Hi all,
Can we establish multiple IKE using one gateway on SRX345? Below is my config. The peer unit is Strongswan. The issue is the user2 cannot establish. Even i disconnect user1 the user2 still cannot establish the IKE.
[edit security ike]
test# show
traceoptions {
file ike-debug size 10m files 10;
flag all;
level 15;
}
proposal ike-proposal {
authentication-method pre-shared-keys;
dh-group group14;
authentication-algorithm sha-256;
encryption-algorithm aes-128-cbc;
}
policy ike-policy {
mode aggressive;
proposals ike-proposal;
pre-shared-key ascii-text "$9$vA4WNdUDkq.foaz39C0OxN-V24aZU"; ## SECRET-DATA
}
gateway ike-gateway {
ike-policy ike-policy;
dynamic user-at-hostname "user1@test.com.us";
dead-peer-detection optimized;
external-interface ge-0/0/0.0;
version v2-only;
}
gateway ike-gateway2 {
ike-policy ike-policy;
dynamic user-at-hostname "user2@test.com.us";
dead-peer-detection optimized;
external-interface ge-0/0/0.0;
version v2-only;
}
[May 18 17:11:25]iked_pm_phase1_sa_cfg_lookup_by_addr: Address based phase 1 SA-CFG lookup failed for local:7.7.7.7, remote:42.153.23.34 IKEv2
[May 18 17:11:25]iked_pm_phase1_sa_cfg_lookup: IKEv2, initial negotiation case, skip ID lookup
[May 18 17:11:25]iked_pm_dynamic_gw_local_addr_based_lookup: called with local ip:7.7.7.7
[May 18 17:11:25]iked_pm_dynamic_gw_local_addr_based_lookup: IKEv2, doing local-address based gateway lookup
[May 18 17:11:25]iked_pm_dynamic_gw_local_addr_based_lookup: ktu local ip:7.7.7.7
[May 18 17:11:25]iked_pm_dynamic_gw_local_addr_based_lookup: Found gateway matching local addr ike-gateway for remote dynamic peer, sa_cfg[ipsec-vpn]
[May 18 17:11:25]iked_pm_phase1_sa_cfg_lookup: dynamic gateway match successfula_cfg:ipsec-vpn Gateway:ike-gateway
[May 18 17:11:25]ikev2_fb_idv2_to_idv1: Converting the IKEv2 payload ID IDa(type = email (3), len = 22, value = user2@test.com.us) to IKEv1 ID
[May 18 17:11:25]ikev2_fb_idv2_to_idv1: IKEv2 payload ID converted to IKEv1 payload ID usr@fqdn(any:0,[0..21]=user2@test.com.us)
[May 18 17:11:25]iked_pm_id_validate called with id usr@fqdn(any:0,[0..21]=user2@test.com.us)
[May 18 17:11:25]iked_pm_id_validate id NOT matched.
Thanks and appreciate any feedback