Getting this from Vendor device eventid eq ike-recv-p1-delete

Reply
Highlighted
Cyber Elite

Getting this from Vendor device eventid eq ike-recv-p1-delete

After Phase 1 success as Responder in PA  I am getting   below event id 

 

( description contains 'IKE protocol notification message received: INITIAL-CONTACT (24578).' )

 

and ( eventid eq ipsec-key-expire )

 

eventid eq ike-recv-p1-delete

description contains 'IKE protocol phase-1 SA delete message received from peer. cookie:5b34d3ab8d000c44:6d1b2079c0cb41f1

 

These steps are reoccuring every time 

 

phase 1 success

and ( eventid eq ike-recv-notify )

and ( eventid eq ipsec-key-expire )

and ( eventid eq ike-send-p2-delete )

 

What can be reson for this?

MP
Tags (2)

Accepted Solutions
Highlighted
Cyber Elite

Seems REbooting the vendor device fixed the issue

MP

View solution in original post


All Replies
Highlighted
L7 Applicator

Are you actually experiencing a problem or are you just curious about the logs?

 

When the keys expire, a new one is received (ike-recv-notify), the old ones expire (ipsec-key-expire), and the old ones are deleted (ike-send-p2-delete).

 

My recommendation would be to set up a single firewall with a single VPN connection and watch the logs as it goes through its normal functions. When you have lots of tunnels, you'll see lots of messaging.

Highlighted
Cyber Elite

we are having issues right now

Phase 1 is up Phase 2 is down

 

We habe single tunnel from PA to this device

MP
Highlighted
Cyber Elite

@MP18 ,

I think what @gwesson was getting at with his message was essentially "have you verified all of the logs you are looking at are coming from the connection in question"? If not then I apologize for putting words on your keyboard @gwesson. If that's the case, they can come from mine.

Essentially if you are just looking at the event-ids and you have multiple tunnels on a device this isn't that helpful. You need to narrow the logs down to a single tunnel so you can start troubleshooting that connection. From all of the event-ids you have listed it's kind of unlikely they are all coming from the same connection with how fast the logs are said to be generating. 

Highlighted
Cyber Elite

Yes i have verified all the logs are from same tunnel.

That's the reason i am here to get help from you so that i can know the reason for this?

MP
Highlighted
Cyber Elite

Hello,

I would suggest contacting support to see what is going on. Also if you could have someone that manages the other device on the line as well, it would make troubleshooting easier.

 

Regards,

Highlighted
Cyber Elite

case is opened with support 

still not going anywhere

MP
Highlighted
Cyber Elite

Seems REbooting the vendor device fixed the issue

MP

View solution in original post

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!