cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who Me Too'd this topic

IpSec Tunnel Phase2 Red But Ike Side Green

L0 Member

Hi,

 

I have several TpLink Archer Mr400 4G Router. I setup Ipsec VPN tunnel between PA-220 and them many times. But new one is not success at Phase2.

 

Phase1 IKE is green so devices communicate. But Phase2 Tunnel Info is red and i can't see any tunnel when i click Tunnel Info. I have read the losg and find below things;

 

2022-04-19 16:50:25.878 +0300 [PNTF]: { 15: }: ====> PHASE-2 NEGOTIATION STARTED AS RESPONDER, (QUICK MODE) <====
====> Initiated SA: PaloAlto_Wan_Ip_here[500]-router_wan_ip_here[500] message id:0xBE906F60 <====
2022-04-19 16:50:25.879 +0300 [ERR ]: { 15: }: can't find matching selector
2022-04-19 16:50:25.879 +0300 [PERR]: { 15: }: failed to get sainfo.
2022-04-19 16:50:25.879 +0300 [ERR ]: failed to pre-process packet.

 

I double check both side PA220 and Tplink phase2 configuration and everyting is same.

 

TPlink Archer MR400 Phase2 Profile;

 

Tplink_ArcherMr400_phase2.PNG

 

PA220 IpSec Crypto Profile;

 

PA_Phase2_ipsecCrypto.PNG

 

IpSec Tunnel Status;

 

PA_Phase2.PNG

 

I am stuck at this point. Any help appreciated.

Thanks.

 

Who Me Too'd this topic