65607197 ae1250545a1fe78c Main 216.184.96.98
9660862 UP 9a43dc7e5165385a 353ce130cfb27b3a Main 144.160.7.164
{primary:node1}
root@fw-srx01b> show security ike security-associations | grep 216.184.96.98
9663248 UP ea205a0d65607197 ae1250545a1fe78c Main 216.184.96.98
{primary:node1}
root@fw-srx01b> show security ipsec security-associations | grep 216.184.96.98
<131104 ESP:aes-cbc-256/sha1 a81a2a16 1083/ unlim - root 500 216.184.96.98
>131104 ESP:aes-cbc-256/sha1 c062776a 1083/ unlim - root 500 216.184.96.98
<131114 ESP:aes-cbc-256/sha1 4fb0933f 3274/ unlim - root 500 216.184.96.98
>131114 ESP:aes-cbc-256/sha1 37fe7552 3274/ unlim - root 500 216.184.96.98
<131124 ESP:aes-cbc-256/sha1 14acf1a9 1256/ unlim - root 500 216.184.96.98
>131124 ESP:aes-cbc-256/sha1 34c37a0b 1256/ unlim - root 500 216.184.96.98
<131126 ESP:aes-cbc-256/sha1 52095d79 1273/ unlim - root 500 216.184.96.98
>131126 ESP:aes-cbc-256/sha1 25aab46b 1273/ unlim - root 500 216.184.96.98
<131128 ESP:aes-cbc-256/sha1 4ee549bf 1192/ unlim - root 500 216.184.96.98
>131128 ESP:aes-cbc-256/sha1 e6418db9 1192/ unlim - root 500 216.184.96.98
<131130 ESP:aes-cbc-256/sha1 c7eeb18a 1299/ unlim - root 500 216.184.96.98
>131130 ESP:aes-cbc-256/sha1 575cae42 1299/ unlim - root 500 216.184.96.98
<131132 ESP:aes-cbc-256/sha1 92c0090f 2290/ unlim - root 500 216.184.96.98
>131132 ESP:aes-cbc-256/sha1 750ac4a 2290/ unlim - root 500 216.184.96.98
{primary:node1}
root@fw-srx01b> show log kmd-logs | grep 216.184.96.98
Aug 3 17:30:06 fw-srx01b kmd[46715]: IKE negotiation failed with error: Invalid syntax. IKE Version: 1, VPN: vpn-telefon-cam-01-451 Gateway: gw-vpn-telefon-cam-01, Local: 69.26.111.152/500, Remote: 216.184.96.98/500, Local IKE-ID: 69.26.111.152, Remote IKE-ID: 216.184.96.98, VR-ID: 4
Aug 3 17:30:06 fw-srx01b kmd[46715]: IKE negotiation failed with error: Invalid syntax. IKE Version: 1, VPN: vpn-telefon-cam-01-340 Gateway: gw-vpn-telefon-cam-01, Local: 69.26.111.152/500, Remote: 216.184.96.98/500, Local IKE-ID: 69.26.111.152, Remote IKE-ID: 216.184.96.98, VR-ID: 4
Aug 3 17:30:06 fw-srx01b kmd[46715]: IKE negotiation failed with error: Invalid syntax. IKE Version: 1, VPN: vpn-telefon-cam-01-452 Gateway: gw-vpn-telefon-cam-01, Local: 69.26.111.152/500, Remote: 216.184.96.98/500, Local IKE-ID: 69.26.111.152, Remote IKE-ID: 216.184.96.98, VR-ID: 4
Aug 3 17:30:06 fw-srx01b kmd[46715]: IKE negotiation failed with error: Invalid syntax. IKE Version: 1, VPN: vpn-telefon-cam-01-453 Gateway: gw-vpn-telefon-cam-01, Local: 69.26.111.152/500, Remote: 216.184.96.98/500, Local IKE-ID: 69.26.111.152, Remote IKE-ID: 216.184.96.98, VR-ID: 4
Aug 3 17:30:06 fw-srx01b kmd[46715]: IKE negotiation failed with error: Invalid syntax. IKE Version: 1, VPN: vpn-telefon-cam-01-454 Gateway: gw-vpn-telefon-cam-01, Local: 69.26.111.152/500, Remote: 216.184.96.98/500, Local IKE-ID: 69.26.111.152, Remote IKE-ID: 216.184.96.98, VR-ID: 4
Aug 3 17:31:06 fw-srx01b kmd[46715]: IKE negotiation failed with error: Invalid syntax. IKE Version: 1, VPN: vpn-telefon-cam-01-340 Gateway: gw-vpn-telefon-cam-01, Local: 69.26.111.152/500, Remote: 216.184.96.98/500, Local IKE-ID: 69.26.111.152, Remote IKE-ID: 216.184.96.98, VR-ID: 4
Aug 3 17:31:06 fw-srx01b kmd[46715]: IKE negotiation failed with error: Invalid syntax. IKE Version: 1, VPN: vpn-telefon-cam-01-451 Gateway: gw-vpn-telefon-cam-01, Local: 69.26.111.152/500, Remote: 216.184.96.98/500, Local IKE-ID: 69.26.111.152, Remote IKE-ID: 216.184.96.98, VR-ID: 4
Aug 3 17:31:06 fw-srx01b kmd[46715]: IKE negotiation failed with error: Invalid syntax. IKE Version: 1, VPN: vpn-telefon-cam-01-452 Gateway: gw-vpn-telefon-cam-01, Local: 69.26.111.152/500, Remote: 216.184.96.98/500, Local IKE-ID: 69.26.111.152, Remote IKE-ID: 216.184.96.98, VR-ID: 4
Aug 3 17:31:06 fw-srx01b kmd[46715]: IKE negotiation failed with error: Invalid syntax. IKE Version: 1, VPN: vpn-telefon-cam-01-453 Gateway: gw-vpn-telefon-cam-01, Local: 69.26.111.152/500, Remote: 216.184.96.98/500, Local IKE-ID: 69.26.111.152, Remote IKE-ID: 216.184.96.98, VR-ID: 4
Aug 3 17:31:06 fw-srx01b kmd[46715]: IKE negotiation failed with error: Invalid syntax. IKE Version: 1, VPN: vpn-telefon-cam-01-454 Gateway: gw-vpn-telefon-cam-01, Local: 69.26.111.152/500, Remote: 216.184.96.98/500, Local IKE-ID: 69.26.111.152, Remote IKE-ID: 216.184.96.98, VR-ID: 4
Aug 3 17:32:06 fw-srx01b kmd[46715]: IKE negotiation failed with error: Invalid syntax. IKE Version: 1, VPN: vpn-telefon-cam-01-451 Gateway: gw-vpn-telefon-cam-01, Local: 69.26.111.152/500, Remote: 216.184.96.98/500, Local IKE-ID: 69.26.111.152, Remote IKE-ID: 216.184.96.98, VR-ID: 4
I'd be grateful for any explanation that resolves this puzzle.
Thank you.
Very best regards.
John D.