Hi, we have 2 srx devices on both sides
Local: 50.208.33.177 <-> Remote: 64.13.163.35
During the day a few times the VPN does down, we have a few site to site VPNs but just one goes down every day
When I check :
>> show security ike security-associations
the state seems to be as DOWN
Index State Initiator cookie Responder cookie Mode Remote Address
2853423 DOWN 8ad07f60fc6c2500 ccc8ba940b4cf03e Any 104.196.42.142
2853427 DOWN edd10fce18408325 25379263dc240f3a Any 104.196.42.142
2853421 DOWN 7d9ee01a946476dc 4c8fb92a02fd9ceb Any 104.196.42.142
2849279 UP 94651e0d5a9d7d86 972a87d367a9e54a Main 104.239.188.167
2853387 UP 8d2418279585930e 2282d9643421dc8d Main 64.13.163.35
Here are the logs from both sides :
Remote Site SRX logs :
Jan 3 18:37:31 srx240-02a kmd[33482]: KMD_VPN_DOWN_ALARM_USER: VPN INSTANCE-hq_0012_0015_0000 from 50.208.33.177 is down.
Jan 3 18:38:24 srx240-02a kmd[33482]: IKE Phase-1 Failure: ISAKMP negotiation retry limit reached [spi=M-^M$^X'M-^UM-^EM-^S^N"M-^B?d4!?M-^M, src_ip=<none>, dst_ip=50.208.33.177]
Jan 3 18:38:34 srx240-02a kmd[33482]: IKE Phase-1 Failure: ISAKMP negotiation retry limit reached [spi=M-^M$^X'M-^UM-^EM-^S^N"M-^B?d4!?M-^M, src_ip=<none>, dst_ip=50.208.33.177]
Jan 3 18:38:34 srx240-02a kmd[33482]: IKE Phase-2 Failure: IKE Phase-2 negotiation retry limit reached [spi=21d29865, src_ip=64.13.163.35, dst_ip=50.208.33.177]
Jan 3 18:38:34 srx240-02a kmd[33482]: IKE Phase-2: Negotiations failed. Local gateway: 64.13.163.35, Remote gateway: 50.208.33.177
Jan 3 18:39:21 srx240-02a kmd[33482]: KMD_VPN_DOWN_ALARM_USER: VPN INSTANCE-hq_0012_0015_0000 from 50.208.33.177 is down.
Jan 3 18:39:26 srx240-02a kmd[33482]: IKE Phase-1 Failure: ISAKMP negotiation retry limit reached [spi=M-^M$^X'M-^UM-^EM-^S^N"M-^B?d4!?M-^M, src_ip=<none>, dst_ip=50.208.33.177]
Jan 3 18:39:36 srx240-02a kmd[33482]: IKE Phase-1 Failure: ISAKMP negotiation retry limit reached [spi=M-^M$^X'M-^UM-^EM-^S^N"M-^B?d4!?M-^M, src_ip=<none>, dst_ip=50.208.33.177]
Jan 3 18:39:36 srx240-02a kmd[33482]: IKE Phase-2 Failure: IKE Phase-2 negotiation retry limit reached [spi=a6ef2584, src_ip=64.13.163.35, dst_ip=50.208.33.177]
Jan 3 18:39:36 srx240-02a kmd[33482]: IKE Phase-2: Negotiations failed. Local gateway: 64.13.163.35, Remote gateway: 50.208.33.177
Jan 3 18:40:29 srx240-02a kmd[33482]: IKE Phase-1 Failure: ISAKMP negotiation retry limit reached [spi=M-^M$^X'M-^UM-^EM-^S^N"M-^B?d4!?M-^M, src_ip=<none>, dst_ip=50.208.33.177]
Jan 3 18:40:39 srx240-02a kmd[33482]: IKE Phase-1 Failure: ISAKMP negotiation retry limit reached [spi=M-^M$^X'M-^UM-^EM-^S^N"M-^B?d4!?M-^M, src_ip=<none>, dst_ip=50.208.33.177]
Jan 3 18:40:39 srx240-02a kmd[33482]: IKE Phase-2 Failure: IKE Phase-2 negotiation retry limit reached [spi=6e368fc4, src_ip=64.13.163.35, dst_ip=50.208.33.177]
Jan 3 18:40:39 srx240-02a kmd[33482]: IKE Phase-2: Negotiations failed. Local gateway: 64.13.163.35, Remote gateway: 50.208.33.177
Jan 3 18:41:11 srx240-02a kmd[33482]: KMD_VPN_DOWN_ALARM_USER: VPN INSTANCE-hq_0012_0015_0000 from 50.208.33.177 is down.
Jan 3 18:43:02 srx240-02a kmd[33482]: KMD_VPN_DOWN_ALARM_USER: VPN INSTANCE-hq_0012_0015_0000 from 50.208.33.177 is down.
Jan 3 18:44:52 srx240-02a kmd[33482]: KMD_VPN_DOWN_ALARM_USER: VPN INSTANCE-hq_0012_0015_0000 from 50.208.33.177 is down.
Jan 3 18:46:42 srx240-02a kmd[33482]: KMD_VPN_DOWN_ALARM_USER: VPN INSTANCE-hq_0012_0015_0000 from 50.208.33.177 is down.
Jan 3 18:48:32 srx240-02a kmd[33482]: KMD_VPN_DOWN_ALARM_USER: VPN INSTANCE-hq_0012_0015_0000 from 50.208.33.177 is down.
Jan 3 18:48:32 srx240-02a kmd[33482]: IKE Phase-1: (Initiator) The symmetric crypto key has been generated successfully [local_ip=64.13.163.35, local_port=500, remote_ip=50.208.33.177, remote_port=500]
Jan 3 18:48:32 srx240-02a kmd[33482]: IKE Phase-1: Negotiation completed; SA expires on Fri Jan 04 2019 18:48:32 { 701272be 02fb954f - b0a532b3 92687e2a } - [local_id=64.13.163.35, local_ip=64.13.163.35, local_port=500, remote_id=50.208.33.177, remote_ip=50.208.33.177, remote_port=500, Exchange Mode:main]
Jan 3 18:48:32 srx240-02a kmd[33482]: KMD_VPN_UP_ALARM_USER: VPN INSTANCE-hq_0012_0015_0000 from 50.208.33.177 is up.
Jan 3 18:48:32 srx240-02a kmd[33482]: KMD_PM_SA_ESTABLISHED: Local gateway: 64.13.163.35, Remote gateway: 50.208.33.177, Local ID: ipv4_subnet(any:0,[0..7]=0.0.0.0/0), Remote ID: ipv4_subnet(any:0,[0..7]=0.0.0.0/0), Direction: inbound, SPI: 0xa8748b89, AUX-SPI: 0, Mode: Tunnel, Type: dynamic
Jan 3 18:48:32 srx240-02a kmd[33482]: IKE Phase-2: Completed negotiations, connection established with tunnel-ID:12 and lifetime 28196 seconds/0 KB - Local gateway: 64.13.163.35, Remote gateway: 50.208.33.177, Local Proxy ID: ipv4_subnet(any:0,[0..7]=0.0.0.0/0), Remote Proxy ID: ipv4_subnet(any:0,[0..7]=0.0.0.0/0), Protocol: ESP, Auth algo: sha256, Encryption algo: 3des-cbc, Direction: inbound, SPI: a8748b89, AUX-SPI: 0, Type: dynamic
Jan 3 18:48:32 srx240-02a kmd[33482]: KMD_PM_SA_ESTABLISHED: Local gateway: 64.13.163.35, Remote gateway: 50.208.33.177, Local ID: ipv4_subnet(any:0,[0..7]=0.0.0.0/0), Remote ID: ipv4_subnet(any:0,[0..7]=0.0.0.0/0), Direction: outbound, SPI: 0x4ce1aa51, AUX-SPI: 0, Mode: Tunnel, Type: dynamic
Jan 3 18:48:32 srx240-02a kmd[33482]: IKE Phase-2: Completed negotiations, connection established with tunnel-ID:12 and lifetime 28196 seconds/0 KB - Local gateway: 64.13.163.35, Remote gateway: 50.208.33.177, Local Proxy ID: ipv4_subnet(any:0,[0..7]=0.0.0.0/0), Remote Proxy ID: ipv4_subnet(any:0,[0..7]=0.0.0.0/0), Protocol: ESP, Auth algo: sha256, Encryption algo: 3des-cbc, Direction: outbound, SPI: 4ce1aa51, AUX-SPI: 0, Type: dynamic
Jan 3 18:48:32 srx240-02a kmd[33482]: IKE Phase-2: (Initiator) The symmetric crypto key has been generated successfully [local_ip=64.13.163.35, local_port=500, remote_ip=50.208.33.177, remote_port=500]
LOCAL Side Srx Logs :
Jan 3 16:52:29 srx240-01 kmd[1447]: KMD_VPN_DOWN_ALARM_USER: VPN svcolo from 64.13.163.35 is down. Local-ip: 50.208.33.177, gateway name: gw_svcolo, vpn name: svcolo, tunnel-id: 131073, local tunnel-if: st0.0, remote tunnel-ip: Not-Available, Local IKE-ID: 50.208.33.177, Remote IKE-ID: 64.13.163.35, XAUTH username: Not-Applicable, VR id: 0
Jan 3 16:56:07 srx240-01 kmd[1447]: IKE negotiation failed with error: SA unusable. IKE Version: 1, VPN: svcolo Gateway: gw_svcolo, Local: 50.208.33.177/500, Remote: 64.13.163.35/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0
Jan 3 16:56:37 srx240-01 kmd[1447]: IKE negotiation failed with error: SA unusable. IKE Version: 1, VPN: svcolo Gateway: gw_svcolo, Local: 50.208.33.177/500, Remote: 64.13.163.35/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0
Jan 3 16:57:07 srx240-01 kmd[1447]: IKE negotiation failed with error: SA unusable. IKE Version: 1, VPN: svcolo Gateway: gw_svcolo, Local: 50.208.33.177/500, Remote: 64.13.163.35/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0
Jan 3 16:57:39 srx240-01 kmd[1447]: IKE negotiation failed with error: SA unusable. IKE Version: 1, VPN: svcolo Gateway: gw_svcolo, Local: 50.208.33.177/500, Remote: 64.13.163.35/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0
Jan 3 16:58:09 srx240-01 kmd[1447]: IKE negotiation failed with error: SA unusable. IKE Version: 1, VPN: svcolo Gateway: gw_svcolo, Local: 50.208.33.177/500, Remote: 64.13.163.35/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0
Jan 3 16:58:39 srx240-01 kmd[1447]: IKE negotiation failed with error: SA unusable. IKE Version: 1, VPN: svcolo Gateway: gw_svcolo, Local: 50.208.33.177/500, Remote: 64.13.163.35/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0
Jan 3 16:59:11 srx240-01 kmd[1447]: IKE negotiation failed with error: SA unusable. IKE Version: 1, VPN: svcolo Gateway: gw_svcolo, Local: 50.208.33.177/500, Remote: 64.13.163.35/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0
Anybody had an issue like this or any idea about it ?
Thanks