Getting this from Vendor device eventid eq ike-recv-p1-delete

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Getting this from Vendor device eventid eq ike-recv-p1-delete

Cyber Elite
Cyber Elite

After Phase 1 success as Responder in PA  I am getting   below event id 

 

( description contains 'IKE protocol notification message received: INITIAL-CONTACT (24578).' )

 

and ( eventid eq ipsec-key-expire )

 

eventid eq ike-recv-p1-delete

description contains 'IKE protocol phase-1 SA delete message received from peer. cookie:5b34d3ab8d000c44:6d1b2079c0cb41f1

 

These steps are reoccuring every time 

 

phase 1 success

and ( eventid eq ike-recv-notify )

and ( eventid eq ipsec-key-expire )

and ( eventid eq ike-send-p2-delete )

 

What can be reson for this?

MP

Help the community: Like helpful comments and mark solutions.
1 accepted solution

Accepted Solutions

Seems REbooting the vendor device fixed the issue

MP

Help the community: Like helpful comments and mark solutions.

View solution in original post

7 REPLIES 7

L7 Applicator

Are you actually experiencing a problem or are you just curious about the logs?

 

When the keys expire, a new one is received (ike-recv-notify), the old ones expire (ipsec-key-expire), and the old ones are deleted (ike-send-p2-delete).

 

My recommendation would be to set up a single firewall with a single VPN connection and watch the logs as it goes through its normal functions. When you have lots of tunnels, you'll see lots of messaging.

we are having issues right now

Phase 1 is up Phase 2 is down

 

We habe single tunnel from PA to this device

MP

Help the community: Like helpful comments and mark solutions.

@MP18 ,

I think what @gwesson was getting at with his message was essentially "have you verified all of the logs you are looking at are coming from the connection in question"? If not then I apologize for putting words on your keyboard @gwesson. If that's the case, they can come from mine.

Essentially if you are just looking at the event-ids and you have multiple tunnels on a device this isn't that helpful. You need to narrow the logs down to a single tunnel so you can start troubleshooting that connection. From all of the event-ids you have listed it's kind of unlikely they are all coming from the same connection with how fast the logs are said to be generating. 

Yes i have verified all the logs are from same tunnel.

That's the reason i am here to get help from you so that i can know the reason for this?

MP

Help the community: Like helpful comments and mark solutions.

Hello,

I would suggest contacting support to see what is going on. Also if you could have someone that manages the other device on the line as well, it would make troubleshooting easier.

 

Regards,

case is opened with support 

still not going anywhere

MP

Help the community: Like helpful comments and mark solutions.

Seems REbooting the vendor device fixed the issue

MP

Help the community: Like helpful comments and mark solutions.
  • 1 accepted solution
  • 7842 Views
  • 7 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!