Hi,
I have the following IKEv2 configuration, external partner is running ASA, we agreed the DH-group is group14, but IKEv2 SA comes up with DH-group-5, I am initiator, partner side is complaining DH-group mis-macth ... in what scenario will this happen?
SRX# run show configuration security ike proposal ike-prop-ExtParter02
authentication-method pre-shared-keys;
dh-group group14; <==================================
authentication-algorithm sha-256;
encryption-algorithm aes-256-cbc;
lifetime-seconds 86400;
vSRX# run show configuration security ike policy ike-pol-ExtParter02
mode main;
proposals ike-prop-ExtParter02;
pre-shared-key ascii-text "FOOBAR"; ## SECRET-DATA
SRX# run show configuration security ike gateway ExtParter02-GW
ike-policy ike-pol-ExtParter02;
address 213.5.3.2;
dead-peer-detection {
always-send;
interval 10;
threshold 3;
}
local-identity inet 48.5.23.7;
external-interface ge-0/0/0.0;
version v2-only;
SRX# run show security ike security-associations 213.5.3.2 detail
IKE peer 213.5.3.2, Index 7224719, Gateway Name: ExtParter02-GW
Role: Initiator, State: UP
Initiator cookie: 021e684b9220c6d8, Responder cookie: 76a3aef189f63d9f
Exchange type: IKEv2, Authentication method: Pre-shared-keys
Local: 48.5.23.7:500, Remote: 213.5.3.2:500
Lifetime: Expires in 85091 seconds
Reauth Lifetime: Disabled
IKE Fragmentation: Enabled, Size: 576
Remote Access Client Info: Unknown Client
Peer ike-id: 213.5.3.2
AAA assigned IP: 0.0.0.0
Algorithms:
Authentication : hmac-sha256-128
Encryption : aes256-cbc
Pseudo random function: hmac-sha256
Diffie-Hellman group : DH-group-5 <=============================
Traffic statistics:
Input bytes : 1112558
Output bytes : 1852214
Input packets: 5489
Output packets: 5470
Input fragmentated packets: 0
Output fragmentated packets: 0
IPSec security associations: 2 created, 0 deleted
Phase 2 negotiations in progress: 1
Negotiation type: Quick mode, Role: Initiator, Message ID: 0
Local: 48.5.23.7:500, Remote:213.5.3.2:500
Local identity: 48.5.23.7
Remote identity:213.5.3.2
Flags: IKE SA is created