SRX

last person joined: 4 days ago 

Ask questions and share experiences about the SRX Series, vSRX, and cSRX.
Expand all | Collapse all

IKE between SRX and StrongSwan keeps timing out

  • 1.  IKE between SRX and StrongSwan keeps timing out

    Posted 07-13-2016 07:47

    Hi all,

     

    I'm trying to set up a site-to-site VPN tunnel from a Juniper SRX220 to a server running StrongSwan using IKEv1 with PSK. The problem is that even if the "ike" service is allowed in the host inbound traffic of the Internet (untrusted) zone, IKE phase 1 keeps timing out.

     

    Here's the SRX's KMD log that indicates a timeout:

    SRX220 kmd[4797]: IKE negotiation failed with error: Timed out. IKE Version: 1, VPN: vpn-amsterdam-strongswan Gateway: gw-amsterdam-strongswan, Local: <srx-ip-address>/4500, Remote: <vpn-server-public-ip>/4500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0

    And here's the StrongSwan logs showing a lot of retransmits:

    Jul 13 10:32:46 vpn-ams charon: 16[ENC] generating ID_PROT response 0 [ ID HASH ]
    Jul 13 10:32:46 vpn-ams charon: 16[NET] sending packet: from 10.18.0.5[4500] to <srx-ip-address>[4500] (92 bytes)
    Jul 13 10:32:46 vpn-ams charon: 16[IKE] destroying duplicate IKE_SA for peer '<redacted>', received INITIAL_CONTACT
    Jul 13 10:32:56 vpn-ams charon: 05[NET] received packet: from <srx-ip-address>[4500] to 10.18.0.5[4500] (108 bytes)
    Jul 13 10:32:56 vpn-ams charon: 05[IKE] received retransmit of request with ID 0, retransmitting response
    Jul 13 10:32:56 vpn-ams charon: 05[NET] sending packet: from 10.18.0.5[4500] to <srx-ip-address>[4500] (92 bytes)
    Jul 13 10:33:06 vpn-ams charon: 13[IKE] sending keep alive to <srx-ip-address>[4500]
    Jul 13 10:33:06 vpn-ams charon: 12[NET] received packet: from <srx-ip-address>[4500] to 10.18.0.5[4500] (108 bytes)
    Jul 13 10:33:06 vpn-ams charon: 12[IKE] received retransmit of request with ID 0, retransmitting response
    Jul 13 10:33:06 vpn-ams charon: 12[NET] sending packet: from 10.18.0.5[4500] to <srx-ip-address>[4500] (92 bytes)

    Running 'show security ike sa' sometimes work and sometimes don't. This result appeared for a while after running 'restart ipsec-key-management', but would disappear after a while.

    namo@SRX220> show security ike sa            
    Index   State  Initiator cookie  Responder cookie  Mode           Remote Address   
    594712  DOWN   3064dc3314993733  0000000000000000  Main           <vpn-server-ip>  
    

     

    Any suggestions?

     



  • 2.  RE: IKE between SRX and StrongSwan keeps timing out

    Posted 07-13-2016 08:22

    Hi,

     

    From the output of the ike se, we can see that there is no responder cookie.

     

    This essentially means that the SRX not receiving the response from the StronSwan Server side.

     

    On the server you can see retransmits from the SRX which essentially means the same thing.

     

    Us the following command to see if we are receiving the response or not on the respective interface :-

     

    >monitor traffic interface <interface_number> matching "host 188.166.202.92"

     

    This would show th ike negotiation packets being sent out from the SRX as well as the response from the other side.

     

    Also check if you have any filters on the loopback or the external interface which could be bloakcing this traffic.

     

    Regards,

    Sahil Sharma

    ---------------------------------------------------

    Please mark my solution as accepted if it helped, Kudos are appreciated as well.



  • 3.  RE: IKE between SRX and StrongSwan keeps timing out

    Posted 07-13-2016 08:33

    I've tried adding the "ike" service to the host inbound traffic interface (pp0.0 in my case) and there seems to be a bit of progress. Listening on pp0.0 now results in this:

    15:16:47.943837  In IP 188.166.202.92.isakmp > <srx-dns-name>.isakmp: isakmp: phase 1 ? ident: [|sa]
    15:16:48.203853  In IP 188.166.202.92.isakmp > <srx-dns-name>.isakmp: isakmp: phase 1 ? ident: [|ke]
    15:16:48.450889  In IP 188.166.202.92.sae-urn > <srx-dns-name>.sae-urn: UDP, length 96
    15:16:48.706399  In IP 188.166.202.92.sae-urn > <srx-dns-name>.sae-urn: UDP, length 80

     

    StrongSwan's logs also changed. It now shows this:

     

    Jul 13 11:28:16 vpn-ams charon: 11[CFG] selected peer config "site2site"
    Jul 13 11:28:16 vpn-ams charon: 11[IKE] IKE_SA site2site[15] established between 10.18.0.5[<vpn-dns-name>]...<srx-ip-address>[<srx-dns-name>]
    Jul 13 11:28:16 vpn-ams charon: 11[IKE] scheduling reauthentication in 3374s
    Jul 13 11:28:16 vpn-ams charon: 11[IKE] maximum IKE_SA lifetime 3554s
    Jul 13 11:28:16 vpn-ams charon: 11[ENC] generating ID_PROT response 0 [ ID HASH ]
    Jul 13 11:28:16 vpn-ams charon: 11[NET] sending packet: from 10.18.0.5[4500] to <srx-ip-address>[4500] (92 bytes)
    Jul 13 11:28:16 vpn-ams charon: 05[NET] received packet: from <srx-ip-address>[4500] to 10.18.0.5[4500] (428 bytes)
    Jul 13 11:28:16 vpn-ams charon: 05[ENC] parsed QUICK_MODE request 3318862050 [ HASH SA No KE ID ID ]
    Jul 13 11:28:16 vpn-ams charon: 05[IKE] no matching CHILD_SA config found
    Jul 13 11:28:16 vpn-ams charon: 05[ENC] generating INFORMATIONAL_V1 request 1831077661 [ HASH N(INVAL_ID) ]
    

     

    Here's the ipsec.conf file, just in case:

    conn site2site
      ikelifetime=60m
      keylife=20m
      rekeymargin=3m
      keyingtries=1
      authby=secret
      keyexchange=ikev1
      mobike=no
      left=%any
      leftid=@<vpn-dns-name>
      auto=start
      right=%any
      rightid=%any
      rightdns=8.8.8.8,8.8.4.4
      rightsourceip=10.10.10.0/24

     

    Could this now be a phase 2 error in which the SRX can't get an IP address (or bind to a private IP address in the 10.10.10.0/24 subnet) on the server?

     



  • 4.  RE: IKE between SRX and StrongSwan keeps timing out

    Posted 07-13-2016 09:26

    Hi,

     

    Is the pp0 getting a dynamic IP address ?

     

    Is this VPN setup a dynamic VPN or a site to site ?

     

    Regards,

    Sahil



  • 5.  RE: IKE between SRX and StrongSwan keeps timing out

    Posted 07-13-2016 09:34

    pp0.0 gets a dynamic IP address from the ISP (ISP uses PPPoE, and unfortunately there's no way to get static IP for the SRX side).

     

    The VPN is intended to be a site-to-site VPN between the SRX (with dynamic IP) and the remote StrongSwan server (which has a static IP).

     

     



  • 6.  RE: IKE between SRX and StrongSwan keeps timing out

    Posted 07-13-2016 09:49

    Hi,

     

    In such a situation, are we using aggressive mode and are we the initiator for the VPN ?

     

    Regards

    Sahil



  • 7.  RE: IKE between SRX and StrongSwan keeps timing out

    Posted 07-13-2016 10:35

    The SRX is the initiator for the connection, and I'm using the "main" IKE mode. Using aggressive results in StrongSwan throwing a security exception:

     

    01[IKE] Aggressive Mode PSK disabled for security reasons

     

    And by the way, here's the SRX's configuration. First, the IKE stuff:

    [edit security ike]
    namo@SRX220# show 
    traceoptions {
        flag all;
    }
    proposal strongswan {
        authentication-method pre-shared-keys;
        dh-group group14;
        authentication-algorithm sha1;
        encryption-algorithm aes-128-cbc;
    }
    policy strongswan {
        mode main;
        description "Amsterdam VPN strongswan";
        proposals strongswan;
        pre-shared-key ascii-text "<redacted>"; ## SECRET-DATA
    }
    gateway gw-amsterdam-strongswan {
        ike-policy strongswan;
        address <vpn-server-ip>;
        local-identity hostname <srx-dns-name>;
        remote-identity inet <vpn-server-ip>;
        external-interface pp0.0;
        version v1-only;
    }                                       
           

     

    And the IPSec stuff:

    [edit security ipsec]
    namo@SRX220# show 
    traceoptions {
        flag all;
    }
    proposal strongswan {
        protocol esp;
        authentication-algorithm hmac-sha1-96;
        encryption-algorithm aes-128-cbc;
    }
    policy strongswan {
        perfect-forward-secrecy {
            keys group14;
        }
        proposals strongswan;
    }
    vpn vpn-amsterdam-strongswan {
        bind-interface st0.0;
        ike {
            gateway gw-amsterdam-strongswan;
            proxy-identity {
                local 10.100.0.0/16;
                remote 0.0.0.0/0;
            }
            ipsec-policy strongswan;
        }                                   
        establish-tunnels immediately;      
    }                                       
           

     

     



  • 8.  RE: IKE between SRX and StrongSwan keeps timing out

    Posted 07-13-2016 10:52

    Hi,

     

    The config on the SRX looks fine.

    Please check why the Server is throwing the error.

     

    Regards,

    Sahil Sharma

    ---------------------------------------------------

    Please mark my solution as accepted if it helped, Kudos are appreciated as well.



  • 9.  RE: IKE between SRX and StrongSwan keeps timing out

    Posted 07-13-2016 11:09

    Here's the full server log after running 'restart ipsec-key-management' on the SRX:

     

    Jul 13 13:58:07 vpn-ams charon: 02[NET] received packet: from <srx-ip-address>[500] to 10.18.0.5[500] (288 bytes)
    Jul 13 13:58:07 vpn-ams charon: 02[ENC] parsed ID_PROT request 0 [ SA V V V V V V V V V ]
    Jul 13 13:58:07 vpn-ams charon: 02[IKE] received DPD vendor ID
    Jul 13 13:58:07 vpn-ams charon: 02[IKE] received draft-stenberg-ipsec-nat-traversal-01 vendor ID
    Jul 13 13:58:07 vpn-ams charon: 02[IKE] received draft-stenberg-ipsec-nat-traversal-02 vendor ID
    Jul 13 13:58:07 vpn-ams charon: 02[IKE] received draft-ietf-ipsec-nat-t-ike-00 vendor ID
    Jul 13 13:58:07 vpn-ams charon: 02[IKE] received draft-ietf-ipsec-nat-t-ike-02 vendor ID
    Jul 13 13:58:07 vpn-ams charon: 02[IKE] received draft-ietf-ipsec-nat-t-ike-02\n vendor ID
    Jul 13 13:58:07 vpn-ams charon: 02[IKE] received draft-ietf-ipsec-nat-t-ike-03 vendor ID
    Jul 13 13:58:07 vpn-ams charon: 02[IKE] received NAT-T (RFC 3947) vendor ID
    Jul 13 13:58:07 vpn-ams charon: 02[ENC] received unknown vendor ID: 69:93:69:22:87:41:c6:d4:ca:09:4c:93:e2:42:c9:de:19:e7:b7:c6:00:00:00:05:00:00:05:00
    Jul 13 13:58:07 vpn-ams charon: 02[IKE] <srx-ip-address> is initiating a Main Mode IKE_SA
    Jul 13 13:58:07 vpn-ams charon: 02[ENC] generating ID_PROT response 0 [ SA V V V ]
    Jul 13 13:58:07 vpn-ams charon: 02[NET] sending packet: from 10.18.0.5[500] to <srx-ip-address>[500] (144 bytes)
    Jul 13 13:58:07 vpn-ams charon: 01[NET] received packet: from <srx-ip-address>[500] to 10.18.0.5[500] (356 bytes)
    Jul 13 13:58:07 vpn-ams charon: 01[ENC] parsed ID_PROT request 0 [ KE No NAT-D NAT-D ]
    Jul 13 13:58:07 vpn-ams charon: 01[IKE] local host is behind NAT, sending keep alives
    Jul 13 13:58:07 vpn-ams charon: 01[ENC] generating ID_PROT response 0 [ KE No NAT-D NAT-D ]
    Jul 13 13:58:07 vpn-ams charon: 01[NET] sending packet: from 10.18.0.5[500] to <srx-ip-address>[500] (372 bytes)
    Jul 13 13:58:07 vpn-ams charon: 12[NET] received packet: from <srx-ip-address>[4500] to 10.18.0.5[4500] (108 bytes)
    Jul 13 13:58:07 vpn-ams charon: 12[ENC] parsed ID_PROT request 0 [ ID HASH N(INITIAL_CONTACT) ]
    Jul 13 13:58:07 vpn-ams charon: 12[CFG] looking for pre-shared key peer configs matching 10.18.0.5...<srx-ip-address>[<srx-dns-name>]
    Jul 13 13:58:07 vpn-ams charon: 12[CFG] selected peer config "site2site"
    Jul 13 13:58:07 vpn-ams charon: 12[IKE] IKE_SA site2site[165] established between 10.18.0.5[<vpn-server-dns-name>]...<srx-ip-address>[<srx-dns-name>]
    Jul 13 13:58:07 vpn-ams charon: 12[IKE] scheduling reauthentication in 3357s
    Jul 13 13:58:07 vpn-ams charon: 12[IKE] maximum IKE_SA lifetime 3537s
    Jul 13 13:58:07 vpn-ams charon: 12[ENC] generating ID_PROT response 0 [ ID HASH ]
    Jul 13 13:58:07 vpn-ams charon: 12[NET] sending packet: from 10.18.0.5[4500] to <srx-ip-address>[4500] (92 bytes)
    Jul 13 13:58:08 vpn-ams charon: 15[NET] received packet: from <srx-ip-address>[4500] to 10.18.0.5[4500] (428 bytes)
    Jul 13 13:58:08 vpn-ams charon: 15[ENC] parsed QUICK_MODE request 884716036 [ HASH SA No KE ID ID ]
    Jul 13 13:58:08 vpn-ams charon: 15[IKE] no matching CHILD_SA config found
    Jul 13 13:58:08 vpn-ams charon: 15[ENC] generating INFORMATIONAL_V1 request 217035400 [ HASH N(INVAL_ID) ]
    Jul 13 13:58:08 vpn-ams charon: 15[NET] sending packet: from 10.18.0.5[4500] to <srx-ip-address>[4500] (76 bytes)
    Jul 13 13:58:08 vpn-ams charon: 13[NET] received packet: from <srx-ip-address>[4500] to 10.18.0.5[4500] (92 bytes)
    Jul 13 13:58:08 vpn-ams charon: 13[ENC] parsed INFORMATIONAL_V1 request 3592259046 [ HASH D ]
    Jul 13 13:58:08 vpn-ams charon: 13[IKE] received DELETE for IKE_SA site2site[165]
    Jul 13 13:58:08 vpn-ams charon: 13[IKE] deleting IKE_SA site2site[165] between 10.18.0.5[<vpn-server-dns-name>]...<srx-ip-address>[<srx-dns-name>]
    

    The issue seems to be around here:

    Jul 13 13:58:08 vpn-ams charon: 15[IKE] no matching CHILD_SA config found
    Jul 13 13:58:08 vpn-ams charon: 15[ENC] generating INFORMATIONAL_V1 request 217035400 [ HASH N(INVAL_ID) ]

    Anyway, I'll see if I can find out a bit more on why the server is throwing this error...

     

    EDIT: I've enabled charon debug and got this (which might have something to do with the error):

    Jul 13 14:24:03 vpn-ams charon: 13[ENC] parsed QUICK_MODE request 1364542533 [ HASH SA No KE ID ID ]
    Jul 13 14:24:03 vpn-ams charon: 13[CFG] looking for a child config for 0.0.0.0/0 === 10.100.0.0/16
    Jul 13 14:24:03 vpn-ams charon: 13[CFG] proposing traffic selectors for us:
    Jul 13 14:24:03 vpn-ams charon: 13[CFG]  10.18.0.5/32
    Jul 13 14:24:03 vpn-ams charon: 13[CFG] proposing traffic selectors for other:
    Jul 13 14:24:03 vpn-ams charon: 13[CFG]  dynamic
    Jul 13 14:24:03 vpn-ams charon: 13[IKE] no matching CHILD_SA config found

     



  • 10.  RE: IKE between SRX and StrongSwan keeps timing out

    Posted 07-13-2016 20:57

    Hi,

     

    Thanks for the additional outputs. The problem could be around here as well :-

     

    Jul 13 13:58:07 vpn-ams charon: 02[IKE] received NAT-T (RFC 3947) vendor ID
    Jul 13 13:58:07 vpn-ams charon: 02[ENC] received unknown vendor ID: 69:93:69:22:87:41:c6:d4:ca:09:4c:93:e2:42:c9:de:19:e7:b7:c6:00:00:00:05:00:00:05:00

    Looks like the server is not recognizing the SRX NAT-T Vendor ID and the communication needs to transition to port 4500 as there seems to be a Nat device in between.

     

    Please enable ike traceoptions on the SRX and provide the output :-

     

    #set security ike traceoptions file test1 size 2m
    #set security ike traceoptions flag all
    #commit
    >request security ike debug-enable local <SRX EXT IP Address> remote <Server IP Address> level 12

    After collecting the output, delete the traceoptions using :-

    #delete security ike traceoptions
    #commit

    Provide the output of the file test1 and we should see something in there.

     

    Regards,

    Sahil



  • 11.  RE: IKE between SRX and StrongSwan keeps timing out

    Posted 07-13-2016 21:30

    Alright, here's the content of "test1":

     

    [Jul 14 04:17:25]kmd_iked_cfgbuf_addrec: 535: ** Allocated recptr is 0, reclen = 161159148 **
    [Jul 14 04:17:25]kmd_iked_cfgbuf_addrec: 535: ** Allocated recptr is c, reclen = 161159148 **
    [Jul 14 04:17:25]Error:No such file or directory in deleting ike debug blob
    [Jul 14 04:17:25]kmd_iked_cfgbuf_addrec: 535: ** Allocated recptr is c58, reclen = 10748016 **
    [Jul 14 04:17:25]kmd_iked_cfgbuf_addrec: 535: ** Allocated recptr is 44, reclen = 10748016 **
    [Jul 14 04:17:25]Error: Unknown record, type = 25
    
    [Jul 14 04:17:25]kmd_iked_cfgbuf_addrec: 535: ** Allocated recptr is 44, reclen = 1073663016 **
    [Jul 14 04:17:25]kmd_iked_cfgbuf_addrec: 535: ** Allocated recptr is 41c, reclen = 1073663008 **
    [Jul 14 04:17:25]kmd_iked_cfgbuf_addrec: 535: ** Allocated recptr is 4, reclen = 4 **
    [Jul 14 04:17:25]kmd_iked_cfgbuf_addrec: 535: ** Allocated recptr is 44, reclen = 1073663024 **
    [Jul 14 04:17:25]kmd_iked_cfgbuf_addrec: 432: record IPSEC_SA_TYPE, reclen = 384 
    [Jul 14 04:17:25]kmd_iked_cfgbuf_addrec: 535: ** Allocated recptr is 180, reclen = 1073663024 **
    [Jul 14 04:17:25]kmd_iked_cfgbuf_addrec: 440: record TRAFFIC_SELECTOR, reclen = 172 
    [Jul 14 04:17:25]kmd_iked_cfgbuf_addrec: 535: ** Allocated recptr is ac, reclen = 145619660 **
    [Jul 14 04:17:25]kmd_iked_cfgbuf_addrec: 535: ** Allocated recptr is d0, reclen = 939524096 **
    [Jul 14 04:17:25]Deleting existing ipsec trace cfg with key: 1
    
    [Jul 14 04:17:25]iked_ipsec_trace_flag_update: Successfully added ipsec trace config with key 0x1
    [Jul 14 04:17:25]kmd_iked_cfgbuf_addrec: 535: ** Allocated recptr is 0, reclen = 0 **
    [Jul 14 04:17:25]No SPUs are operational, returning.
    [Jul 14 04:17:25]iked_spu_sync_config_add this is SEC ASSOC on RE/complete, add it to the list
    [Jul 14 04:17:25]Config download: Processed 1 - 2 messages
    [Jul 14 04:17:25]Config download time: 0 secs
    [Jul 14 04:17:25]iked_config_process_config_list, configuration diff complete
    [Jul 14 04:17:25]iked_pm_ike_spd_notify_request: Sending Initial contact
    [Jul 14 04:17:25]ssh_ike_connect: Start, remote_name = <vpn-server-ip-address>:500, xchg = 2, flags = 00090000
    [Jul 14 04:17:25]ike_sa_allocate: Start, SA = { 629db3b2 d66bfe49 - 00000000 00000000 }
    [Jul 14 04:17:25]ike_init_isakmp_sa: Start, remote = <vpn-server-ip-address>:500, initiator = 1
    [Jul 14 04:17:25]ssh_ike_connect: SA = { 629db3b2 d66bfe49 - 00000000 00000000}, nego = -1
    [Jul 14 04:17:25]ike_st_o_sa_proposal: Start
    [Jul 14 04:17:25]ike_policy_reply_isakmp_vendor_ids: Start
    [Jul 14 04:17:25]ike_st_o_private: Start
    [Jul 14 04:17:25]ike_policy_reply_private_payload_out: Start
    [Jul 14 04:17:25]ike_encode_packet: Start, SA = { 0x629db3b2 d66bfe49 - 00000000 00000000 } / 00000000, nego = -1
    [Jul 14 04:17:25]ike_send_packet: Start, send SA = { 629db3b2 d66bfe49 - 00000000 00000000}, nego = -1, local ip= <srx-ip-address>, dst = <vpn-server-ip-address>:500,  routing table id = 0
    [Jul 14 04:17:26]ikev2_packet_allocate: Allocated packet e40400 from freelist
    [Jul 14 04:17:26]ike_sa_find: Not found SA = { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc }
    [Jul 14 04:17:26]ikev2_packet_v1_start: Passing IKE v1.0 packet to IKEv1 library
    [Jul 14 04:17:26]ike_get_sa: Start, SA = { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc } / 00000000, remote = <vpn-server-ip-address>:500
    [Jul 14 04:17:26]ike_sa_find: Not found SA = { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc }
    [Jul 14 04:17:26]ike_sa_find_half: Found half SA = { 629db3b2 d66bfe49 - 00000000 00000000 }
    [Jul 14 04:17:26]ike_sa_upgrade: Start, SA = { 629db3b2 d66bfe49 - 00000000 00000000 } -> { ... - 5b5a9907 88ba74cc }
    [Jul 14 04:17:26]ike_decode_packet: Start
    [Jul 14 04:17:26]ike_decode_packet: Start, SA = { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc} / 00000000, nego = -1
    [Jul 14 04:17:26]ike_decode_payload_sa: Start
    [Jul 14 04:17:26]ike_decode_payload_t: Start, # trans = 1
    [Jul 14 04:17:26]ike_st_i_sa_value: Start
    [Jul 14 04:17:26]ike_st_i_cr: Start
    [Jul 14 04:17:26]ike_st_i_cert: Start
    [Jul 14 04:17:26]ike_st_i_vid: VID[0..8] = 09002689 dfd6b712 ...
    [Jul 14 04:17:26]ike_st_i_vid: VID[0..16] = afcad713 68a1f1c9 ...
    [Jul 14 04:17:26]ike_st_i_vid: VID[0..16] = 4a131c81 07035845 ...
    [Jul 14 04:17:26]ike_st_i_private: Start
    [Jul 14 04:17:26]ike_st_o_ke: Start
    [Jul 14 04:17:26]ike_st_o_nonce: Start
    [Jul 14 04:17:26]ike_policy_reply_isakmp_nonce_data_len: Start
    [Jul 14 04:17:26]ike_st_o_private: Start
    [Jul 14 04:17:26]ike_policy_reply_private_payload_out: Start
    [Jul 14 04:17:26]ike_policy_reply_private_payload_out: Start
    [Jul 14 04:17:26]ike_policy_reply_private_payload_out: Start
    [Jul 14 04:17:26]ike_encode_packet: Start, SA = { 0x629db3b2 d66bfe49 - 5b5a9907 88ba74cc } / 00000000, nego = -1
    [Jul 14 04:17:26]ike_send_packet: Start, send SA = { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc}, nego = -1, local ip= <srx-ip-address>, dst = <vpn-server-ip-address>:500,  routing table id = 0
    [Jul 14 04:17:26]ikev2_packet_allocate: Allocated packet e40800 from freelist
    [Jul 14 04:17:26]ike_sa_find: Found SA = { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc }
    [Jul 14 04:17:26]ikev2_packet_v1_start: Passing IKE v1.0 packet to IKEv1 library
    [Jul 14 04:17:26]ike_get_sa: Start, SA = { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc } / 00000000, remote = <vpn-server-ip-address>:500
    [Jul 14 04:17:26]ike_sa_find: Found SA = { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc }
    [Jul 14 04:17:26]ike_decode_packet: Start
    [Jul 14 04:17:26]ike_decode_packet: Start, SA = { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc} / 00000000, nego = -1
    [Jul 14 04:17:26]ike_st_i_nonce: Start, nonce[0..32] = 26023d47 1fcaf934 ...
    [Jul 14 04:17:26]ike_st_i_ke: Ke[0..256] = 5fe3f28f 1415883b ...
    [Jul 14 04:17:26]ike_st_i_cr: Start
    [Jul 14 04:17:26]ike_st_i_cert: Start
    [Jul 14 04:17:26]ike_st_i_private: Start
    [Jul 14 04:17:26]ike_st_o_id: Start
    [Jul 14 04:17:26]ike_st_o_hash: Start
    [Jul 14 04:17:26]ike_find_pre_shared_key: Find pre shared key key for <srx-ip-address>:500, id = fqdn(any:0,[0..10]=<srx-dns-name>) -> <vpn-server-ip-address>:500, id = No Id
    [Jul 14 04:17:26]ike_policy_reply_find_pre_shared_key: Start
    [Jul 14 04:17:26]ike_calc_mac: Start, initiator = true, local = true
    [Jul 14 04:17:26]ike_st_o_status_n: Start
    [Jul 14 04:17:26]ike_st_o_private: Start
    [Jul 14 04:17:26]ike_policy_reply_private_payload_out: Start
    [Jul 14 04:17:26]ike_st_o_encrypt: Marking encryption for packet
    [Jul 14 04:17:26]ike_encode_packet: Start, SA = { 0x629db3b2 d66bfe49 - 5b5a9907 88ba74cc } / 00000000, nego = -1
    [Jul 14 04:17:26]ike_send_packet: Start, send SA = { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc}, nego = -1, local ip= <srx-ip-address>, dst = <vpn-server-ip-address>:4500,  routing table id = 0
    [Jul 14 04:17:26]ikev2_packet_allocate: Allocated packet e40c00 from freelist
    [Jul 14 04:17:26]ike_sa_find: Found SA = { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc }
    [Jul 14 04:17:26]ikev2_packet_v1_start: Passing IKE v1.0 packet to IKEv1 library
    [Jul 14 04:17:26]ike_get_sa: Start, SA = { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc } / 00000000, remote = <vpn-server-ip-address>:4500
    [Jul 14 04:17:26]ike_sa_find: Found SA = { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc }
    [Jul 14 04:17:26]ike_decode_packet: Start
    [Jul 14 04:17:26]ike_decode_packet: Start, SA = { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc} / 00000000, nego = -1
    [Jul 14 04:17:26]ike_st_i_encrypt: Check that packet was encrypted succeeded
    [Jul 14 04:17:26]ike_st_i_id: Start
    [Jul 14 04:17:26]ike_st_i_hash: Start, hash[0..20] = 5529534d 299062e1 ...
    [Jul 14 04:17:26]ike_calc_mac: Start, initiator = true, local = false
    [Jul 14 04:17:26]ike_st_i_cert: Start
    [Jul 14 04:17:26]ike_st_i_private: Start
    [Jul 14 04:17:26]ike_st_o_wait_done: Marking for waiting for done
    [Jul 14 04:17:26]ike_st_o_all_done: MESSAGE: Phase 1 { 0x629db3b2 d66bfe49 - 0x5b5a9907 88ba74cc } / 00000000, version = 1.0, xchg = Identity protect, auth_method = Pre shared keys, Initiator, cipher = aes-cbc, hash = sha1, prf = hmac-sha1,
    [Jul 14 04:17:26]<srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc [-1] / 0x00000000 } IP; MESSAGE: Phase 1 version = 1.0, auth_method = Pre shared keys, cipher = aes-cbc, hash = sha1, prf = hmac
    [Jul 14 04:17:26]ike_send_notify: Connected, SA = { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc}, nego = -1
    [Jul 14 04:17:26]iked_pm_ike_sa_done: local:<srx-ip-address>, remote:<vpn-server-ip-address> IKEv1
    [Jul 14 04:17:26]iked_pm_id_validate id NOT matched.
    [Jul 14 04:17:26]Added (spi=0xbd5ed04, protocol=0) entry to the spi table
    [Jul 14 04:17:26]Added (spi=0x5513d2a, protocol=0) entry to the spi table
    [Jul 14 04:17:26]ssh_ike_connect_ipsec: Start, remote_name = :500, flags = 00010000
    [Jul 14 04:17:26]ike_alloc_negotiation: Start, SA = { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc}
    [Jul 14 04:17:26]ssh_ike_connect_ipsec: SA = { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc}, nego = 0
    [Jul 14 04:17:26]ike_init_qm_negotiation: Start, initiator = 1, message_id = cd5c1207
    [Jul 14 04:17:26]ike_st_o_qm_hash_1: Start
    [Jul 14 04:17:26]ike_st_o_qm_sa_proposals: Start
    [Jul 14 04:17:26]ike_st_o_qm_nonce: Start
    [Jul 14 04:17:26]ike_policy_reply_qm_nonce_data_len: Start
    [Jul 14 04:17:26]ike_st_o_qm_optional_ke: Start
    [Jul 14 04:17:26]ike_st_o_qm_optional_ids: Start
    [Jul 14 04:17:26]ike_st_qm_optional_id: Start
    [Jul 14 04:17:26]ike_st_qm_optional_id: Start
    [Jul 14 04:17:26]ike_st_o_private: Start
    [Jul 14 04:17:26]Construction NHTB payload for  local:<srx-ip-address>, remote:<vpn-server-ip-address> IKEv1 P1 SA index 6384394 sa-cfg vpn-amsterdam-strongswan
    [Jul 14 04:17:26]Peer router vendor is not Juniper. Not sending NHTB payload for sa-cfg vpn-amsterdam-strongswan, p1_sa=6384394 
    [Jul 14 04:17:26]ike_policy_reply_private_payload_out: Start
    [Jul 14 04:17:26]ike_st_o_encrypt: Marking encryption for packet
    [Jul 14 04:17:26]ike_encode_packet: Start, SA = { 0x629db3b2 d66bfe49 - 5b5a9907 88ba74cc } / cd5c1207, nego = 0
    [Jul 14 04:17:26]ike_finalize_qm_hash_1: Hash[0..20] = 2192b78b d8ac19fc ...
    [Jul 14 04:17:26]ike_send_packet: Start, send SA = { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc}, nego = 0, local ip= <srx-ip-address>, dst = <vpn-server-ip-address>:4500,  routing table id = 0
    [Jul 14 04:17:26]P1 SA 6384394 timer expiry. ref cnt 2, timer reason Defer delete timer expired (3), flags 0x110.
    [Jul 14 04:17:26]iked_pm_ike_sa_delete_notify_done_cb: For p1 sa index 6384394, ref cnt 2, status: Error ok
    [Jul 14 04:17:26]ike_expire_callback: Start, expire SA = { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc}, nego = -1
    [Jul 14 04:17:26]ike_alloc_negotiation: Start, SA = { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc}
    [Jul 14 04:17:26]ike_encode_packet: Start, SA = { 0x629db3b2 d66bfe49 - 5b5a9907 88ba74cc } / 3798b363, nego = 1
    [Jul 14 04:17:26]ike_send_packet: Start, send SA = { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc}, nego = 1, local ip= <srx-ip-address>, dst = <vpn-server-ip-address>:4500,  routing table id = 0
    [Jul 14 04:17:26]ike_delete_negotiation: Start, SA = { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc}, nego = 1
    [Jul 14 04:17:26]ike_free_negotiation_info: Start, nego = 1
    [Jul 14 04:17:26]ike_free_negotiation: Start, nego = 1
    [Jul 14 04:17:26]ike_remove_callback: Start, delete SA = { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc}, nego = -1
    [Jul 14 04:17:26]ike_delete_negotiation: Start, SA = { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc}, nego = -1
    [Jul 14 04:17:26]ssh_ike_tunnel_table_entry_delete: Deleting tunnel_id: 0 from IKE tunnel table
    [Jul 14 04:17:26]ssh_ike_tunnel_table_entry_delete: The tunnel id: 0 doesn't exist in IKE tunnel table
    [Jul 14 04:17:26]ike_sa_delete: Start, SA = { 629db3b2 d66bfe49 - 5b5a9907 88ba74cc }
    [Jul 14 04:17:26]ike_free_negotiation_qm: Start, nego = 0
    [Jul 14 04:17:26]ike_free_negotiation: Start, nego = 0
    [Jul 14 04:17:26]ike_free_id_payload: Start, id type = 4
    [Jul 14 04:17:26]ike_free_id_payload: Start, id type = 4
    [Jul 14 04:17:26]ike_free_negotiation_isakmp: Start, nego = -1
    [Jul 14 04:17:26]ike_free_negotiation: Start, nego = -1
    [Jul 14 04:17:26]IKE SA delete called for p1 sa 6384394 (ref cnt 2) local:<srx-ip-address>, remote:<vpn-server-ip-address>, IKEv1 
    [Jul 14 04:17:26]P1 SA 6384394 reference count is not zero (1). Delaying deletion of SA
    [Jul 14 04:17:26]ike_free_id_payload: Start, id type = 2
    [Jul 14 04:17:26]ike_free_id_payload: Start, id type = 2
    [Jul 14 04:17:26]ike_free_sa: Start
    [Jul 14 04:17:26]iked_pm_p1_sa_destroy:  p1 sa 6384394 (ref cnt 0), waiting_for_del 0xe03460
    [Jul 14 04:17:26]iked_deferred_free_inactive_peer_entry: Free 1 peer_entry(s)
    [Jul 14 04:17:36]iked_pm_ike_spd_notify_request: Sending Initial contact
    [Jul 14 04:17:36]ssh_ike_connect: Start, remote_name = <vpn-server-ip-address>:500, xchg = 2, flags = 00090000
    [Jul 14 04:17:36]ike_sa_allocate: Start, SA = { 6e438568 477ec276 - 00000000 00000000 }
    [Jul 14 04:17:36]ike_init_isakmp_sa: Start, remote = <vpn-server-ip-address>:500, initiator = 1
    [Jul 14 04:17:36]ssh_ike_connect: SA = { 6e438568 477ec276 - 00000000 00000000}, nego = -1
    [Jul 14 04:17:36]ike_st_o_sa_proposal: Start
    [Jul 14 04:17:36]ike_policy_reply_isakmp_vendor_ids: Start
    [Jul 14 04:17:36]ike_st_o_private: Start
    [Jul 14 04:17:36]ike_policy_reply_private_payload_out: Start
    [Jul 14 04:17:36]ike_encode_packet: Start, SA = { 0x6e438568 477ec276 - 00000000 00000000 } / 00000000, nego = -1
    [Jul 14 04:17:36]ike_send_packet: Start, send SA = { 6e438568 477ec276 - 00000000 00000000}, nego = -1, local ip= <srx-ip-address>, dst = <vpn-server-ip-address>:500,  routing table id = 0
    [Jul 14 04:17:36]ikev2_packet_allocate: Allocated packet e41000 from freelist
    [Jul 14 04:17:36]ike_sa_find: Not found SA = { 6e438568 477ec276 - 488e3b61 b2fc1a47 }
    [Jul 14 04:17:36]ikev2_packet_v1_start: Passing IKE v1.0 packet to IKEv1 library
    [Jul 14 04:17:36]ike_get_sa: Start, SA = { 6e438568 477ec276 - 488e3b61 b2fc1a47 } / 00000000, remote = <vpn-server-ip-address>:500
    [Jul 14 04:17:36]ike_sa_find: Not found SA = { 6e438568 477ec276 - 488e3b61 b2fc1a47 }
    [Jul 14 04:17:36]ike_sa_find_half: Found half SA = { 6e438568 477ec276 - 00000000 00000000 }
    [Jul 14 04:17:36]ike_sa_upgrade: Start, SA = { 6e438568 477ec276 - 00000000 00000000 } -> { ... - 488e3b61 b2fc1a47 }
    [Jul 14 04:17:36]ike_decode_packet: Start
    [Jul 14 04:17:36]ike_decode_packet: Start, SA = { 6e438568 477ec276 - 488e3b61 b2fc1a47} / 00000000, nego = -1
    [Jul 14 04:17:36]ike_decode_payload_sa: Start
    [Jul 14 04:17:36]ike_decode_payload_t: Start, # trans = 1
    [Jul 14 04:17:36]ike_st_i_sa_value: Start
    [Jul 14 04:17:36]ike_st_i_cr: Start
    [Jul 14 04:17:36]ike_st_i_cert: Start
    [Jul 14 04:17:36]ike_st_i_vid: VID[0..8] = 09002689 dfd6b712 ...
    [Jul 14 04:17:36]ike_st_i_vid: VID[0..16] = afcad713 68a1f1c9 ...
    [Jul 14 04:17:36]ike_st_i_vid: VID[0..16] = 4a131c81 07035845 ...
    [Jul 14 04:17:36]ike_st_i_private: Start
    [Jul 14 04:17:36]ike_st_o_ke: Start
    [Jul 14 04:17:36]ike_st_o_nonce: Start
    [Jul 14 04:17:36]ike_policy_reply_isakmp_nonce_data_len: Start
    [Jul 14 04:17:36]ike_st_o_private: Start
    [Jul 14 04:17:36]ike_policy_reply_private_payload_out: Start
    [Jul 14 04:17:36]ike_policy_reply_private_payload_out: Start
    [Jul 14 04:17:36]ike_policy_reply_private_payload_out: Start
    [Jul 14 04:17:36]ike_encode_packet: Start, SA = { 0x6e438568 477ec276 - 488e3b61 b2fc1a47 } / 00000000, nego = -1
    [Jul 14 04:17:36]ike_send_packet: Start, send SA = { 6e438568 477ec276 - 488e3b61 b2fc1a47}, nego = -1, local ip= <srx-ip-address>, dst = <vpn-server-ip-address>:500,  routing table id = 0
    [Jul 14 04:17:37]ikev2_packet_allocate: Allocated packet e41400 from freelist
    [Jul 14 04:17:37]ike_sa_find: Found SA = { 6e438568 477ec276 - 488e3b61 b2fc1a47 }
    [Jul 14 04:17:37]ikev2_packet_v1_start: Passing IKE v1.0 packet to IKEv1 library
    [Jul 14 04:17:37]ike_get_sa: Start, SA = { 6e438568 477ec276 - 488e3b61 b2fc1a47 } / 00000000, remote = <vpn-server-ip-address>:500
    [Jul 14 04:17:37]ike_sa_find: Found SA = { 6e438568 477ec276 - 488e3b61 b2fc1a47 }
    [Jul 14 04:17:37]ike_decode_packet: Start
    [Jul 14 04:17:37]ike_decode_packet: Start, SA = { 6e438568 477ec276 - 488e3b61 b2fc1a47} / 00000000, nego = -1
    [Jul 14 04:17:37]ike_st_i_nonce: Start, nonce[0..32] = e886988f 3c945522 ...
    [Jul 14 04:17:37]ike_st_i_ke: Ke[0..256] = 35e1c8d5 c8ba70fc ...
    [Jul 14 04:17:37]ike_st_i_cr: Start
    [Jul 14 04:17:37]ike_st_i_cert: Start
    [Jul 14 04:17:37]ike_st_i_private: Start
    [Jul 14 04:17:37]ike_st_o_id: Start
    [Jul 14 04:17:37]ike_st_o_hash: Start
    [Jul 14 04:17:37]ike_find_pre_shared_key: Find pre shared key key for <srx-ip-address>:500, id = fqdn(any:0,[0..10]=<srx-dns-name>) -> <vpn-server-ip-address>:500, id = No Id
    [Jul 14 04:17:37]ike_policy_reply_find_pre_shared_key: Start
    [Jul 14 04:17:37]ike_calc_mac: Start, initiator = true, local = true
    [Jul 14 04:17:37]ike_st_o_status_n: Start
    [Jul 14 04:17:37]ike_st_o_private: Start
    [Jul 14 04:17:37]ike_policy_reply_private_payload_out: Start
    [Jul 14 04:17:37]ike_st_o_encrypt: Marking encryption for packet
    [Jul 14 04:17:37]ike_encode_packet: Start, SA = { 0x6e438568 477ec276 - 488e3b61 b2fc1a47 } / 00000000, nego = -1
    [Jul 14 04:17:37]ike_send_packet: Start, send SA = { 6e438568 477ec276 - 488e3b61 b2fc1a47}, nego = -1, local ip= <srx-ip-address>, dst = <vpn-server-ip-address>:4500,  routing table id = 0
    [Jul 14 04:17:37]ikev2_packet_allocate: Allocated packet e41800 from freelist
    [Jul 14 04:17:37]ike_sa_find: Found SA = { 6e438568 477ec276 - 488e3b61 b2fc1a47 }
    [Jul 14 04:17:37]ikev2_packet_v1_start: Passing IKE v1.0 packet to IKEv1 library
    [Jul 14 04:17:37]ike_get_sa: Start, SA = { 6e438568 477ec276 - 488e3b61 b2fc1a47 } / 00000000, remote = <vpn-server-ip-address>:4500
    [Jul 14 04:17:37]ike_sa_find: Found SA = { 6e438568 477ec276 - 488e3b61 b2fc1a47 }
    [Jul 14 04:17:37]ike_decode_packet: Start
    [Jul 14 04:17:37]ike_decode_packet: Start, SA = { 6e438568 477ec276 - 488e3b61 b2fc1a47} / 00000000, nego = -1
    [Jul 14 04:17:37]ike_st_i_encrypt: Check that packet was encrypted succeeded
    [Jul 14 04:17:37]ike_st_i_id: Start
    [Jul 14 04:17:37]ike_st_i_hash: Start, hash[0..20] = 0c1f0b58 d45e1d1d ...
    [Jul 14 04:17:37]ike_calc_mac: Start, initiator = true, local = false
    [Jul 14 04:17:37]ike_st_i_cert: Start
    [Jul 14 04:17:37]ike_st_i_private: Start
    [Jul 14 04:17:37]ike_st_o_wait_done: Marking for waiting for done
    [Jul 14 04:17:37]ike_st_o_all_done: MESSAGE: Phase 1 { 0x6e438568 477ec276 - 0x488e3b61 b2fc1a47 } / 00000000, version = 1.0, xchg = Identity protect, auth_method = Pre shared keys, Initiator, cipher = aes-cbc, hash = sha1, prf = hmac-sha1,
    [Jul 14 04:17:37]<srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { 6e438568 477ec276 - 488e3b61 b2fc1a47 [-1] / 0x00000000 } IP; MESSAGE: Phase 1 version = 1.0, auth_method = Pre shared keys, cipher = aes-cbc, hash = sha1, prf = hmac
    [Jul 14 04:17:37]ike_send_notify: Connected, SA = { 6e438568 477ec276 - 488e3b61 b2fc1a47}, nego = -1
    [Jul 14 04:17:37]iked_pm_ike_sa_done: local:<srx-ip-address>, remote:<vpn-server-ip-address> IKEv1
    [Jul 14 04:17:37]iked_pm_id_validate id NOT matched.
    [Jul 14 04:17:37]Added (spi=0x6302b9d2, protocol=0) entry to the spi table
    [Jul 14 04:17:37]Added (spi=0xefd79302, protocol=0) entry to the spi table
    [Jul 14 04:17:37]ssh_ike_connect_ipsec: Start, remote_name = :500, flags = 00010000
    [Jul 14 04:17:37]ike_alloc_negotiation: Start, SA = { 6e438568 477ec276 - 488e3b61 b2fc1a47}
    [Jul 14 04:17:37]ssh_ike_connect_ipsec: SA = { 6e438568 477ec276 - 488e3b61 b2fc1a47}, nego = 0
    [Jul 14 04:17:37]ike_init_qm_negotiation: Start, initiator = 1, message_id = 6c7e2ebc
    [Jul 14 04:17:37]ike_st_o_qm_hash_1: Start
    [Jul 14 04:17:37]ike_st_o_qm_sa_proposals: Start
    [Jul 14 04:17:37]ike_st_o_qm_nonce: Start
    [Jul 14 04:17:37]ike_policy_reply_qm_nonce_data_len: Start
    [Jul 14 04:17:37]ike_st_o_qm_optional_ke: Start
    [Jul 14 04:17:37]ike_st_o_qm_optional_ids: Start
    [Jul 14 04:17:37]ike_st_qm_optional_id: Start
    [Jul 14 04:17:37]ike_st_qm_optional_id: Start
    [Jul 14 04:17:37]ike_st_o_private: Start
    [Jul 14 04:17:37]Construction NHTB payload for  local:<srx-ip-address>, remote:<vpn-server-ip-address> IKEv1 P1 SA index 6384395 sa-cfg vpn-amsterdam-strongswan
    [Jul 14 04:17:37]Peer router vendor is not Juniper. Not sending NHTB payload for sa-cfg vpn-amsterdam-strongswan, p1_sa=6384395 
    [Jul 14 04:17:37]ike_policy_reply_private_payload_out: Start
    [Jul 14 04:17:37]ike_st_o_encrypt: Marking encryption for packet
    [Jul 14 04:17:37]ike_encode_packet: Start, SA = { 0x6e438568 477ec276 - 488e3b61 b2fc1a47 } / 6c7e2ebc, nego = 0
    [Jul 14 04:17:37]ike_finalize_qm_hash_1: Hash[0..20] = 0913242b 2241f7e0 ...
    [Jul 14 04:17:37]ike_send_packet: Start, send SA = { 6e438568 477ec276 - 488e3b61 b2fc1a47}, nego = 0, local ip= <srx-ip-address>, dst = <vpn-server-ip-address>:4500,  routing table id = 0
    [Jul 14 04:17:37]P1 SA 6384395 timer expiry. ref cnt 2, timer reason Defer delete timer expired (3), flags 0x110.
    [Jul 14 04:17:37]iked_pm_ike_sa_delete_notify_done_cb: For p1 sa index 6384395, ref cnt 2, status: Error ok
    [Jul 14 04:17:37]ike_expire_callback: Start, expire SA = { 6e438568 477ec276 - 488e3b61 b2fc1a47}, nego = -1
    [Jul 14 04:17:37]ike_alloc_negotiation: Start, SA = { 6e438568 477ec276 - 488e3b61 b2fc1a47}
    [Jul 14 04:17:37]ike_encode_packet: Start, SA = { 0x6e438568 477ec276 - 488e3b61 b2fc1a47 } / ecf4fdc7, nego = 1
    [Jul 14 04:17:37]ike_send_packet: Start, send SA = { 6e438568 477ec276 - 488e3b61 b2fc1a47}, nego = 1, local ip= <srx-ip-address>, dst = <vpn-server-ip-address>:4500,  routing table id = 0
    [Jul 14 04:17:37]ike_delete_negotiation: Start, SA = { 6e438568 477ec276 - 488e3b61 b2fc1a47}, nego = 1
    [Jul 14 04:17:37]ike_free_negotiation_info: Start, nego = 1
    [Jul 14 04:17:37]ike_free_negotiation: Start, nego = 1
    [Jul 14 04:17:37]ike_remove_callback: Start, delete SA = { 6e438568 477ec276 - 488e3b61 b2fc1a47}, nego = -1
    [Jul 14 04:17:37]ike_delete_negotiation: Start, SA = { 6e438568 477ec276 - 488e3b61 b2fc1a47}, nego = -1
    [Jul 14 04:17:37]ssh_ike_tunnel_table_entry_delete: Deleting tunnel_id: 0 from IKE tunnel table
    [Jul 14 04:17:37]ssh_ike_tunnel_table_entry_delete: The tunnel id: 0 doesn't exist in IKE tunnel table
    [Jul 14 04:17:37]ike_sa_delete: Start, SA = { 6e438568 477ec276 - 488e3b61 b2fc1a47 }
    [Jul 14 04:17:37]ike_free_negotiation_qm: Start, nego = 0
    [Jul 14 04:17:37]ike_free_negotiation: Start, nego = 0
    [Jul 14 04:17:37]ike_free_id_payload: Start, id type = 4
    [Jul 14 04:17:37]ike_free_id_payload: Start, id type = 4
    [Jul 14 04:17:37]ike_free_negotiation_isakmp: Start, nego = -1
    [Jul 14 04:17:37]ike_free_negotiation: Start, nego = -1
    [Jul 14 04:17:37]IKE SA delete called for p1 sa 6384395 (ref cnt 2) local:<srx-ip-address>, remote:<vpn-server-ip-address>, IKEv1 
    [Jul 14 04:17:37]P1 SA 6384395 reference count is not zero (1). Delaying deletion of SA
    [Jul 14 04:17:37]ike_free_id_payload: Start, id type = 2
    [Jul 14 04:17:37]ike_free_id_payload: Start, id type = 2
    [Jul 14 04:17:37]ike_free_sa: Start
    [Jul 14 04:17:37]iked_pm_p1_sa_destroy:  p1 sa 6384395 (ref cnt 0), waiting_for_del 0xe78a60
    [Jul 14 04:17:37]iked_deferred_free_inactive_peer_entry: Free 1 peer_entry(s)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  Inside iked_get_primary_addr_by_intf_name... AF = 2
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]    iked_get_primary_addr_by_intf_name:2421 intf_name pp0.0, af=inet, addr_len=4 
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]    iked_get_primary_addr_by_intf_name:2425 ip address = <srx-ip-address> ifam_flags = 0xd0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  Got address <srx-ip-address> as prefered address for interface pp0.0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_cfg_populate_sa_cfg_with_ike_gateway_info: Found ip address for local interface <srx-ip-address>
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_config_stage_update_and_activate: Activating route-based sa_cfg vpn-amsterdam-strongswan
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_cfg_activate_route_based_sa_cfg: called
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_cfg_activate_route_based_sa_cfg Set this sa_cfg as INSTANCE
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  In iked_ipsec_is_ifl_installed for sa_cfg vpn-amsterdam-strongswan
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_ipsec_is_ifl_installed: Bind interface st0.0 index<70>
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  In iked_ipsec_is_ifl_installed if:pp0 
    
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_sa_cfg_set_local_if_zone_id: Getting zone for If: pp0.0;
    
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_iface2zone: Returning zone = 7 for if: pp0.0
    
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_sa_cfg_set_local_if_zone_id: Changing zone of ifl pp0.0 from 65535 -> 7
    
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_sa_cfg_set_local_if_zone_id: Got Zone - If: pp0.0; Zone: 7
    
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_iface2zone: Returning zone = 16 for if: st0.0
    
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_ipsec_is_ifl_installed: Bind interface st0.0, index<70>, IFL ext is up
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_ipsec_is_ifl_installed: Updating IFA for sa_cfg vpn-amsterdam-strongswan gateway gw-amsterdam-strongswan
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]    SA CFG Name: vpn-amsterdam-strongswan
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]    Interface name: pp0, Unit: 0, AF: 2, ksa_cfg_ifl_index: 82
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]    Local gateway: <srx-ip-address> 
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]    Remote gateway: <vpn-server-ip-address> 
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  Inside iked_get_primary_addr_by_intf_name... AF = 2
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]    iked_get_primary_addr_by_intf_name:2421 intf_name pp0.0, af=inet, addr_len=4 
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]    iked_get_primary_addr_by_intf_name:2425 ip address = <srx-ip-address> ifam_flags = 0xd0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  Got address <srx-ip-address> as prefered address for interface pp0.0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_ipsec_is_ifl_installed: Found ip address for external interface <srx-ip-address>. Marking sa-cfg vpn-amsterdam-strongswan as ifa up
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_check_if_sa_cfg_ready: SA-CFG is ready
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  Added sa_cfg vpn-amsterdam-strongswan to sadb hash tbl at hash:1250
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_sa_cfg_get_parent_sa_cfg_child_sas_count No parent for sa_cfg vpn-amsterdam-strongswan count is 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_is_anchoring_instance sa_dist_id=0, self_dist_id=255
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  (iked_is_anchoring_instance): This is ANCHORING instance
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_deactivate_bind_interface: No more NHTB entries are active for st0.0. Bringing down the interface
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  kmd_update_tunnel_interface: update ifl st0.0 status DOWN for sa_cfg vpn-amsterdam-strongswan
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  In iked_ipsec_sa_config_add: if:pp0 flags = 0x600a29 UP
    
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  In iked_fill_sa_bundle
    
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  vpn-amsterdam-strongswan : VPN Monitor Interval=0(0) Optimized=0(0)
    
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_lookup_peer_entry: Peer entry 0x0 Not FOUND for local <srx-ip-address>:500 and remote <vpn-server-ip-address>:0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_fill_sa_bundle : DPD Interval=0
    
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  SA bundle remote gateway: IP <vpn-server-ip-address> chosen
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  SA bundle local  gateway: IP <srx-ip-address> chosen
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  Installing SA vpn-amsterdam-strongswan (mode: tunnel) tunnel ID 131073 to kernel
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ----------------Voyager ipsec SA BUNDLE-------------------
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  SA Config add request for:   Tunnel index: 131073
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      Local Gateway address: <srx-ip-address>
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      Primary remote Gateway address: <vpn-server-ip-address>
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      Backup remote Gateway State: Active
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]   Anti replay: counter-based enabled
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]   Window_size: 64
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]   Server Time: 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]   Peer : Static
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]   Mode : Tunnel
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]   VPN Type : route-based
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      Tunnel mtu: 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      DF bit: 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      local-if ifl idx: 82
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      tunnel-if ifl idx: 70
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      Tunnel mtu: 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      DPD interval: 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      policy id: 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      NATT enabled: 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      NATT version: 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      NAT position: 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      SA Idle time: 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      SA Outbound install delay time: 1
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      IKED ID: 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      DIST ID: 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      Keepalive interval: 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      VPN monitoring interval: 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      VPN monitoring optimized: 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      Respond-bad-SPI: 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      seq_out: 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      Local port: 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      Remote port: 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      SA CFG name: vpn-amsterdam-strongswan
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      Dial-up IKE ID: 
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      RG ID: 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]      Group template tunnel ID: 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  In iked_sa_config_install Adding GENCFG msg with key; Tunnel = 131073, SPI-In = 0x0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_sa_config_install msg_len=688
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  Successfully added SA Config
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_sa_cfg_get_parent_sa_cfg_child_sas_count No parent for sa_cfg vpn-amsterdam-strongswan count is 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_set_bind_interface_nhtb_status: sa-cfg vpn-amsterdam-strongswan sa count is zero, bringing down st0.0 as VPN Monitor or establish immediately is configured
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_deactivate_bind_interface: No more NHTB entries are active for st0.0. Bringing down the interface
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  kmd_update_tunnel_interface: update ifl st0.0 status DOWN for sa_cfg vpn-amsterdam-strongswan
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_is_anchoring_instance sa_dist_id=0, self_dist_id=255
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  (iked_is_anchoring_instance): This is ANCHORING instance
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_stop_vpnm_timer: processing SA vpn-amsterdam-strongswan
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_lookup_peer_entry: Peer entry 0x0 Not FOUND for local <srx-ip-address>:500 and remote <vpn-server-ip-address>:0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  Triggering negotiation for vpn-amsterdam-strongswan config block
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_trigger_callback: lookup peer entry for gateway gw-amsterdam-strongswan, local_port=500, remote_port=500
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_lookup_peer_entry: Peer entry 0x0 Not FOUND for local <srx-ip-address>:500 and remote <vpn-server-ip-address>:500
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_create_peer_entry: Created peer entry 0xeed800 for local <srx-ip-address>:500 remote <vpn-server-ip-address>:500
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_fetch_or_create_peer_entry: Create peer entry 0xeed800 for local <srx-ip-address>:500 remote <vpn-server-ip-address>:500. gw gw-amsterdam-strongswan, VR id 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_dist_table_entry_update : Dist table entry creation not needed
    
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_trigger_callback: FOUND peer entry for gateway gw-amsterdam-strongswan
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  Initiating new P1 SA for gateway gw-amsterdam-strongswan
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ikev2_ike_sa_allocate: Allocating IKE SA <vpn-server-ip-address>;500/4500
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  chassis 0 fpc 0 pic 0 kmd-instance 0
    current tunnel id 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  Allocated IKE SA index 310166, ref cnt 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  P1 SA 310166 start timer. timer duration 30, reason 1.
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_ike_sa_alloc_cb: Allocated IKE SA eeb400 Iae0c09cd 0cfc3bf8 (<vpn-server-ip-address>;500/4500)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_udp_window_init: Allocating transmission windows for SA eeb400
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_allocate_exchange_data: Calling exchange_data_alloc
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_ike_exchange_data_alloc: Successfully inserted pm_ed eede00 into list for sa_cfg N/A
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  Exchange data allocated for IKE SA 310166. VR 65535
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_allocate_exchange_data: Successfully allocated exchange data for SA eeb400
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ikev2_ipsec_create_sa: State = IKE_INIT_SA
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_allocate_exchange_data_ike: Allocating IKE exchange data for SA eeb400 ED ef0028
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_allocate_exchange_data_ike: Successfully allocated IKE exchange data for SA eeb400 ED ef0028
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_allocate_exchange_data_ipsec: Allocating IPsec exchange data for SA eeb400 ED ef0028
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_allocate_exchange_data_ipsec: Successfully allocated IPsec exchange data for SA eeb400 ED ef0028
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ikev2_ike_sa_take_ref: Calling ike_sa_take_ref
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  Taking reference to P1 SA 310166 to ref count 1
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_trigger_negotiation Set p2_ed in sa_cfg=vpn-amsterdam-strongswan
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_peer_insert_p1sa_entry: Insert p1 sa 310166 in peer entry 0xeed800
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_trigger_negotiation Convert traffic selectors from V1 format to V2 format for narrowing/matching selectors
    
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ikev2_ts_allocate: Allocated ts 0xe78a20, ref_cnt 1
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ikev2_ts_allocate: Allocated ts 0xe78a40, ref_cnt 1
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fallback_negotiation_alloc: Taking reference to fallback negotiation eef800 (now 1 references)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fallback_negotiation_alloc: Allocated fallback negotiation eef800
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ikev2_ike_sa_take_ref: Calling ike_sa_take_ref
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  Taking reference to P1 SA 310166 to ref count 2
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_set_thread_debug_info: ikev2_fb_initiate_ipsec_sa: set thread debug info - local <srx-ip-address> remote <vpn-server-ip-address> neg 0xeef800 neg->ike_sa 0xeeb400 ike_sa 0x0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  Attach ed ef0028 to P1 SA 310166, slot 0. op handle ef02a0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_reference_exchange_data: Taking reference to exchange data ef0028 (to 2)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ikev2_ts_free: ts 0xe78a20, ref_cnt 2
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ikev2_ts_free: ts 0xe78a40, ref_cnt 2
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_i_p1_negotiation_start: Taking reference to fallback negotiation eef800 (now 2 references)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_set_thread_debug_info: ikev2_fb_i_p1_negotiation_start: set thread debug info - local <srx-ip-address> remote <vpn-server-ip-address> neg 0xeef800 neg->ike_sa 0xeeb400 ike_sa 0x0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_st_i_ike_local_address_request: FB; Calling v2 policy function get_local_address_list
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_st_i_ike_id_request: FB; Calling v2 policy function id
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_id_request_cb: Local id payload is ID(type = fqdn (2), len = 11, value = <srx-dns-name>)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_idv2_to_idv1: Converting the IKEv2 payload ID ID(type = fqdn (2), len = 11, value = <srx-dns-name>) to IKEv1 ID
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_idv2_to_idv1: IKEv2 payload ID converted to IKEv1 payload ID fqdn(any:0,[0..10]=<srx-dns-name>)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_st_i_ike_notify_request: FB; Calling v2 policy function notify_request
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  Parsing notification payload for local:<srx-ip-address>, remote:<vpn-server-ip-address> IKEv1 
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_ike_spd_notify_request: Sending Initial contact
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_st_i_ike_psk_request: FB; Calling v2 policy function shared_key
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_ike_pre_shared_key Start...
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_id_validate NO remote ID, skip validation.
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_find_pre_shared_key_cb: Found preshared key
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_st_i_ike_sa_request: FB; Calling v2 policy function fill_ike_sa
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  IKE SA fill called for negotiation of local:<srx-ip-address>, remote:<vpn-server-ip-address> IKEv1 
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  Initiator's proposing IKE SA payload SA()
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_st_i_conf_request: FB; Calling v2 policy function conf_request
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fallback_negotiation_free: Fallback negotiation eef800 has still 1 references
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_i_p1_negotiation_negotiate: Sending Initial Contact notification
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_i_p1_negotiation_negotiate: Taking reference to fallback negotiation eef800 (now 2 references)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_connect: Start, remote_name = <vpn-server-ip-address>:500, xchg = 2, flags = 00090000
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_sa_allocate_half: Start
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_sa_allocate: Start, SA = { ae0c09cd 0cfc3bf8 - 00000000 00000000 }
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_init_isakmp_sa: Start, remote = <vpn-server-ip-address>:500, initiator = 1
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; SA: Number of proposals = 1
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; SA[0]: Number of protocols = 1
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; SA[0][0]: Number of transforms = 1
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; SA[0][0][0]: ISAKMP protocol
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 1 (0x0001), value = 7 (0x00000007), len = 2 (0x0002)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Encryption alg = 7 (aes-cbc)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 14 (0x000e), value = 256 (0x00000100), len = 2 (0x0002)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Key length = 256
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 4 (0x0004), value = 14 (0x0000000e), len = 2 (0x0002)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Group = 14, ec7070
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 2 (0x0002), value = 2 (0x00000002), len = 2 (0x0002)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Hash alg = 2 (sha1)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 11 (0x000b), value = 1 (0x00000001), len = 2 (0x0002)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 12 (0x000c), value = 28800 (0x00007080), len = 4 (0x0004)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Life duration 28800 secs
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 3 (0x0003), value = 1 (0x00000001), len = 2 (0x0002)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Auth method = 1
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_connect: SA = { ae0c09cd 0cfc3bf8 - 00000000 00000000}, nego = -1
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Start isakmp sa negotiation
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Version = 1.0, Input packet fields = 0000 
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Current state = Start sa negotiation I (1)/-1, exchange = 2, auth_method = pre shared key, Initiator
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation R (2), xchg = 2, auth = 0, fields = 0001 / 06c0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation R (2), xchg = 4, auth = 0, fields = 0017 / 06e0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation I (1), xchg = 2, auth = 3, fields = 0000 / 0000
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation I (1), xchg = 2, auth = 0, fields = 0000 / 0000
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matched state = Start sa negotiation I (1)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling output function[0] = ike_st_o_sa_proposal
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_o_sa_proposal: Start
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling output function[1] = ike_st_o_vids
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_isakmp_request_vendor_ids: Request vendor ID's policy call entered, IKE SA eeb400 (neg eef800)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_isakmp_request_vendor_ids: FB; Calling v2 policy function vendor_id_request
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_vid_request_cb: Got a VID of length 16 (neg eef800)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_ike_request_vendor_id: Sending VID RFC 3706 (Dead Peer Detection)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_vid_request_cb: Got a VID of length 16 (neg eef800)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_ike_request_vendor_id: Sending VID draft-stenberg-ipsec-nat-traversal-01
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_vid_request_cb: Got a VID of length 16 (neg eef800)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_ike_request_vendor_id: Sending VID draft-stenberg-ipsec-nat-traversal-02
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_vid_request_cb: Got a VID of length 16 (neg eef800)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_ike_request_vendor_id: Sending VID draft-ietf-ipsec-nat-t-ike-00
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_vid_request_cb: Got a VID of length 16 (neg eef800)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_ike_request_vendor_id: Sending VID draft-ietf-ipsec-nat-t-ike-02
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_vid_request_cb: Got a VID of length 16 (neg eef800)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_ike_request_vendor_id: Sending VID draft-ietf-ipsec-nat-t-ike-02
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_vid_request_cb: Got a VID of length 16 (neg eef800)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_ike_request_vendor_id: Sending VID draft-ietf-ipsec-nat-t-ike-03
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_vid_request_cb: Got a VID of length 16 (neg eef800)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_ike_request_vendor_id: Sending VID RFC 3947
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_vid_request_cb: Got a VID of length 28 (neg eef800)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_ike_request_vendor_id: Sending VID NetScreen Technologies
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_vid_request_cb: No more VIDs
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_policy_reply_isakmp_vendor_ids: Start
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling output function[2] = ike_st_o_private
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_o_private: Start
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_private_p_1_out: Phase-I output: packet_number 1 ike_sa eeb400 (neg eef800)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_phase1_pending_natt_operations: Processing pending NAT-T operations
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_private_p_1_out: Remote end does not support NAT-T (or Vendor IDs not received yet)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_private_p_1_out: FB; Calling v2 policy function private_payload_request
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_policy_reply_private_payload_out: Start
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: All done, new state = MM SA I (3)
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Start, SA = { 0xae0c09cd 0cfc3bf8 - 00000000 00000000 } / 00000000, nego = -1
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Encode packet, version = 1.0, flags = 0x00000000
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Encode SA: doi = 1, sit = 0x1
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Encode SA: Proposal[0] = 1 .protocol[0] = 1, # transforms = 1, spi[8] 
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Encode SA: trans[0] = 0, id = 1, # sa = 7
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_encode_data_attribute: encode B: type = 1 (0x0001), len = 2, value = 0007
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Encode SA: da[0], type = 1, value[2] = 0x0007
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_encode_data_attribute: encode B: type = 14 (0x000e), len = 2, value = 0100
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Encode SA: da[1], type = 14, value[2] = 0x0100
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_encode_data_attribute: encode B: type = 4 (0x0004), len = 2, value = 000e
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Encode SA: da[2], type = 4, value[2] = 0x000e
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_encode_data_attribute: encode B: type = 2 (0x0002), len = 2, value = 0002
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Encode SA: da[3], type = 2, value[2] = 0x0002
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_encode_data_attribute: encode B: type = 11 (0x000b), len = 2, value = 0001
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Encode SA: da[4], type = 11, value[2] = 0x0001
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_encode_data_attribute: encode V: type = 12 (0x000c), len = 4 (0x0004), value = 00007080 ...
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Encode SA: da[5], type = 12, value[4] = 0x00007080
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_encode_data_attribute: encode B: type = 3 (0x0003), len = 2, value = 0001
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Encode SA: da[6], type = 3, value[2] = 0x0001
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Payload length = 68
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Encode VID: vendor id[16] = 0xafcad713 68a1f1c9 6b8696fc 77570100
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Payload length = 20
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Encode VID: vendor id[16] = 0x27bab5dc 01ea0760 ea4e3190 ac27c0d0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Payload length = 20
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Encode VID: vendor id[16] = 0x6105c422 e76847e4 3f968480 1292aecd
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Payload length = 20
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Encode VID: vendor id[16] = 0x4485152d 18b6bbcd 0be8a846 9579ddcc
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Payload length = 20
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Encode VID: vendor id[16] = 0xcd604643 35df21f8 7cfdb2fc 68b6a448
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Payload length = 20
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Encode VID: vendor id[16] = 0x90cb8091 3ebb696e 086381b5 ec427b1f
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Payload length = 20
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Encode VID: vendor id[16] = 0x7d9419a6 5310ca6f 2c179d92 15529d56
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Payload length = 20
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Encode VID: vendor id[16] = 0x4a131c81 07035845 5c5728f2 0e95452f
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Payload length = 20
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Encode VID: vendor id[28] = 0x69936922 8741c6d4 ca094c93 e242c9de 19e7
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Payload length = 32
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Packet length = 288
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 00000000 00000000 [-1] / 0x00000000 } IP; Encoded packet[288] = 0xae0c09cd 0cfc3bf8 00000000 00000000 01100200 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Final length = 288
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_send_packet: Start, send SA = { ae0c09cd 0cfc3bf8 - 00000000 00000000}, nego = -1, local ip= <srx-ip-address>, dst = <vpn-server-ip-address>:500,  routing table id = 0
    [Jul 14 04:18:17][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_send_packet: Inserting retransmission timer after 10.000000 seconds
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  *** Processing received packet from <vpn-server-ip-address>:500 to <srx-ip-address>:0, VR 0, packet len: 144, on Interface: pp0.0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_packet_st_input_start: [e21800/0] Processing received
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_sa_find: Start, SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 }
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_sa_find: Not found SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 }
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  Failed to find IKEv1 SA for given spi
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_packet_st_input_v1_create_sa: [e21800/0] No IKE SA for packet; requesting permission to create one.
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_ike_rate_limit: Soft limit for p1 negotiation 100.Current active p1 negotiations 0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  New connection from <vpn-server-ip-address>:500 allowed
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_packet_st_connect_decision: [e21800/0] Pad allows connection
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_packet_v1_start: Passing IKE v1.0 packet to IKEv1 library
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_udp_callback_common: Packet from <vpn-server-ip-address>:500, use_natt=0 data[0..144] = ae0c09cd 0cfc3bf8 0b1943d8 9b0a01f8 ...
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_get_sa: Start, SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 } / 00000000, remote = <vpn-server-ip-address>:500
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_sa_find: Start, SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 }
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_sa_find: Not found SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 }
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_sa_find_half: Start, SA = { ae0c09cd 0cfc3bf8 - 00000000 00000000 }
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_sa_find_half: Found half SA = { ae0c09cd 0cfc3bf8 - 00000000 00000000 }
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_get_sa: We are intiator, first response packet
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_sa_upgrade: Start, SA = { ae0c09cd 0cfc3bf8 - 00000000 00000000 } -> { ... - 0b1943d8 9b0a01f8 }
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_udp_callback_common: Old negotiation message_id = 00000000, slot -1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Packet to old negotiation
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_decode_packet: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Packet received[144] = 0xae0c09cd 0cfc3bf8 0b1943d8 9b0a01f8 01100200 
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_decode_packet: Start, SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8} / 00000000, nego = -1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_decode_packet: first_payload_type:1.
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_decode_packet: next_payload_type:13.
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_decode_packet: next_payload_type:13.
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_decode_packet: next_payload_type:13.
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_decode_packet: next_payload_type:0.
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_decode_payload_sa: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Decode SA: doi = 1, sit = 0x1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_decode_payload_sa: Found 1 proposals
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Decode SA: Proposal[0] = 1 .protocol[0] = 1, # transforms = 1, spi[8] 
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_decode_payload_t: Start, # trans = 1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_decode_data_attribute_size: decode_size B: type = 1 (0x0001), value = 7 (0x0007), size = 4
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_decode_data_attribute_size: decode_size B: type = 14 (0x000e), value = 256 (0x0100), size = 4
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_decode_data_attribute_size: decode_size B: type = 2 (0x0002), value = 2 (0x0002), size = 4
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_decode_data_attribute_size: decode_size B: type = 4 (0x0004), value = 14 (0x000e), size = 4
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_decode_data_attribute_size: decode_size B: type = 3 (0x0003), value = 1 (0x0001), size = 4
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_decode_data_attribute_size: decode_size B: type = 11 (0x000b), value = 1 (0x0001), size = 4
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_decode_data_attribute_size: decode_size B: type = 12 (0x000c), value = 28800 (0x7080), size = 4
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Decode SA: trans[0] = 1, id = 1, # sa = #7
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_decode_data_attribute: decode B: type = 1 (0x0001), value = 7 (0x0007), len = 2, used_bytes = 4
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Decode SA: da[0], type = 1, value[2] = 0x0007
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_decode_data_attribute: decode B: type = 14 (0x000e), value = 256 (0x0100), len = 2, used_bytes = 4
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Decode SA: da[1], type = 14, value[2] = 0x0100
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_decode_data_attribute: decode B: type = 2 (0x0002), value = 2 (0x0002), len = 2, used_bytes = 4
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Decode SA: da[2], type = 2, value[2] = 0x0002
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_decode_data_attribute: decode B: type = 4 (0x0004), value = 14 (0x000e), len = 2, used_bytes = 4
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Decode SA: da[3], type = 4, value[2] = 0x000e
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_decode_data_attribute: decode B: type = 3 (0x0003), value = 1 (0x0001), len = 2, used_bytes = 4
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Decode SA: da[4], type = 3, value[2] = 0x0001
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_decode_data_attribute: decode B: type = 11 (0x000b), value = 1 (0x0001), len = 2, used_bytes = 4
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Decode SA: da[5], type = 11, value[2] = 0x0001
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_decode_data_attribute: decode B: type = 12 (0x000c), value = 28800 (0x7080), len = 2, used_bytes = 4
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Decode SA: da[6], type = 12, value[2] = 0x7080
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Decode VID: data[8] = 0x09002689 dfd6b712
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Decode VID: data[16] = 0xafcad713 68a1f1c9 6b8696fc 77570100
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Decode VID: data[16] = 0x4a131c81 07035845 5c5728f2 0e95452f
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Version = 1.0, Input packet fields = 0401 SA VID 
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Current state = MM SA I (3)/-1, exchange = 2, auth_method = pre shared key, Initiator
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation R (2), xchg = 2, auth = 0, fields = 0001 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation R (2), xchg = 4, auth = 0, fields = 0017 / 06e0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation I (1), xchg = 2, auth = 3, fields = 0000 / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation I (1), xchg = 2, auth = 0, fields = 0000 / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation I (1), xchg = 4, auth = 3, fields = 0000 / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation I (1), xchg = 4, auth = 2, fields = 0000 / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation I (1), xchg = 4, auth = 4, fields = 0000 / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM final R (8), xchg = 2, auth = 0, fields = ffff / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM done I (9), xchg = 2, auth = 0, fields = ffff / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM final I (12), xchg = 4, auth = 0, fields = ffff / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM done R (13), xchg = 4, auth = 0, fields = ffff / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM SA I (3), xchg = 2, auth = 2, fields = 0001 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM SA R (4), xchg = 2, auth = 2, fields = 0012 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM KE I (5), xchg = 2, auth = 2, fields = 0012 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM KE R (6), xchg = 2, auth = 2, fields = 000c / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM final I (7), xchg = 2, auth = 2, fields = 000c / 0680
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM SA I (10), xchg = 4, auth = 2, fields = 001f / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM SA R (11), xchg = 4, auth = 2, fields = 0008 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM SA I (3), xchg = 2, auth = 3, fields = 0001 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM SA R (4), xchg = 2, auth = 3, fields = 0016 / 06e0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM KE I (5), xchg = 2, auth = 3, fields = 0016 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM KE R (6), xchg = 2, auth = 3, fields = 0020 / 0680
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM final I (7), xchg = 2, auth = 3, fields = 0020 / 0680
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM SA I (10), xchg = 4, auth = 3, fields = 0037 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM SA R (11), xchg = 4, auth = 3, fields = 0020 / 0680
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM SA I (3), xchg = 2, auth = 4, fields = 0001 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matched state = MM SA I (3)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling input function[0] = ike_st_i_sa_value
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_i_sa_value: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 1 (0x0001), value = 7 (0x00000007), len = 2 (0x0002)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Encryption alg = 7 (aes-cbc)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 14 (0x000e), value = 256 (0x00000100), len = 2 (0x0002)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Key length = 256
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 4 (0x0004), value = 14 (0x0000000e), len = 2 (0x0002)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Group = 14, ec7070
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 2 (0x0002), value = 2 (0x00000002), len = 2 (0x0002)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Hash alg = 2 (sha1)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 11 (0x000b), value = 1 (0x00000001), len = 2 (0x0002)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 12 (0x000c), value = 28800 (0x00007080), len = 4 (0x0004)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Life duration 28800 secs
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 3 (0x0003), value = 1 (0x00000001), len = 2 (0x0002)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Auth method = 1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 1 (0x0001), value = 7 (0x00000007), len = 2 (0x0002)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Encryption alg = 7 (aes-cbc)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 14 (0x000e), value = 256 (0x00000100), len = 2 (0x0002)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Key length = 256
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 2 (0x0002), value = 2 (0x00000002), len = 2 (0x0002)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Hash alg = 2 (sha1)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 4 (0x0004), value = 14 (0x0000000e), len = 2 (0x0002)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Group = 14, ec7070
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 3 (0x0003), value = 1 (0x00000001), len = 2 (0x0002)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Auth method = 1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 11 (0x000b), value = 1 (0x00000001), len = 2 (0x0002)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 12 (0x000c), value = 28800 (0x00007080), len = 2 (0x0002)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Life duration 28800 secs
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 1 (0x0001), value = 7 (0x00000007), len = 2 (0x0002)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Encryption alg = 7 (aes-cbc)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 14 (0x000e), value = 256 (0x00000100), len = 2 (0x0002)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Key length = 256
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 2 (0x0002), value = 2 (0x00000002), len = 2 (0x0002)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Hash alg = 2 (sha1)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 4 (0x0004), value = 14 (0x0000000e), len = 2 (0x0002)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Group = 14, ec7070
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 3 (0x0003), value = 1 (0x00000001), len = 2 (0x0002)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Auth method = 1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 11 (0x000b), value = 1 (0x00000001), len = 2 (0x0002)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 12 (0x000c), value = 28800 (0x00007080), len = 2 (0x0002)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Life duration 28800 secs
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling input function[1] = ike_st_i_cr
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_i_cr: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling input function[2] = ike_st_i_cert
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_i_cert: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling input function[3] = ike_st_i_status_n
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling input function[4] = ike_st_i_vid
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_i_vid: VID[0..8] = 09002689 dfd6b712 ...
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_isakmp_vendor_id: Received vendor ID, length 8, IKE SA eeb400 (neg eef800)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_check_natt_vendor_id: Start ike_sa eeb400
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_isakmp_vendor_id: FB; Calling v2 policy function vendor_id
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_i_vid: VID[0..16] = afcad713 68a1f1c9 ...
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_isakmp_vendor_id: Received vendor ID, length 16, IKE SA eeb400 (neg eef800)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_check_natt_vendor_id: Start ike_sa eeb400
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_isakmp_vendor_id: FB; Calling v2 policy function vendor_id
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_ike_received_vendor_id: Received vendor-id for RFC 3706 (Dead Peer Detection)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_i_vid: VID[0..16] = 4a131c81 07035845 ...
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_isakmp_vendor_id: Received vendor ID, length 16, IKE SA eeb400 (neg eef800)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_check_natt_vendor_id: Start ike_sa eeb400
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_check_natt_vendor_id: Received NAT-T vendor id [RFC 3947]
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_isakmp_vendor_id: FB; Calling v2 policy function vendor_id
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_ike_received_vendor_id: Received vendor-id for RFC 3947
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling input function[5] = ike_st_i_private
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_i_private: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling output function[0] = ike_st_o_ke
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_o_ke: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_dh_get_group: DH Group type dl-modp
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_dh_get_group: DH Group size 2048
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_dh_get_group: DH Group 14
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_dh_generate_sync: Requested DH group 14
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_dh_create_contexts: Initialized JSF CRYPTO for kmd instance 0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_dh_create_contexts: System supports hardware DH mode
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_dh_generate: Generated DH keys using hardware for DH group 14
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  juniper_dlp_diffie_hellman_generate_async: DH Generate Secs [0] USecs [24922]
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  juniper_dlp_diffie_hellman_generate_async: Generated DH using hardware
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling output function[1] = ike_st_o_nonce
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_o_nonce: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_isakmp_nonce_data_len: Entered
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_policy_reply_isakmp_nonce_data_len: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Nonce data[16] = 0xc8fd2c49 51db1314 205a018b ba66e350
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling output function[2] = ike_st_o_private
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_o_private: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_private_p_1_out: Phase-I output: packet_number 3 ike_sa eeb400 (neg eef800)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_phase1_pending_natt_operations: Processing pending NAT-T operations
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_handle_send_hash_id: Adding NAT-D payloads: ike_sa eeb400 (neg eef800)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_id_as_hashed_string: Start ip = <vpn-server-ip-address> port = 500
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_policy_reply_private_payload_out: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_id_as_hashed_string: Start ip = <srx-ip-address> port = 500
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_policy_reply_private_payload_out: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_private_p_1_out: FB; Calling v2 policy function private_payload_request
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_policy_reply_private_payload_out: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: All done, new state = MM KE I (5)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Start, SA = { 0xae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 } / 00000000, nego = -1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Encode packet, version = 1.0, flags = 0x00000000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Encode KE: ke[256] = 0x75bd050d c6171621 804b0fbe 922aa0d9 6158fd48 92
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Payload length = 260
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Encode NONCE: nonce[16] = 0xc8fd2c49 51db1314 205a018b ba66e350
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Payload length = 20
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Encode PRV[20]: data[20] = 0xa8893d79 17588ba3 84f3a612 2b97a519 42729
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Payload length = 24
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Encode PRV[20]: data[20] = 0x43a3b194 75792bd7 93cfe829 a4790752 34b95
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Payload length = 24
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Packet length = 356
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Encoded packet[356] = 0xae0c09cd 0cfc3bf8 0b1943d8 9b0a01f8 04100200 0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Final length = 356
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_send_packet: Start, send SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8}, nego = -1, local ip= <srx-ip-address>, dst = <vpn-server-ip-address>:500,  routing table id = 0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_send_packet: Inserting retransmission timer after 10.000000 seconds
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_packet_destroy: [e21800/0] Destructor
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_packet_free: [e21800/0] Freeing
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  Ignoring the ifa preferred address add/change message as previous local address is the same
    [Jul 14 04:18:18]KMD_INTERNAL_ERROR: iked_ifstate_eoc_handler: EOC msg received
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  *** Processing received packet from <vpn-server-ip-address>:500 to <srx-ip-address>:0, VR 0, packet len: 372, on Interface: pp0.0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_packet_st_input_start: [e21c00/0] Processing received
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_sa_find: Start, SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 }
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_sa_find: Found SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 }
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  Found IKEv1 SA
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_packet_st_input_v1_get_sa: [e21c00/deadbeee] Packet to existing v1 SA
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_packet_v1_start: Passing IKE v1.0 packet to IKEv1 library
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_udp_callback_common: Packet from <vpn-server-ip-address>:500, use_natt=0 data[0..372] = ae0c09cd 0cfc3bf8 0b1943d8 9b0a01f8 ...
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_get_sa: Start, SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 } / 00000000, remote = <vpn-server-ip-address>:500
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_sa_find: Start, SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 }
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_sa_find: Found SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 }
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_udp_callback_common: Old negotiation message_id = 00000000, slot -1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Packet to old negotiation
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_decode_packet: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Packet received[372] = 0xae0c09cd 0cfc3bf8 0b1943d8 9b0a01f8 04100200 
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_decode_packet: Start, SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8} / 00000000, nego = -1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_decode_packet: first_payload_type:4.
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_decode_packet: next_payload_type:10.
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_decode_packet: next_payload_type:20.
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_private_p_1_check: New Phase-I private payload: private_payload_id 20
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_private_p_1_check: RFC 3947 NAT-D payload
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_decode_packet: next_payload_type:20.
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_private_p_1_check: New Phase-I private payload: private_payload_id 20
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_private_p_1_check: RFC 3947 NAT-D payload
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_decode_packet: next_payload_type:0.
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Decode KE: ke[256] = 0x87eb0469 af5c967f 62cf7276 cece3554 cc027c90 01
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Decode NONCE: nonce[32] = 0xa19223df 0108f531 9c579554 53b9c830 061f94
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Decode PRV[20]: data[20] = 0x43a3b194 75792bd7 93cfe829 a4790752 34b95
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Decode PRV[20]: data[20] = 0xf2953a2e 1cc5096d aa613b4f b18bfc83 297f6
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Version = 1.0, Input packet fields = 0012 KE NONCE 
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Current state = MM KE I (5)/-1, exchange = 2, auth_method = pre shared key, Initiator
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation R (2), xchg = 2, auth = 0, fields = 0001 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation R (2), xchg = 4, auth = 0, fields = 0017 / 06e0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation I (1), xchg = 2, auth = 3, fields = 0000 / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation I (1), xchg = 2, auth = 0, fields = 0000 / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation I (1), xchg = 4, auth = 3, fields = 0000 / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation I (1), xchg = 4, auth = 2, fields = 0000 / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation I (1), xchg = 4, auth = 4, fields = 0000 / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM final R (8), xchg = 2, auth = 0, fields = ffff / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM done I (9), xchg = 2, auth = 0, fields = ffff / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM final I (12), xchg = 4, auth = 0, fields = ffff / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM done R (13), xchg = 4, auth = 0, fields = ffff / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM SA I (3), xchg = 2, auth = 2, fields = 0001 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM SA R (4), xchg = 2, auth = 2, fields = 0012 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM KE I (5), xchg = 2, auth = 2, fields = 0012 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM KE R (6), xchg = 2, auth = 2, fields = 000c / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM final I (7), xchg = 2, auth = 2, fields = 000c / 0680
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM SA I (10), xchg = 4, auth = 2, fields = 001f / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM SA R (11), xchg = 4, auth = 2, fields = 0008 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM SA I (3), xchg = 2, auth = 3, fields = 0001 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM SA R (4), xchg = 2, auth = 3, fields = 0016 / 06e0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM KE I (5), xchg = 2, auth = 3, fields = 0016 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM KE R (6), xchg = 2, auth = 3, fields = 0020 / 0680
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM final I (7), xchg = 2, auth = 3, fields = 0020 / 0680
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM SA I (10), xchg = 4, auth = 3, fields = 0037 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM SA R (11), xchg = 4, auth = 3, fields = 0020 / 0680
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM SA I (3), xchg = 2, auth = 4, fields = 0001 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM SA R (4), xchg = 2, auth = 4, fields = 0012 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM KE I (5), xchg = 2, auth = 4, fields = 0012 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matched state = MM KE I (5)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling input function[0] = ike_st_i_nonce
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_i_nonce: Start, nonce[0..32] = a19223df 0108f531 ...
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling input function[1] = ike_st_i_ke
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_i_ke: Ke[0..256] = 87eb0469 af5c967f ...
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling input function[2] = ike_st_i_cr
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_i_cr: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling input function[3] = ike_st_i_cert
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_i_cert: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling input function[4] = ike_st_i_status_n
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling input function[5] = ike_st_i_vid
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling input function[6] = ike_st_i_private
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_i_private: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_private_p_1_in: Phase-I input: packet_number 4 ike_sa eeb400 (neg eef800)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_natt_hash_choice: Start ike_sa eeb400 (neg eef800)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_natt_hash_choice: First payload: checking local ID
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_id_as_hashed_string: Start ip = <srx-ip-address> port = 500
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_natt_hash_choice: Local end not behind NAT
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_private_p_1_in: Phase-I input: packet_number 4 ike_sa eeb400 (neg eef800)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_natt_hash_choice: Start ike_sa eeb400 (neg eef800)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_natt_hash_choice: Not first payload: checking remote ID
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_id_as_hashed_string: Start ip = <vpn-server-ip-address> port = 500
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_natt_hash_choice: Remote end behind NAT
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling output function[0] = ike_st_o_id
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_o_id: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Encoding ID = fqdn(any:0,[0..10]=<srx-dns-name>)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling output function[1] = ike_st_o_hash
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_o_hash: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_dh_get_group: DH Group type dl-modp
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_dh_get_group: DH Group size 2048
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_dh_get_group: DH Group 14
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_dh_compute_synch: Requested DH group 14
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  Peer public key has length 256
    
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  juniper_dlp_diffie_hellman_final_async: DH Compute Secs [0] USecs [24817]
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  juniper_dlp_diffie_hellman_final_async: Computed DH using hardware
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Diffie-hellman secret g^xy[256] = 0xe2471641 d59bbc62 78cacb3c 0cdbce7
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_find_pre_shared_key: Find pre shared key key for <srx-ip-address>:500, id = fqdn(any:0,[0..10]=<srx-dns-name>) -> <vpn-server-ip-address>:500, id = No Id
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_find_pre_shared_key: Find pre-shared key policy call entered, IKE SA eeb400 (neg eef800)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_policy_reply_find_pre_shared_key: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Hash algorithm = hmac-sha1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Prf key[32] = 0x77544832 56246765 23304a35 62645f56 546e4d39 69332650 
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Calculating SKEYID
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; SKEYID hash .= Ni[16] = 0xc8fd2c49 51db1314 205a018b ba66e350
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; SKEYID hash .= Nr[32] = 0xa19223df 0108f531 9c579554 53b9c830 061f943a
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Output of SKEYID hash[20] = 0xdaf25951 681f17cf b09245e2 8169df0d 6362
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; SKEYID_d hash .= g^xy[256] = 0xe2471641 d59bbc62 78cacb3c 0cdbce70 06e
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; SKEYID_d hash .= CKY-I[8] = 0xae0c09cd 0cfc3bf8
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; SKEYID_d hash .= CKY-R[8] = 0x0b1943d8 9b0a01f8
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; SKEYID_d hash .= 0[1] = 0x00
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Output of SKEYID_d hash[20] = 0x67618601 627f41e9 c5034e4e 3328776b 9e
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; SKEYID_a hash .= SKEYID_d[20] = 0x67618601 627f41e9 c5034e4e 3328776b 
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; SKEYID_a hash .= g^xy[256] = 0xe2471641 d59bbc62 78cacb3c 0cdbce70 06e
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; SKEYID_a hash .= CKY-I[8] = 0xae0c09cd 0cfc3bf8
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; SKEYID_a hash .= CKY-R[8] = 0x0b1943d8 9b0a01f8
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; SKEYID_a hash .= 1[1] = 0x01
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Output of SKEYID_a hash[20] = 0x47b80ce4 890bbaa3 0355fda3 dbdff53a ff
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; SKEYID_e hash .= SKEYID_a[20] = 0x47b80ce4 890bbaa3 0355fda3 dbdff53a 
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; SKEYID_e hash .= g^xy[256] = 0xe2471641 d59bbc62 78cacb3c 0cdbce70 06e
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; SKEYID_e hash .= CKY-I[8] = 0xae0c09cd 0cfc3bf8
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; SKEYID_e hash .= CKY-R[8] = 0x0b1943d8 9b0a01f8
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; SKEYID_e hash .= 2[1] = 0x02
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Output SKEYID_e hash[20] = 0xdd2155dd a638d84f c2cc6fcd 8b89dd38 63648
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; K1 hash .= 0[1] = 0x00
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Output of K1 hash[20] = 0x598e1f6b 144195e1 c162c2ff 8bb849b0 facf0fdc
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; K2 hash .= K1[20] = 0x598e1f6b 144195e1 c162c2ff 8bb849b0 facf0fdc
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Output of K2 hash[20] = 0xc56634b5 6a474c25 e21b2fa0 a56893a7 1facb319
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Final encryption key[32] = 0x598e1f6b 144195e1 c162c2ff 8bb849b0 facf0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; IV hash .= g^xi[256] = 0x75bd050d c6171621 804b0fbe 922aa0d9 6158fd48 
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; IV hash .= g^xr[256] = 0x87eb0469 af5c967f 62cf7276 cece3554 cc027c90 
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Output of IV hash[16] = 0x6c8c8339 e7acfe8e 671b1fb4 79a0b8fa
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_calc_mac: Start, initiator = true, local = true
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; HASH_I hash .= g^xi[256] = 0x75bd050d c6171621 804b0fbe 922aa0d9 6158f
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; HASH_I hash .= g^xr[256] = 0x87eb0469 af5c967f 62cf7276 cece3554 cc027
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; HASH_I hash .= CKY-I[8] = 0xae0c09cd 0cfc3bf8
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; HASH_I hash .= CKY-R[8] = 0x0b1943d8 9b0a01f8
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; HASH_I hash .= SAi_b[64] = 0x00000001 00000001 00000038 01010801 ae0c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Encoding ID = fqdn(any:0,[0..10]=<srx-dns-name>)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; HASH_I hash .= IDii_b[15] = 0x02000000 6e616d6f 6465762e 6e6574
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:500 (Initiator) <-> <vpn-server-ip-address>:500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Output of HASH_I hash[20] = 0x8ea5eec5 53ec7cf0 afc907cc a5635fb9 d370
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling output function[2] = ike_st_o_status_n
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_o_status_n: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling output function[3] = ike_st_o_private
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_o_private: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_private_p_1_out: Phase-I output: packet_number 5 ike_sa eeb400 (neg eef800)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_phase1_pending_natt_operations: Processing pending NAT-T operations
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_initiator_float_ike_server: Floating IKE ports
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_private_p_1_out: FB; Calling v2 policy function private_payload_request
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_policy_reply_private_payload_out: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling output function[4] = ike_st_o_encrypt
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_o_encrypt: Marking encryption for packet
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: All done, new state = MM final I (7)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Start, SA = { 0xae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 } / 00000000, nego = -1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Encode packet, version = 1.0, flags = 0x00000001
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Encode ID: packet[15] = 0x02000000 6e616d6f 6465762e 6e6574
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Payload length = 19
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Encode HASH: hash[20] = 0x8ea5eec5 53ec7cf0 afc907cc a5635fb9 d3709c
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Payload length = 24
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Encode N: doi = 1, proto = 1, type = 24578, spi[16] = 0xae0c09cd 0cf
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Encode N: data[0]
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Payload length = 28
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Packet length = 108
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Encoded packet[108] = 0xae0c09cd 0cfc3bf8 0b1943d8 9b0a01f8 05100201
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Encrypting packet
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; dec->enc IV[16] = 0x6c8c8339 e7acfe8e 671b1fb4 79a0b8fa
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; enc->dec IV[16] = 0xbe0eaa16 40210890 fbb777f3 d63ad91f
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Encrypted packet[108] = 0xae0c09cd 0cfc3bf8 0b1943d8 9b0a01f8 051002
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Final length = 108
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_send_packet: Start, send SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8}, nego = -1, local ip= <srx-ip-address>, dst = <vpn-server-ip-address>:4500,  routing table id = 0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_send_packet: Inserting retransmission timer after 10.000000 seconds
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_packet_destroy: [e21c00/deadbeee] Destructor
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_packet_free: [e21c00/deadbeee] Freeing
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  *** Processing received packet from <vpn-server-ip-address>:4500 to <srx-ip-address>:0, VR 0, packet len: 96, on Interface: pp0.0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_packet_st_input_start: [e37000/0] Processing received
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_sa_find: Start, SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 }
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_sa_find: Found SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 }
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  Found IKEv1 SA
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_packet_st_input_v1_get_sa: [e37000/deadbeee] Packet to existing v1 SA
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_packet_v1_start: Passing IKE v1.0 packet to IKEv1 library
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_udp_callback_common: Packet from <vpn-server-ip-address>:4500, use_natt=1 data[0..96] = 00000000 ae0c09cd 0cfc3bf8 0b1943d8 ...
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_get_sa: Start, SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 } / 00000000, remote = <vpn-server-ip-address>:4500
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_sa_find: Start, SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 }
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_sa_find: Found SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 }
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_udp_callback_common: Old negotiation message_id = 00000000, slot -1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Packet to old negotiation
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_decode_packet: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Packet received[92] = 0xae0c09cd 0cfc3bf8 0b1943d8 9b0a01f8 05100201
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_decode_packet: Start, SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8} / 00000000, nego = -1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_decode_packet: first_payload_type:5.
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_decode_packet: Decrypting packet
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Decrypted packet[92] = 0xae0c09cd 0cfc3bf8 0b1943d8 9b0a01f8 0510020
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_decode_packet: next_payload_type:8.
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_decode_packet: next_payload_type:0.
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Decode ID: packet[30] = 0x02000000 616d7333 2e766e78 2e65676e 61726e
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Decode HASH: hash[20] = 0xad5fdc97 b644a4ca 729a638b 668c27fe 8a3e34
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Version = 1.0, Input packet fields = 0024 ID HASH 
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Current state = MM final I (7)/-1, exchange = 2, auth_method = pre shared key, Initiator
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation R (2), xchg = 2, auth = 0, fields = 0001 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation R (2), xchg = 4, auth = 0, fields = 0017 / 06e0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation I (1), xchg = 2, auth = 3, fields = 0000 / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation I (1), xchg = 2, auth = 0, fields = 0000 / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation I (1), xchg = 4, auth = 3, fields = 0000 / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation I (1), xchg = 4, auth = 2, fields = 0000 / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation I (1), xchg = 4, auth = 4, fields = 0000 / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM final R (8), xchg = 2, auth = 0, fields = ffff / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM done I (9), xchg = 2, auth = 0, fields = ffff / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM final I (12), xchg = 4, auth = 0, fields = ffff / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM done R (13), xchg = 4, auth = 0, fields = ffff / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM SA I (3), xchg = 2, auth = 2, fields = 0001 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM SA R (4), xchg = 2, auth = 2, fields = 0012 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM KE I (5), xchg = 2, auth = 2, fields = 0012 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM KE R (6), xchg = 2, auth = 2, fields = 000c / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM final I (7), xchg = 2, auth = 2, fields = 000c / 0680
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM SA I (10), xchg = 4, auth = 2, fields = 001f / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM SA R (11), xchg = 4, auth = 2, fields = 0008 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM SA I (3), xchg = 2, auth = 3, fields = 0001 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM SA R (4), xchg = 2, auth = 3, fields = 0016 / 06e0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM KE I (5), xchg = 2, auth = 3, fields = 0016 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM KE R (6), xchg = 2, auth = 3, fields = 0020 / 0680
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM final I (7), xchg = 2, auth = 3, fields = 0020 / 0680
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM SA I (10), xchg = 4, auth = 3, fields = 0037 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM SA R (11), xchg = 4, auth = 3, fields = 0020 / 0680
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM SA I (3), xchg = 2, auth = 4, fields = 0001 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM SA R (4), xchg = 2, auth = 4, fields = 0012 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM KE I (5), xchg = 2, auth = 4, fields = 0012 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM KE R (6), xchg = 2, auth = 4, fields = 0024 / 0680
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM final I (7), xchg = 2, auth = 4, fields = 0024 / 0680
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matched state = MM final I (7)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling input function[0] = ike_st_i_encrypt
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_i_encrypt: Check that packet was encrypted succeeded
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling input function[1] = ike_st_i_id
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_i_id: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Decoded ID = fqdn(any:0,[0..25]=<vpn-server-dns-name>)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling input function[2] = ike_st_i_hash
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_i_hash: Start, hash[0..20] = ad5fdc97 b644a4ca ...
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_calc_mac: Start, initiator = true, local = false
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; HASH_R hash .= g^xr[256] = 0x87eb0469 af5c967f 62cf7276 cece3554 cc0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; HASH_R hash .= g^xi[256] = 0x75bd050d c6171621 804b0fbe 922aa0d9 615
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; HASH_R hash .= CKY-R[8] = 0x0b1943d8 9b0a01f8
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; HASH_R hash .= CKY-I[8] = 0xae0c09cd 0cfc3bf8
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; HASH_R hash .= SAi_b[64] = 0x00000001 00000001 00000038 01010801 ae0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Encoding ID = fqdn(any:0,[0..25]=<vpn-server-dns-name>)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; HASH_R hash .= IDir_b[30] = 0x02000000 616d7333 2e766e78 2e65676e 61
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Output of HASH_R hash[20] = 0xad5fdc97 b644a4ca 729a638b 668c27fe 8a
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling input function[3] = ike_st_i_cert
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_i_cert: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling input function[4] = ike_st_i_status_n
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling input function[5] = ike_st_i_vid
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling input function[6] = ike_st_i_private
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_i_private: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling output function[0] = ike_st_o_copy_iv
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; dec->enc iv[16] = 0xb1a59f2c d9bd4f2a de951eae e1acf56d
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling output function[1] = ike_st_o_wait_done
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_o_wait_done: Marking for waiting for done
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_o_all_done: MESSAGE: Phase 1 { 0xae0c09cd 0cfc3bf8 - 0x0b1943d8 9b0a01f8 } / 00000000, version = 1.0, xchg = Identity protect, auth_method = Pre shared keys, Initiator, cipher = ae
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; MESSAGE: Phase 1 version = 1.0, auth_method = Pre shared keys, ciphe
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_free_packet: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: All done, new state = MM done I (9)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_negotiation_done_isakmp: Entered IKE error code Connected notification (16384), IKE SA eeb400 (neg eef800)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_phase1_pending_natt_operations: Processing pending NAT-T operations
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_i_ike_negotiation_cb: Connect IKE done callback, status Connected notification (neg eef800)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fallback_negotiation_free: Fallback negotiation eef800 has still 1 references
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_send_notify: Connected, SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8}, nego = -1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Connected
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_process_packet: No output packet, returning
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_packet_destroy: [e37000/deadbeee] Destructor
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_packet_free: [e37000/deadbeee] Freeing
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_i_p1_negotiation_result: Phase I negotiation result
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_i_p1_negotiation_result: FB; Calling v2 policy function ike_sa_done
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_ike_sa_done: local:<srx-ip-address>, remote:<vpn-server-ip-address> IKEv1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_idv2_to_idv1: Converting the IKEv2 payload ID ID(type = fqdn (2), len = 26, value = <vpn-server-dns-name>) to IKEv1 ID
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_idv2_to_idv1: IKEv2 payload ID converted to IKEv1 payload ID fqdn(any:0,[0..25]=<vpn-server-dns-name>)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_id_validate called with id fqdn(any:0,[0..25]=<vpn-server-dns-name>)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_id_validate id NOT matched.
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_ike_sa_done ID validation fails
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  P1 SA 310166 stop timer. timer duration 30, reason 1.
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  P1 SA 310166 start timer. timer duration 0, reason 3.
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_i_p1_check_cfg: Phase I done : check XAUTH/CFGMODE
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_i_p1_check_cfg: cfg_pending=0, xauth=0, xauth_done=0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_i_p1_finish: Phase I done, move to QM start (neg eef800)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_i_qm_negotiation_start: QM negotiation start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_i_qm_negotiation_start: Taking reference to fallback negotiation eef800 (now 2 references)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_set_thread_debug_info: ikev2_fb_i_qm_negotiation_start: set thread debug info - local <srx-ip-address> remote <vpn-server-ip-address> neg 0xeef800 neg->ike_sa 0xeeb400 ike_sa 0x0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_i_qm_negotiation_negotiate: QM negotiation negotiate
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_st_i_qm_sa_alloc_spi: FB; Calling v2 policy function ipsec_spi_allocate
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_ipsec_spi_allocate: local:<srx-ip-address>, remote:<vpn-server-ip-address> IKEv1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  Allocated SPI [08eec5fc]. proto 0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  Added (spi=0x8eec5fc, protocol=0) entry to the spi table
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  Parsing notification payload for local:<srx-ip-address>, remote:<vpn-server-ip-address> IKEv1 
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_ipsec_spi_allocate_cb: New IPSec SPI 8eec5fc allocated successfully (neg eef800)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_st_i_qm_sa_alloc_spi: FB; Calling v2 policy function ipsec_spi_allocate
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_ipsec_spi_allocate: local:<srx-ip-address>, remote:<vpn-server-ip-address> IKEv1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  Allocated SPI [abe18102]. proto 0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  Added (spi=0xabe18102, protocol=0) entry to the spi table
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  Parsing notification payload for local:<srx-ip-address>, remote:<vpn-server-ip-address> IKEv1 
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_ipsec_spi_allocate_cb: New IPSec SPI abe18102 allocated successfully (neg eef800)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_st_i_qm_sa_notify_request: FB; Calling v2 policy function notify_request
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  Parsing notification payload for local:<srx-ip-address>, remote:<vpn-server-ip-address> IKEv1 
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_st_i_qm_sa_request: FB; Calling v2 policy function fill_ipsec_sa
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fallback_negotiation_free: Fallback negotiation eef800 has still 1 references
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_i_qm_negotiation_negotiate: QM negotiation negotiate
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_i_qm_negotiation_negotiate: Taking reference to fallback negotiation eef800 (now 2 references)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_connect_ipsec: Start, remote_name = :500, flags = 00010000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_sa_find_ip_port: Start, remote = all:500
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_alloc_negotiation: Start, SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8}
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_alloc_negotiation: Found slot 0, max 1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_connect_ipsec: SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8}, nego = 0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_init_qm_negotiation: Start, initiator = 1, message_id = 4c80a79e
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Number of SA proposals = 1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; SA[0]: Number of proposals = 1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; SA[0][0]: Number of protocols = 1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; SA[0][0][0]: Number of transforms = 1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; SA[0][0][0][0]: ESP protocol
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Transform id = 12
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 6 (0x0006), value = 256 (0x00000100), len = 2 (0x0002)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Key length = 256
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 5 (0x0005), value = 2 (0x00000002), len = 2 (0x0002)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Auth alg = 2 (hmac-sha1-96)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 3 (0x0003), value = 14 (0x0000000e), len = 2 (0x0002)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Group = 14
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 1 (0x0001), value = 1 (0x00000001), len = 2 (0x0002)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 2 (0x0002), value = 3600 (0x00000e10), len = 4 (0x0004)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Life duration 3600 secs
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_get_data_attribute_int: get_int: type = 4 (0x0004), value = 3 (0x00000003), len = 2 (0x0002)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; encapsulation mode = 3 (udp-tunnel)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Start ipsec sa negotiation
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Version = 1.0, Input packet fields = 0000 
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Current state = Start QM I (14)/-1, exchange = 32, auth_method = phase1, Initiator
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation R (2), xchg = 2, auth = 0, fields = 0001 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation R (2), xchg = 4, auth = 0, fields = 0017 / 06e0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation I (1), xchg = 2, auth = 3, fields = 0000 / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation I (1), xchg = 2, auth = 0, fields = 0000 / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation I (1), xchg = 4, auth = 3, fields = 0000 / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation I (1), xchg = 4, auth = 2, fields = 0000 / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start sa negotiation I (1), xchg = 4, auth = 4, fields = 0000 / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM final R (8), xchg = 2, auth = 0, fields = ffff / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM done I (9), xchg = 2, auth = 0, fields = ffff / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM final I (12), xchg = 4, auth = 0, fields = ffff / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM done R (13), xchg = 4, auth = 0, fields = ffff / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM SA I (3), xchg = 2, auth = 2, fields = 0001 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM SA R (4), xchg = 2, auth = 2, fields = 0012 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM KE I (5), xchg = 2, auth = 2, fields = 0012 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM KE R (6), xchg = 2, auth = 2, fields = 000c / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM final I (7), xchg = 2, auth = 2, fields = 000c / 0680
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM SA I (10), xchg = 4, auth = 2, fields = 001f / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM SA R (11), xchg = 4, auth = 2, fields = 0008 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM SA I (3), xchg = 2, auth = 3, fields = 0001 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM SA R (4), xchg = 2, auth = 3, fields = 0016 / 06e0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM KE I (5), xchg = 2, auth = 3, fields = 0016 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM KE R (6), xchg = 2, auth = 3, fields = 0020 / 0680
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM final I (7), xchg = 2, auth = 3, fields = 0020 / 0680
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM SA I (10), xchg = 4, auth = 3, fields = 0037 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM SA R (11), xchg = 4, auth = 3, fields = 0020 / 0680
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM SA I (3), xchg = 2, auth = 4, fields = 0001 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM SA R (4), xchg = 2, auth = 4, fields = 0012 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM KE I (5), xchg = 2, auth = 4, fields = 0012 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM KE R (6), xchg = 2, auth = 4, fields = 0024 / 0680
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM final I (7), xchg = 2, auth = 4, fields = 0024 / 0680
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM SA I (10), xchg = 4, auth = 4, fields = 0037 / 0680
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = AM SA R (11), xchg = 4, auth = 4, fields = 0020 / 0680
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = MM SA I (3), xchg = 2, auth = 0, fields = 0001 / 06c0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matching with state = Start QM I (14), xchg = 32, auth = 1, fields = 0000 / 0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Matched state = Start QM I (14)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling output function[0] = ike_st_o_qm_hash_1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_o_qm_hash_1: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling output function[1] = ike_st_o_qm_sa_proposals
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_o_qm_sa_proposals: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling output function[2] = ike_st_o_qm_nonce
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_o_qm_nonce: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_qm_nonce_data_len: Entered
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_policy_reply_qm_nonce_data_len: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling output function[3] = ike_st_o_qm_optional_ke
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_o_qm_optional_ke: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_dh_get_group: DH Group type dl-modp
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_dh_get_group: DH Group size 2048
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_dh_get_group: DH Group 14
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_dh_generate_sync: Requested DH group 14
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_dh_generate: Generated DH keys using hardware for DH group 14
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  juniper_dlp_diffie_hellman_generate_async: DH Generate Secs [0] USecs [38269]
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  juniper_dlp_diffie_hellman_generate_async: Generated DH using hardware
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling output function[4] = ike_st_o_qm_optional_ids
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_o_qm_optional_ids: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_qm_optional_id: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Encoding ID = ipv4_subnet(any:0,[0..7]=10.100.0.0/16)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_qm_optional_id: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Encoding ID = ipv4_subnet(any:0,[0..7]=0.0.0.0/0)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling output function[5] = ike_st_o_private
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_o_private: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_private_p_qm_out: FB; Calling v2 policy function private_payload_request
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  Construction NHTB payload for  local:<srx-ip-address>, remote:<vpn-server-ip-address> IKEv1 P1 SA index 310166 sa-cfg vpn-amsterdam-strongswan
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  Peer router vendor is not Juniper. Not sending NHTB payload for sa-cfg vpn-amsterdam-strongswan, p1_sa=310166 
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_policy_reply_private_payload_out: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: Calling output function[6] = ike_st_o_encrypt
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_st_o_encrypt: Marking encryption for packet
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; IV hash .= Final Phase 1 IV[16] = 0xb1a59f2c d9bd4f2a de951eae e1acf56d
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; IV hash .= Message id[4] = 0x4c80a79e
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Output of phase 2 IV hash[16] = 0x4678a9c2 98759dcb bd8e12da edc76f1b
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_state_step: All done, new state = QM HASH SA I (16)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Start, SA = { 0xae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 } / 4c80a79e, nego = 0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Encode packet, version = 1.0, flags = 0x00000001
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Encode HASH: hash[20] = 0x00000000 00000000 00000000 00000000 00000000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Payload length = 24
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Encode SA: doi = 1, sit = 0x1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Encode SA: Proposal[0] = 1 .protocol[0] = 3, # transforms = 1, spi[4] = 0x08e
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Encode SA: trans[0] = 0, id = 12, # sa = 6
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_encode_data_attribute: encode B: type = 6 (0x0006), len = 2, value = 0100
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Encode SA: da[0], type = 6, value[2] = 0x0100
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_encode_data_attribute: encode B: type = 5 (0x0005), len = 2, value = 0002
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Encode SA: da[1], type = 5, value[2] = 0x0002
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_encode_data_attribute: encode B: type = 3 (0x0003), len = 2, value = 000e
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Encode SA: da[2], type = 3, value[2] = 0x000e
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_encode_data_attribute: encode B: type = 1 (0x0001), len = 2, value = 0001
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Encode SA: da[3], type = 1, value[2] = 0x0001
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_encode_data_attribute: encode V: type = 2 (0x0002), len = 4 (0x0004), value = 00000e10 ...
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Encode SA: da[4], type = 2, value[4] = 0x00000e10
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_encode_data_attribute: encode B: type = 4 (0x0004), len = 2, value = 0003
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Encode SA: da[5], type = 4, value[2] = 0x0003
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Payload length = 60
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Encode NONCE: nonce[16] = 0xe9bc1162 ffa47619 2a43e085 2e286914
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Payload length = 20
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Encode KE: ke[256] = 0x9cefe529 dfb763cc 2163769c e075a2c3 89bc5bfb 6b5152ab 
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Payload length = 260
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Encode ID: packet[12] = 0x04000000 0a640000 ffff0000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Payload length = 16
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Encode ID: packet[12] = 0x04000000 00000000 00000000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Payload length = 16
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Packet length = 428
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Calling finalizing function for payload[0].type = 8
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; HASH hash .= M-ID[4] = 0x4c80a79e
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Output of HASH hash[20] = 0xa8cfe9d0 f88010ca 42029a97 a704ad0c beb7e567
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_finalize_qm_hash_1: Hash[0..20] = a8cfe9d0 f88010ca ...
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Encoded packet[428] = 0xae0c09cd 0cfc3bf8 0b1943d8 9b0a01f8 08102001 4c80a79e
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Encrypting packet
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; dec->enc IV[16] = 0x4678a9c2 98759dcb bd8e12da edc76f1b
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; enc->dec IV[16] = 0xe9897ee0 9e3a3537 f1a49186 1d884045
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [0] / 0x4c80a79e } QM; Encrypted packet[428] = 0xae0c09cd 0cfc3bf8 0b1943d8 9b0a01f8 08102001 4c80a7
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Final length = 428
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_send_packet: Start, send SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8}, nego = 0, local ip= <srx-ip-address>, dst = <vpn-server-ip-address>:4500,  routing table id = 0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_send_packet: Inserting retransmission timer after 10.000000 seconds
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  P1 SA 310166 timer expiry. ref cnt 2, timer reason Defer delete timer expired (3), flags 0x110.
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_ha_check_ike_sa_activeness_by_rg_id:RG 0 is active on this chassiss
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  Initiate IKE P1 SA 310166 delete. curr ref count 2, del flags 0x2
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_ike_sa_delete_notify_done_cb: For p1 sa index 310166, ref cnt 2, status: Error ok
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_set_debug_gw_info: ssh_set_debug_gw_info: set gw debug info - local <srx-ip-address> remote <vpn-server-ip-address>
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_expire_callback: Start, expire SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8}, nego = -1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Expiring negotiation
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_ha_check_ike_sa_activeness_by_rg_id:RG 0 is active on this chassiss
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_alloc_negotiation: Start, SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8}
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_alloc_negotiation: Found slot 1, max 2
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_init_info_exchange: New informational negotiation message_id = 677201e1 initialized using slot 1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [1] / 0x677201e1 } Info; IV hash .= Final Phase 1 IV[16] = 0xb1a59f2c d9bd4f2a de951eae e1acf56d
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [1] / 0x677201e1 } Info; IV hash .= Message id[4] = 0x677201e1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [1] / 0x677201e1 } Info; Output of phase 2 IV hash[16] = 0xd8880943 6e8b42d9 d5b9b989 c0ca419c
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_init_info_exchange: Created random message id = 677201e1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_init_info_exchange: Phase 1 done, use HASH and N or D payload
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [1] / 0x677201e1 } Info; Sending delete notify back
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Start, SA = { 0xae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 } / 677201e1, nego = 1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [1] / 0x677201e1 } Info; Encode packet, version = 1.0, flags = 0x00000001
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [1] / 0x677201e1 } Info; Encode HASH: hash[20] = 0x00000000 00000000 00000000 00000000 00000000
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Payload length = 24
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [1] / 0x677201e1 } Info; Encode D: doi = 1, proto = 1, # spis = 1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [1] / 0x677201e1 } Info; Encode D: spi[0][16] = 0xae0c09cd 0cfc3bf8 0b1943d8 9b0a01f8
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Payload length = 28
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Packet length = 92
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Calling finalizing function for payload[0].type = 8
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [1] / 0x677201e1 } Info; HASH hash .= M-ID[4] = 0x677201e1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [1] / 0x677201e1 } Info; Output of HASH hash[20] = 0xe6113e44 170dbae4 e1c4a3d7 43d1953c 532df20f
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [1] / 0x677201e1 } Info; Encoded packet[92] = 0xae0c09cd 0cfc3bf8 0b1943d8 9b0a01f8 08100501 677201
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Encrypting packet
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [1] / 0x677201e1 } Info; dec->enc IV[16] = 0xd8880943 6e8b42d9 d5b9b989 c0ca419c
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [1] / 0x677201e1 } Info; enc->dec IV[16] = 0xd530201b 23821fc7 22b1055b 88b73375
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [1] / 0x677201e1 } Info; Encrypted packet[92] = 0xae0c09cd 0cfc3bf8 0b1943d8 9b0a01f8 08100501 6772
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_encode_packet: Final length = 92
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_expire_callback: Sending notification to <vpn-server-ip-address>:4500
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_send_packet: Start, send SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8}, nego = 1, local ip= <srx-ip-address>, dst = <vpn-server-ip-address>:4500,  routing table id = 0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_free_packet: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_delete_negotiation: Start, SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8}, nego = 1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <none>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [1] / 0x677201e1 } Info; Deleting negotiation
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_free_negotiation_info: Start, nego = 1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_free_negotiation: Start, nego = 1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_phase_ii_sa_freed: Phase-II free Entered
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_set_debug_gw_info: ssh_set_debug_gw_info: set gw debug info - local <srx-ip-address> remote <vpn-server-ip-address>
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_remove_callback: Start, delete SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8}, nego = -1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Removing negotiation
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_delete_negotiation: Start, SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8}, nego = -1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  <srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip-address>:4500 { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 [-1] / 0x00000000 } IP; Deleting negotiation
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_tunnel_table_entry_delete: Deleting tunnel_id: 0 from IKE tunnel table
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ike_tunnel_table_entry_delete: The tunnel id: 0 doesn't exist in IKE tunnel table
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_sa_delete: Start, SA = { ae0c09cd 0cfc3bf8 - 0b1943d8 9b0a01f8 }
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_negotiation_done_qm: Entered IKE error code Aborted notification (8199) (neg eef800)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_i_ipsec_negotiation_cb: Connect IPSec done callback, status Aborted notification (neg eef800)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_free_negotiation_qm: Start, nego = 0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_free_negotiation: Start, nego = 0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_free_packet: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_qm_sa_freed: QM free Entered
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_phase_qm_clear_pm_data: Clearing FB negotiation eef800 from qm_info ef9200
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fallback_negotiation_free: Fallback negotiation eef800 has still 1 references
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_free_id_payload: Start, id type = 4
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_free_id_payload: Start, id type = 4
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_free_negotiation_isakmp: Start, nego = -1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_free_negotiation: Start, nego = -1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_free_packet: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_free_packet: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_free_packet: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_free_packet: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_free_packet: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_free_packet: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_isakmp_sa_freed: Received notification from the ISAKMP library that the IKE SA eeb400 is freed
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_isakmp_sa_freed: Clearing p1_info from fallback negotiation eef800
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_isakmp_sa_freed: FB; Calling v2 policy function ike_sa_delete
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  IKE SA delete called for p1 sa 310166 (ref cnt 2) local:<srx-ip-address>, remote:<vpn-server-ip-address>, IKEv1 
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  P1 SA 310166 stop timer. timer duration 0, reason 0.
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_sa_abort: Aborting QM negotiation eef800
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_sa_abort: Finishing IKE SA negotiation (neg eef800)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_free_exchange_data: Freeing exchange data from SA eeb400, ED ef0028 (2)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  Freeing reference to P1 SA 310166 to ref count 1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  P1 SA 310166 reference count is not zero (1). Delaying deletion of SA
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_free_id_payload: Start, id type = 2
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_free_id_payload: Start, id type = 2
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ike_free_sa: Start
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_i_p1_negotiation_result: Phase I negotiation result
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_i_p1_negotiation_result: Phase I negotiation was aborted (neg eef800)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fb_p1_negotiation_destructor: Freeing fallback negotiation context
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_fallback_negotiation_free: Freeing fallback negotiation eef800
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_free_exchange_data: Freeing exchange data from SA eeb400, ED ef0028 (1)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_free_exchange_data_ipsec: Freeing IPsec exchange data from SA eeb400
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ikev2_ts_free: ts 0xe78a20, ref_cnt 1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ikev2_ts_free: ts 0xe78a40, ref_cnt 1
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_free_exchange_data_ipsec: Successfully freed IPsec exchange data from SA eeb400
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_free_exchange_data_ike: Freeing IKE exchange data from SA eeb400
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_free_exchange_data_ike: Successfully freed IKE exchange data from SA eeb400
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_free_exchange_data: Calling exchange_data_free
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  Freeing P2 Ed for sa-cfg vpn-amsterdam-strongswan
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_unset_sa_cfg_p2_ed unset_sa_cfg_p2_ed,  sa_cfg=vpn-amsterdam-strongswan
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_ike_exchange_data_free: Successfully removed pm_ed eede00 from list for sa_cfg N/A
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_free_exchange_data: Successfully freed exchange data from SA eeb400
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ssh_ikev2_ike_sa_free: Calling ike_sa_free_ref
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  Freeing reference to P1 SA 310166 to ref count 0
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  No more references to IKE SA 310166 and waiting for delete. Deleting IKE SA
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_p1_sa_destroy:  p1 sa 310166 (ref cnt 0), waiting_for_del 0xe03460
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_peer_remove_p1sa_entry: Remove p1 sa 310166 from peer entry 0xeed800
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_delete_peer_entry: Requested for peer-entry 0xeed800 deletion for local <srx-ip-address>:500 and remote <vpn-server-ip-address>:500
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_dist_table_entry_update : Dist table entry creation not needed
    
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_peer_entry_patricia_delete:Peer entry 0xeed800 deleted for local <srx-ip-address>:500 and remote <vpn-server-ip-address>:500
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  Deleting p1 sa (310166) node from IKE p1 SA P-tree 
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  The tunnel id: 310166 doesn't exist in P1 SA P-tree
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  ikev2_udp_window_uninit: Freeing transmission windows for SA eeb400
    


  • 12.  RE: IKE between SRX and StrongSwan keeps timing out

    Posted 07-13-2016 22:34

    Hi,

    Looks like the identity is not matching :-

     

    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_id_validate called with id fqdn(any:0,[0..25]=<vpn-server-dns-name>)
    [Jul 14 04:18:18][<srx-ip-address> <-> <vpn-server-ip-address>]  iked_pm_id_validate id NOT matched.

    Check what is the local and remote identites configured on the server.

     

    Regards,

    Sahil



  • 13.  RE: IKE between SRX and StrongSwan keeps timing out

    Posted 07-14-2016 02:22

    That worked. The SRX was trying to connect using the VPN server's IP address, but the server's left_id is a domain name. Changing the leftid directive in ipsec.conf does the trick:

     

    leftid=<vpn_server_ip_address>

    The tunnel comes up properly now:

     

    namo@SRX220> show security ipsec sa 
      Total active tunnels: 1
      ID    Algorithm       SPI      Life:sec/kb  Mon lsys Port  Gateway   
      <131073 ESP:aes-cbc-256/sha1 dd7749c2 3582/ unlim - root 4500 <vpn-server-ip-address>  
      >131073 ESP:aes-cbc-256/sha1 cfd954dc 3582/ unlim - root 4500 <vpn-server-ip-address>  
    
    namo@SRX220> show security ike sa 
    Index   State  Initiator cookie  Responder cookie  Mode           Remote Address   
    7586532 UP     56ab7386d313bac4  6a3b59971503eed8  Main           <vpn-server-ip-address>  
    

    I've also changed the SRX's IPSec configuration a bit - because I wanted all internet traffic to route through this VPN, route-based VPN doesn't seems to be possible (or is it?), so I tried creating a policy-based VPN by dropping the "bind-interface" rule from the IPSec configuration on the SRX, and modifying the outgoing policy by adding:

     

    tunnel {
        ipsec-vpn vpn-amsterdam-strongswan;
    }

    To the outgoing policy, but now the network can't access the internet. Pinging anything outside of the local network results in a timeout. Any suggestions?

     

     



  • 14.  RE: IKE between SRX and StrongSwan keeps timing out

    Posted 07-14-2016 06:13

    Hi,

     

    It is good to see that the tunnel is up now after the issue with the identities was rectified.

     

    For route based VPN, if you point the default route to the st interface, all the traffic would go over the tunnel, however you would have to put specific route for the Remote Server IP to your default gateway so that the VPN negotiation can take place.

     

    For a policy based tunnel, the configuration changes you have mentioned seem to be fine. Check if the traffic is getting encrypted from our side and being sent to the Server :-

    "show security ipsec statistics index <Index_Number>"

     

    Check for encaps and decaps.

     

    If you see encaps incrementing when we are initiating traffic from behind the SRX, then check what is happening to this traffic when it reaches the server.

     

    Regards,

    Sahil Sharma

    ---------------------------------------------------

    Please mark my solution as accepted if it helped, Kudos are appreciated as well.



  • 15.  RE: IKE between SRX and StrongSwan keeps timing out

    Posted 07-14-2016 08:57

    I've discovered why I can't access the internet earlier. Somehow there's a remnant of st0.0 configured in the route:

     

    static {
        route 0.0.0.0/0 {
            next-hop st0.0;
            qualified-next-hop pp0.0 {
                metric 1;
            }
        }
    }
    

    Deleted that and the internet is now working fine. There's a new problem however - IKE/IPSec fails to come up completely. The server doesn't log anything (highly likely that there's no traffic reaching the server at all), so I enabled traceoptions on the SRX again and got this:

     

    namo@SRX220> show log test1 
    [Jul 14 15:39:04]Successfully delete ike debug blob
    [Jul 14 15:39:04]kmd_iked_cfgbuf_addrec: 535: ** Allocated recptr is c58, reclen = 10748016 **
    [Jul 14 15:39:04]kmd_iked_cfgbuf_addrec: 535: ** Allocated recptr is 44, reclen = 10748016 **
    [Jul 14 15:39:04]Error: Unknown record, type = 25
     
    [Jul 14 15:39:04]kmd_iked_cfgbuf_addrec: 535: ** Allocated recptr is 4, reclen = 4 **
    [Jul 14 15:39:04]kmd_iked_cfgbuf_addrec: 535: ** Allocated recptr is 0, reclen = 0 **
    [Jul 14 15:39:04]No SPUs are operational, returning.
    [Jul 14 15:39:04]Config download: Processed 1 - 2 messages
    [Jul 14 15:39:04]Config download time: 0 secs
    [Jul 14 15:39:04]iked_config_process_config_list, configuration diff complete

     

    Tried pinging the VPN server (both by IP and DNS), everything seems normal. Any suggestions?



  • 16.  RE: IKE between SRX and StrongSwan keeps timing out

    Posted 07-14-2016 09:42

    Hi,

     

    I see the error - No SPUs are operational.

     

    Please check the following :-

     

    >show chassis fpc

     

    This should show if the dataplane is functional.

     

    Regards,

    Sahil Sharma

    ---------------------------------------------------

    Please mark my solution as accepted if it helped, Kudos are appreciated as well.



  • 17.  RE: IKE between SRX and StrongSwan keeps timing out

    Posted 07-14-2016 09:58

    Here's the result:

     

    namo@SRX220> show chassis fpc 
                         Temp  CPU Utilization (%)   Memory    Utilization (%)
    Slot State            (C)  Total  Interrupt      DRAM (MB) Heap     Buffer
      0  Online          -------------------- CPU less FPC --------------------
      1  Empty           
      2  Empty           
    
    

    Anyway - I did found one weird thing. The VPN server was rebooted, and AppArmor was blocking access to a private key used by some other VPN configuration on the same server and StrongSwan seems to freeze. What's strange is that why did the SRX report "No SPUs are operational" (is this normal, a bug, or something else?)

     

    Running

     

    $ apparmor_parser -R /etc/apparmor.d/usr.lib.ipsec.charon
    $ apparmor_parser -R /etc/apparmor.d/usr.lib.ipsec.stroke

    on the server seems to resolve the issue, but this needs to be done on every reboot. (I'm pretty sure there's a permanent solution available, but this also works, so let's move on for now...)

     

    Also did "show IPSec statistics" and found out that the "Encrypted bytes" counter does increase while trying to ping 8.8.8.8. So should be a server-side issue now...

     

    namo@SRX220> show security ipsec statistics index 0    
    ESP Statistics:
      Encrypted bytes:           237368
      Decrypted bytes:                0
      Encrypted packets:           1795
      Decrypted packets:              0
    AH Statistics:
      Input bytes:                    0
      Output bytes:                   0
      Input packets:                  0
      Output packets:                 0
    Errors:
      AH authentication failures: 0, Replay errors: 0
      ESP authentication failures: 0, ESP decryption failures: 0
      Bad headers: 0, Bad trailers: 0
    

     

    Here's the SA's now:

     

    namo@SRX220> show security ipsec sa                    
      Total active tunnels: 1
      ID    Algorithm       SPI      Life:sec/kb  Mon lsys Port  Gateway   
      <3    ESP:aes-cbc-256/sha1 772e50f7 3600/ unlim - root 4500 <vpn-server-ip>  
      >3    ESP:aes-cbc-256/sha1 c65ef7ef 3600/ unlim - root 4500 <vpn-server-ip>   
    
    namo@SRX220> show security ike sa                      
    Index   State  Initiator cookie  Responder cookie  Mode           Remote Address   
    7254498 UP     8abb9434c313f381  c211bd694523c689  Main           <vpn-server-ip>   
    

     

    Thanks for all your help!

     

    I'll try to see what server side issue is preventing the traffic from flowing through (probably a bit off-topic now, but any ideas are welcome). Will update thread here for reference if I found what's causing the issue.



  • 18.  RE: IKE between SRX and StrongSwan keeps timing out

    Posted 07-14-2016 22:02

    Hi,

     

    Thanks for the update.

     

    The SPU not operational message was nto seen quite often, should not be a bug.

     

    If the SRX is encrypting the traffic, the issue seems to be on the server side.

     

    We can see that there are no decrypted bytes, so no response ESP packets are being received on the SRX from the server.

     

    Regards,

    Sahil Sharma

    ---------------------------------------------------

    Please mark my solution as accepted if it helped, Kudos are appreciated as well.



  • 19.  RE: IKE between SRX and StrongSwan keeps timing out

    Posted 07-13-2016 21:23

    Update: I've changed the encryption parameters a bit (the SRX's encryption was also updated to aes-256-cbc) and the server now doesn't seems to complain about anything:

     

     

    Jul 14 00:17:06 vpn-ams charon: 02[CFG] looking for a child config for 0.0.0.0/0 === 10.100.0.0/16
    Jul 14 00:17:06 vpn-ams charon: 02[CFG] proposing traffic selectors for us:
    Jul 14 00:17:06 vpn-ams charon: 02[CFG]  0.0.0.0/0
    Jul 14 00:17:06 vpn-ams charon: 02[CFG] proposing traffic selectors for other:
    Jul 14 00:17:06 vpn-ams charon: 02[CFG]  10.100.0.0/16
    Jul 14 00:17:06 vpn-ams charon: 02[CFG]   candidate "site2site" with prio 5+5
    Jul 14 00:17:06 vpn-ams charon: 02[CFG] found matching child config "site2site" with prio 10
    Jul 14 00:17:06 vpn-ams charon: 02[CFG] selecting traffic selectors for other:
    Jul 14 00:17:06 vpn-ams charon: 02[CFG]  config: 10.100.0.0/16, received: 10.100.0.0/16 => match: 10.100.0.0/16
    Jul 14 00:17:06 vpn-ams charon: 02[CFG] selecting traffic selectors for us:
    Jul 14 00:17:06 vpn-ams charon: 02[CFG]  config: 0.0.0.0/0, received: 0.0.0.0/0 => match: 0.0.0.0/0
    Jul 14 00:17:06 vpn-ams charon: 02[CFG] selecting proposal:
    Jul 14 00:17:06 vpn-ams charon: 02[CFG]   proposal matches
    Jul 14 00:17:06 vpn-ams charon: 02[CFG] received proposals: ESP:AES_CBC_256/HMAC_SHA1_96/MODP_2048/NO_EXT_SEQ
    Jul 14 00:17:06 vpn-ams charon: 02[CFG] configured proposals: ESP:AES_CBC_256/HMAC_SHA1_96/MODP_2048/NO_EXT_SEQ
    Jul 14 00:17:06 vpn-ams charon: 02[CFG] selected proposal: ESP:AES_CBC_256/HMAC_SHA1_96/MODP_2048/NO_EXT_SEQ
    Jul 14 00:17:06 vpn-ams charon: 02[IKE] received 3600s lifetime, configured 1200s
    Jul 14 00:17:06 vpn-ams charon: 02[KNL] got SPI c9fbef93
    Jul 14 00:17:06 vpn-ams charon: 02[ENC] generating QUICK_MODE response 3294626395 [ HASH SA No KE ID ID ]
    Jul 14 00:17:06 vpn-ams charon: 02[NET] sending packet: from 10.18.0.5[4500] to <srx-ip-address>[4500] (444 bytes)
    Jul 14 00:17:06 vpn-ams charon: 06[NET] received packet: from <srx-ip-address>[4500] to 10.18.0.5[4500] (92 bytes)
    Jul 14 00:17:06 vpn-ams charon: 06[ENC] parsed INFORMATIONAL_V1 request 2254351893 [ HASH D ]
    Jul 14 00:17:06 vpn-ams charon: 06[IKE] received DELETE for IKE_SA site2site[9]
    Jul 14 00:17:06 vpn-ams charon: 06[IKE] deleting IKE_SA site2site[9] between 10.18.0.5[<vpn-server-dns>]...<srx-ip-address>[<srx-dns-name>]
    Jul 14 00:17:06 vpn-ams charon: 06[IKE] IKE_SA site2site[9] state change: ESTABLISHED => DELETING
    Jul 14 00:17:06 vpn-ams charon: 06[IKE] IKE_SA site2site[9] state change: DELETING => DELETING
    

     

     

     

    But the SRX's kmd-logs file is showing:

     

     

    Jul 14 04:05:37  SRX220 kmd[55323]: IKE negotiation failed with error: Authentication failed. IKE Version: 1, VPN: vpn-amsterdam-strongswan Gateway: gw-amsterdam-strongswan, Local: <srx-ip-address>/4500, Remote: <server-ip-address>/4500, Local IKE-ID: <srx-dns-name>, Remote IKE-ID: <vpn-server-dns>, VR-ID: 0

     

     

    I've double-checked the shared keys - they should not be a problem.

     

    Here's the full log in "kmd" after restarting ipsec-key-management:

     

    [Jul 14 04:04:24]iked_pm_ike_spd_notify_request: Sending Initial contact
    [Jul 14 04:04:24]ssh_ike_connect: Start, remote_name = <vpn-server-ip>:500, xchg = 2, flags = 00090000
    [Jul 14 04:04:24]ike_sa_allocate: Start, SA = { 14300bc9 5bae2b94 - 00000000 00000000 }
    [Jul 14 04:04:24]ike_init_isakmp_sa: Start, remote = <vpn-server-ip>:500, initiator = 1
    [Jul 14 04:04:24]ssh_ike_connect: SA = { 14300bc9 5bae2b94 - 00000000 00000000}, nego = -1
    [Jul 14 04:04:24]ike_st_o_sa_proposal: Start
    [Jul 14 04:04:24]ike_policy_reply_isakmp_vendor_ids: Start
    [Jul 14 04:04:24]ike_st_o_private: Start
    [Jul 14 04:04:24]ike_policy_reply_private_payload_out: Start
    [Jul 14 04:04:24]ike_encode_packet: Start, SA = { 0x14300bc9 5bae2b94 - 00000000 00000000 } / 00000000, nego = -1
    [Jul 14 04:04:24]ike_send_packet: Start, send SA = { 14300bc9 5bae2b94 - 00000000 00000000}, nego = -1, local ip= <srx-ip-address>, dst = <vpn-server-ip>:500,  routing table id = 0
    [Jul 14 04:04:24]ikev2_packet_allocate: Allocated packet e38c00 from freelist
    [Jul 14 04:04:24]ike_sa_find: Not found SA = { 14300bc9 5bae2b94 - bbc082dd 5cc0897b }
    [Jul 14 04:04:24]ikev2_packet_v1_start: Passing IKE v1.0 packet to IKEv1 library
    [Jul 14 04:04:24]ike_get_sa: Start, SA = { 14300bc9 5bae2b94 - bbc082dd 5cc0897b } / 00000000, remote = <vpn-server-ip>:500
    [Jul 14 04:04:24]ike_sa_find: Not found SA = { 14300bc9 5bae2b94 - bbc082dd 5cc0897b }
    [Jul 14 04:04:24]ike_sa_find_half: Found half SA = { 14300bc9 5bae2b94 - 00000000 00000000 }
    [Jul 14 04:04:24]ike_sa_upgrade: Start, SA = { 14300bc9 5bae2b94 - 00000000 00000000 } -> { ... - bbc082dd 5cc0897b }
    [Jul 14 04:04:24]ike_decode_packet: Start
    [Jul 14 04:04:24]ike_decode_packet: Start, SA = { 14300bc9 5bae2b94 - bbc082dd 5cc0897b} / 00000000, nego = -1
    [Jul 14 04:04:24]ike_decode_payload_sa: Start
    [Jul 14 04:04:24]ike_decode_payload_t: Start, # trans = 1
    [Jul 14 04:04:24]ike_st_i_sa_value: Start
    [Jul 14 04:04:24]ike_st_i_cr: Start
    [Jul 14 04:04:24]ike_st_i_cert: Start
    [Jul 14 04:04:24]ike_st_i_vid: VID[0..8] = 09002689 dfd6b712 ...
    [Jul 14 04:04:24]ike_st_i_vid: VID[0..16] = afcad713 68a1f1c9 ...
    [Jul 14 04:04:24]ike_st_i_vid: VID[0..16] = 4a131c81 07035845 ...
    [Jul 14 04:04:24]ike_st_i_private: Start
    [Jul 14 04:04:24]ike_st_o_ke: Start
    [Jul 14 04:04:24]ike_st_o_nonce: Start
    [Jul 14 04:04:24]ike_policy_reply_isakmp_nonce_data_len: Start
    [Jul 14 04:04:24]ike_st_o_private: Start
    [Jul 14 04:04:24]ike_policy_reply_private_payload_out: Start
    [Jul 14 04:04:24]ike_policy_reply_private_payload_out: Start
    [Jul 14 04:04:24]ike_policy_reply_private_payload_out: Start
    [Jul 14 04:04:24]ike_encode_packet: Start, SA = { 0x14300bc9 5bae2b94 - bbc082dd 5cc0897b } / 00000000, nego = -1
    [Jul 14 04:04:24]ike_send_packet: Start, send SA = { 14300bc9 5bae2b94 - bbc082dd 5cc0897b}, nego = -1, local ip= <srx-ip-address>, dst = <vpn-server-ip>:500,  routing table id = 0
    [Jul 14 04:04:24]ikev2_packet_allocate: Allocated packet e39000 from freelist
    [Jul 14 04:04:24]ike_sa_find: Found SA = { 14300bc9 5bae2b94 - bbc082dd 5cc0897b }
    [Jul 14 04:04:24]ikev2_packet_v1_start: Passing IKE v1.0 packet to IKEv1 library
    [Jul 14 04:04:24]ike_get_sa: Start, SA = { 14300bc9 5bae2b94 - bbc082dd 5cc0897b } / 00000000, remote = <vpn-server-ip>:500
    [Jul 14 04:04:24]ike_sa_find: Found SA = { 14300bc9 5bae2b94 - bbc082dd 5cc0897b }
    [Jul 14 04:04:24]ike_decode_packet: Start
    [Jul 14 04:04:24]ike_decode_packet: Start, SA = { 14300bc9 5bae2b94 - bbc082dd 5cc0897b} / 00000000, nego = -1
    [Jul 14 04:04:24]ike_st_i_nonce: Start, nonce[0..32] = 3eaa8f56 a351ae3b ...
    [Jul 14 04:04:24]ike_st_i_ke: Ke[0..256] = f5254939 045f5c33 ...
    [Jul 14 04:04:24]ike_st_i_cr: Start
    [Jul 14 04:04:24]ike_st_i_cert: Start
    [Jul 14 04:04:24]ike_st_i_private: Start
    [Jul 14 04:04:24]ike_st_o_id: Start
    [Jul 14 04:04:24]ike_st_o_hash: Start
    [Jul 14 04:04:24]ike_find_pre_shared_key: Find pre shared key key for <srx-ip-address>:500, id = fqdn(any:0,[0..10]=<srx-dns-name>) -> <vpn-server-ip>:500, id = No Id
    [Jul 14 04:04:24]ike_policy_reply_find_pre_shared_key: Start
    [Jul 14 04:04:24]ike_calc_mac: Start, initiator = true, local = true
    [Jul 14 04:04:24]ike_st_o_status_n: Start
    [Jul 14 04:04:24]ike_st_o_private: Start
    [Jul 14 04:04:24]ike_policy_reply_private_payload_out: Start
    [Jul 14 04:04:24]ike_st_o_encrypt: Marking encryption for packet
    [Jul 14 04:04:24]ike_encode_packet: Start, SA = { 0x14300bc9 5bae2b94 - bbc082dd 5cc0897b } / 00000000, nego = -1
    [Jul 14 04:04:24]ike_send_packet: Start, send SA = { 14300bc9 5bae2b94 - bbc082dd 5cc0897b}, nego = -1, local ip= <srx-ip-address>, dst = <vpn-server-ip>:4500,  routing table id = 0
    [Jul 14 04:04:24]ikev2_packet_allocate: Allocated packet e39400 from freelist
    [Jul 14 04:04:24]ike_sa_find: Found SA = { 14300bc9 5bae2b94 - bbc082dd 5cc0897b }
    [Jul 14 04:04:24]ikev2_packet_v1_start: Passing IKE v1.0 packet to IKEv1 library
    [Jul 14 04:04:24]ike_get_sa: Start, SA = { 14300bc9 5bae2b94 - bbc082dd 5cc0897b } / 00000000, remote = <vpn-server-ip>:4500
    [Jul 14 04:04:24]ike_sa_find: Found SA = { 14300bc9 5bae2b94 - bbc082dd 5cc0897b }
    [Jul 14 04:04:24]ike_decode_packet: Start
    [Jul 14 04:04:24]ike_decode_packet: Start, SA = { 14300bc9 5bae2b94 - bbc082dd 5cc0897b} / 00000000, nego = -1
    [Jul 14 04:04:24]ike_st_i_encrypt: Check that packet was encrypted succeeded
    [Jul 14 04:04:24]ike_st_i_id: Start
    [Jul 14 04:04:24]ike_st_i_hash: Start, hash[0..20] = 6fb082df 57c4eb9c ...
    [Jul 14 04:04:24]ike_calc_mac: Start, initiator = true, local = false
    [Jul 14 04:04:24]ike_st_i_cert: Start
    [Jul 14 04:04:24]ike_st_i_private: Start
    [Jul 14 04:04:24]ike_st_o_wait_done: Marking for waiting for done
    [Jul 14 04:04:24]ike_st_o_all_done: MESSAGE: Phase 1 { 0x14300bc9 5bae2b94 - 0xbbc082dd 5cc0897b } / 00000000, version = 1.0, xchg = Identity protect, auth_method = Pre shared keys, Initiator, cipher = aes-cbc, hash = sha1, prf = hmac-sha1,
    [Jul 14 04:04:24]<srx-ip-address>:4500 (Initiator) <-> <vpn-server-ip>:4500 { 14300bc9 5bae2b94 - bbc082dd 5cc0897b [-1] / 0x00000000 } IP; MESSAGE: Phase 1 version = 1.0, auth_method = Pre shared keys, cipher = aes-cbc, hash = sha1, prf = hmac
    [Jul 14 04:04:24]ike_send_notify: Connected, SA = { 14300bc9 5bae2b94 - bbc082dd 5cc0897b}, nego = -1
    [Jul 14 04:04:24]iked_pm_ike_sa_done: local:<srx-ip-address>, remote:<vpn-server-ip> IKEv1
    [Jul 14 04:04:24]iked_pm_id_validate id NOT matched.
    [Jul 14 04:04:24]Added (spi=0x5a49b0d3, protocol=0) entry to the spi table
    [Jul 14 04:04:24]Added (spi=0x8e7fdce9, protocol=0) entry to the spi table
    [Jul 14 04:04:24]ssh_ike_connect_ipsec: Start, remote_name = :500, flags = 00010000
    [Jul 14 04:04:24]ike_alloc_negotiation: Start, SA = { 14300bc9 5bae2b94 - bbc082dd 5cc0897b}
    [Jul 14 04:04:24]ssh_ike_connect_ipsec: SA = { 14300bc9 5bae2b94 - bbc082dd 5cc0897b}, nego = 0
    [Jul 14 04:04:24]ike_init_qm_negotiation: Start, initiator = 1, message_id = d9048630
    [Jul 14 04:04:24]ike_st_o_qm_hash_1: Start
    [Jul 14 04:04:24]ike_st_o_qm_sa_proposals: Start
    [Jul 14 04:04:24]ike_st_o_qm_nonce: Start
    [Jul 14 04:04:24]ike_policy_reply_qm_nonce_data_len: Start
    [Jul 14 04:04:24]ike_st_o_qm_optional_ke: Start
    [Jul 14 04:04:24]ike_st_o_qm_optional_ids: Start
    [Jul 14 04:04:24]ike_st_qm_optional_id: Start
    [Jul 14 04:04:24]ike_st_qm_optional_id: Start
    [Jul 14 04:04:24]ike_st_o_private: Start
    [Jul 14 04:04:24]Construction NHTB payload for  local:<srx-ip-address>, remote:<vpn-server-ip> IKEv1 P1 SA index 2979961 sa-cfg vpn-amsterdam-strongswan
    [Jul 14 04:04:24]Peer router vendor is not Juniper. Not sending NHTB payload for sa-cfg vpn-amsterdam-strongswan, p1_sa=2979961 
    [Jul 14 04:04:24]ike_policy_reply_private_payload_out: Start
    [Jul 14 04:04:24]ike_st_o_encrypt: Marking encryption for packet
    [Jul 14 04:04:24]ike_encode_packet: Start, SA = { 0x14300bc9 5bae2b94 - bbc082dd 5cc0897b } / d9048630, nego = 0
    [Jul 14 04:04:24]ike_finalize_qm_hash_1: Hash[0..20] = 9892b0f5 9c5e15b8 ...
    [Jul 14 04:04:24]ike_send_packet: Start, send SA = { 14300bc9 5bae2b94 - bbc082dd 5cc0897b}, nego = 0, local ip= <srx-ip-address>, dst = <vpn-server-ip>:4500,  routing table id = 0
    [Jul 14 04:04:24]P1 SA 2979961 timer expiry. ref cnt 2, timer reason Defer delete timer expired (3), flags 0x110.
    [Jul 14 04:04:24]iked_pm_ike_sa_delete_notify_done_cb: For p1 sa index 2979961, ref cnt 2, status: Error ok
    [Jul 14 04:04:24]ike_expire_callback: Start, expire SA = { 14300bc9 5bae2b94 - bbc082dd 5cc0897b}, nego = -1
    [Jul 14 04:04:24]ike_alloc_negotiation: Start, SA = { 14300bc9 5bae2b94 - bbc082dd 5cc0897b}
    [Jul 14 04:04:24]ike_encode_packet: Start, SA = { 0x14300bc9 5bae2b94 - bbc082dd 5cc0897b } / f7ffb97a, nego = 1
    [Jul 14 04:04:24]ike_send_packet: Start, send SA = { 14300bc9 5bae2b94 - bbc082dd 5cc0897b}, nego = 1, local ip= <srx-ip-address>, dst = <vpn-server-ip>:4500,  routing table id = 0
    [Jul 14 04:04:24]ike_delete_negotiation: Start, SA = { 14300bc9 5bae2b94 - bbc082dd 5cc0897b}, nego = 1
    [Jul 14 04:04:24]ike_free_negotiation_info: Start, nego = 1
    [Jul 14 04:04:24]ike_free_negotiation: Start, nego = 1
    [Jul 14 04:04:24]ike_remove_callback: Start, delete SA = { 14300bc9 5bae2b94 - bbc082dd 5cc0897b}, nego = -1
    [Jul 14 04:04:24]ike_delete_negotiation: Start, SA = { 14300bc9 5bae2b94 - bbc082dd 5cc0897b}, nego = -1
    [Jul 14 04:04:24]ssh_ike_tunnel_table_entry_delete: Deleting tunnel_id: 0 from IKE tunnel table
    [Jul 14 04:04:24]ssh_ike_tunnel_table_entry_delete: The tunnel id: 0 doesn't exist in IKE tunnel table
    [Jul 14 04:04:24]ike_sa_delete: Start, SA = { 14300bc9 5bae2b94 - bbc082dd 5cc0897b }
    [Jul 14 04:04:24]ike_free_negotiation_qm: Start, nego = 0
    [Jul 14 04:04:24]ike_free_negotiation: Start, nego = 0
    [Jul 14 04:04:24]ike_free_id_payload: Start, id type = 4
    [Jul 14 04:04:24]ike_free_id_payload: Start, id type = 4
    [Jul 14 04:04:24]ike_free_negotiation_isakmp: Start, nego = -1
    [Jul 14 04:04:24]ike_free_negotiation: Start, nego = -1
    [Jul 14 04:04:24]IKE SA delete called for p1 sa 2979961 (ref cnt 2) local:<srx-ip-address>, remote:<vpn-server-ip>, IKEv1 
    [Jul 14 04:04:24]P1 SA 2979961 reference count is not zero (1). Delaying deletion of SA
    [Jul 14 04:04:24]ike_free_id_payload: Start, id type = 2
    [Jul 14 04:04:24]ike_free_id_payload: Start, id type = 2
    [Jul 14 04:04:24]ike_free_sa: Start
    [Jul 14 04:04:24]iked_pm_p1_sa_destroy:  p1 sa 2979961 (ref cnt 0), waiting_for_del 0xe78a40
    [Jul 14 04:04:24]iked_deferred_free_inactive_peer_entry: Free 1 peer_entry(s)