Proxy-ID Error message for GlobalProtect Client

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Proxy-ID Error message for GlobalProtect Client

L0 Member

We have configured a GlobalProtect Gateway to service clients using both the GP Agent and X-Auth parameters with 3rd Party Clients.

 

We have been receiving the following error messages:

'IKE phase-2 negotiation failed when processing proxy ID. cannot find matching phase-2 tunnel for received proxy ID. received local id: 10.0.0.0/8 type IPv4_subnet protocol 0 port 0, received remote id: 10.10.2.5/32 type IPv4_address protocol 0 port 0.'

 

The Object shown in the error messages identifies the name of our GlobalProtect Gateway. 

 

I am surprised to find Phase-2 Proxy-ID error messsages associated with a GP Gateway. Any thoughts on what might be the cause of this?

1 accepted solution

Accepted Solutions

L7 Applicator

Hi @Don_Russell

 

Behind the scenes global protect is nothing else than a standard IKE/IPSec tunnel (with additional features).

 

What routes did you configure in your global protect gateway settings? Is 10.0.0.0/8 configured? And also does the client IP match the IP pool you have configured? If not, then it looks like a third party client has changed the settings manually on the local client and so does not accept the settings from your gateway.

View solution in original post

2 REPLIES 2

L7 Applicator

Hi @Don_Russell

 

Behind the scenes global protect is nothing else than a standard IKE/IPSec tunnel (with additional features).

 

What routes did you configure in your global protect gateway settings? Is 10.0.0.0/8 configured? And also does the client IP match the IP pool you have configured? If not, then it looks like a third party client has changed the settings manually on the local client and so does not accept the settings from your gateway.

Thank you, @Remo! That was what I needed to know. I greatly appreciate the help!

  • 1 accepted solution
  • 2169 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!