phase 1 up phase 2 down

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

phase 1 up phase 2 down

Cyber Elite
Cyber Elite

( description contains 'IKE phase-1 negotiation is failed. Peer\'s ID payload 10.175.150.0 (type ipaddr) does not match a configured IKE gateway.' )

 

 

and ( description contains 'IKE phase-1 negotiation is failed as responder, main mode. Failed SA: 198.160.191.5[500]-173.182.112.167[500] cookie:5357205146f1b40c:a194d23cbec27a50. Due to timeout.' )

 

I get above in system logs phase 1 is up but phase 2 not 

MP

Help the community: Like helpful comments and mark solutions.
1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

@MP18,

Under the IKE Gateway for the tunnel verify that the Local Identification and the Peer Identification are actually matching (in reverse order) for the selected tunnel.

The following is an example:

 

PA-1:

Local Identification:    IP address    10.10.139.230

Peer Identification    FQDN (hostname)    TEST01

 

PA-2:

Local Identification:    FQDN (hostname)    TEST01

Peer Identification:    IP address   10.10.139.230

 

What the log is saying is that essentially the peer device is sending the id of 10.175.150.0 as it's Local Identification, and that ID doesn't match any of your IKE Gateway's configured Peer Identification. Meaning that the firewall doesn't have an IKE Gateway configured for the device. 

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

@MP18,

Under the IKE Gateway for the tunnel verify that the Local Identification and the Peer Identification are actually matching (in reverse order) for the selected tunnel.

The following is an example:

 

PA-1:

Local Identification:    IP address    10.10.139.230

Peer Identification    FQDN (hostname)    TEST01

 

PA-2:

Local Identification:    FQDN (hostname)    TEST01

Peer Identification:    IP address   10.10.139.230

 

What the log is saying is that essentially the peer device is sending the id of 10.175.150.0 as it's Local Identification, and that ID doesn't match any of your IKE Gateway's configured Peer Identification. Meaning that the firewall doesn't have an IKE Gateway configured for the device. 

Got it.

 

Many Thanks

MP

Help the community: Like helpful comments and mark solutions.
  • 1 accepted solution
  • 9430 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!