Quantcast
Channel: SRX Services Gateway topics
Viewing all articles
Browse latest Browse all 3959

multiple IKE using same gateway?

$
0
0

Hi all,

 

Can we establish multiple IKE using one gateway on SRX345? Below is my config. The peer unit is Strongswan. The issue is the user2 cannot establish. Even i disconnect user1 the user2 still cannot establish the IKE.

 

[edit security ike]
test# show
traceoptions {
    file ike-debug size 10m files 10;
    flag all;
    level 15;
}
proposal ike-proposal {
    authentication-method pre-shared-keys;
    dh-group group14;
    authentication-algorithm sha-256;
    encryption-algorithm aes-128-cbc;
}
policy ike-policy {
    mode aggressive;
    proposals ike-proposal;
    pre-shared-key ascii-text "$9$vA4WNdUDkq.foaz39C0OxN-V24aZU"; ## SECRET-DATA
}
gateway ike-gateway {
    ike-policy ike-policy;
    dynamic user-at-hostname "user1@test.com.us";
    dead-peer-detection optimized;
    external-interface ge-0/0/0.0;
    version v2-only;
}
gateway ike-gateway2 {
    ike-policy ike-policy;
    dynamic user-at-hostname "user2@test.com.us";
    dead-peer-detection optimized;
    external-interface ge-0/0/0.0;
    version v2-only;
}

 

[May 18 17:11:25]iked_pm_phase1_sa_cfg_lookup_by_addr: Address based phase 1 SA-CFG lookup failed for local:7.7.7.7, remote:42.153.23.34 IKEv2

[May 18 17:11:25]iked_pm_phase1_sa_cfg_lookup: IKEv2, initial negotiation case, skip ID lookup

[May 18 17:11:25]iked_pm_dynamic_gw_local_addr_based_lookup: called with local ip:7.7.7.7

[May 18 17:11:25]iked_pm_dynamic_gw_local_addr_based_lookup: IKEv2, doing local-address based gateway lookup

[May 18 17:11:25]iked_pm_dynamic_gw_local_addr_based_lookup: ktu local ip:7.7.7.7

[May 18 17:11:25]iked_pm_dynamic_gw_local_addr_based_lookup: Found gateway matching local addr ike-gateway for remote dynamic peer, sa_cfg[ipsec-vpn]

[May 18 17:11:25]iked_pm_phase1_sa_cfg_lookup: dynamic gateway match successfulSmiley Frustrateda_cfg:ipsec-vpn Gateway:ike-gateway

[May 18 17:11:25]ikev2_fb_idv2_to_idv1: Converting the IKEv2 payload ID IDa(type = email (3), len = 22, value = user2@test.com.us) to IKEv1 ID

[May 18 17:11:25]ikev2_fb_idv2_to_idv1: IKEv2 payload ID converted to IKEv1 payload ID usr@fqdn(any:0,[0..21]=user2@test.com.us)

[May 18 17:11:25]iked_pm_id_validate called with id usr@fqdn(any:0,[0..21]=user2@test.com.us)

[May 18 17:11:25]iked_pm_id_validate id NOT matched.

 

 

Thanks and appreciate any feedback


Viewing all articles
Browse latest Browse all 3959

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>