- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-29-2019 09:05 AM - edited 03-29-2019 09:06 AM
( description contains 'IKE phase-1 negotiation is failed. Peer\'s ID payload 10.175.150.0 (type ipaddr) does not match a configured IKE gateway.' )
and ( description contains 'IKE phase-1 negotiation is failed as responder, main mode. Failed SA: 198.160.191.5[500]-173.182.112.167[500] cookie:5357205146f1b40c:a194d23cbec27a50. Due to timeout.' )
I get above in system logs phase 1 is up but phase 2 not
03-29-2019 11:23 AM
Under the IKE Gateway for the tunnel verify that the Local Identification and the Peer Identification are actually matching (in reverse order) for the selected tunnel.
The following is an example:
PA-1:
Local Identification: IP address 10.10.139.230
Peer Identification FQDN (hostname) TEST01
PA-2:
Local Identification: FQDN (hostname) TEST01
Peer Identification: IP address 10.10.139.230
What the log is saying is that essentially the peer device is sending the id of 10.175.150.0 as it's Local Identification, and that ID doesn't match any of your IKE Gateway's configured Peer Identification. Meaning that the firewall doesn't have an IKE Gateway configured for the device.
03-29-2019 11:23 AM
Under the IKE Gateway for the tunnel verify that the Local Identification and the Peer Identification are actually matching (in reverse order) for the selected tunnel.
The following is an example:
PA-1:
Local Identification: IP address 10.10.139.230
Peer Identification FQDN (hostname) TEST01
PA-2:
Local Identification: FQDN (hostname) TEST01
Peer Identification: IP address 10.10.139.230
What the log is saying is that essentially the peer device is sending the id of 10.175.150.0 as it's Local Identification, and that ID doesn't match any of your IKE Gateway's configured Peer Identification. Meaning that the firewall doesn't have an IKE Gateway configured for the device.
03-29-2019 11:57 AM
Got it.
Many Thanks
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!