SRX

last person joined: 18 hours ago 

Ask questions and share experiences about the SRX Series, vSRX, and cSRX.
  • 1.  IPSec VPN IKE SA Issues

    Posted 05-25-2015 06:05
      |   view attached

     

    Hello.
    My task is to make a VPN channel between the two routers.
    In the derivation of logs seen this message.

     

    kmd[1090]: IKE negotiation failed with error: SA unusable. IKE Version: 1, VPN: gw-jvsrx-b Gateway: gw-jvsrx-b, Local: *.*.*.*/4500, Remote: *.*.*.*/4500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0

     

    Tell me what you need to fix.
    Juniper recently started studying. I am a novice at this.

     

    Attachment(s)

    txt
    Conf.txt   5 KB 1 version


  • 2.  RE: IPSec VPN IKE SA Issues

     
    Posted 05-25-2015 07:16
    As per your config/logs you are using NAT. Can you mention your public ip as local- address on this srx and the same as remote -address on the other end.
    You need to configure this under ike gateway hierarchy.


  • 3.  RE: IPSec VPN IKE SA Issues

    Posted 05-25-2015 09:18

    Write an example please.
    On the basis of my config.



  • 4.  RE: IPSec VPN IKE SA Issues
    Best Answer

     
    Posted 05-25-2015 09:28
    root@Peer# set security ike gateway To_SRX local-identity x.x.x.x

    Please refer to below kb

    http://kb.juniper.net/InfoCenter/index?page=content&id=KB25462


  • 5.  RE: IPSec VPN IKE SA Issues

    Posted 05-25-2015 11:02

    Thanks, I do it.

    But i have a new problem)

     

    IKE negotiation failed with error: Authentication failed.

     

    What else i must do?



  • 6.  RE: IPSec VPN IKE SA Issues

     
    Posted 05-25-2015 11:26
    Authentication error because preshared key not matching. Make sure they are matching


  • 7.  RE: IPSec VPN IKE SA Issues

    Posted 05-25-2015 14:17
      |   view attached

    It still no wokking.

    Can u analizy my log?

     

    Attachment(s)

    txt
    ike-log.txt   21 KB 1 version


  • 8.  RE: IPSec VPN IKE SA Issues

    Posted 05-26-2015 12:13

    Paste your IPSec config. It was your IPSec negotiation that failed according to the logs you pasted