I have an IPsec tunnel up and working, using ge-0/0/1 as the external interface and st0.0 as the bind interface. I'm trying to set up two additional tunnels to AWS using ge-0/0/1 as th external interface and st1.0 and st1.1 as the bind interfaces. Running Junos 12.1X44-D20.3, should this be an issue?
The two additional tunnels to AWS aren't coming up. I'm seeing in the debug logs that it's not finding a gateway match:
[Jan 6 14:20:08][<local IP> <-> <remote IP>] Search for a tunnel matching the IKE peers, local:<local IP>, remote:<remote IP> IKEv1
[Jan 6 14:20:08][<local IP> <-> <remote IP>] iked_pm_phase1_sa_cfg_lookup_by_addr: Address based phase 1 SA-CFG lookup failed for local:<local IP>, remote:<remote IP> IKEv1
[Jan 6 14:20:08][<local IP> <-> <remote IP>] iked_pm_dynamic_gw_local_addr_based_lookup: called with local ip:<local IP>
[Jan 6 14:20:08][<local IP> <-> <remote IP>] dynamic gateway match unsuccessful:
[Jan 6 14:20:08][<local IP> <-> <remote IP>] iked_pm_ike_spd_select_ike_sa failed. rc 1, error_code: No proposal chosen
[Jan 6 14:20:08][<local IP> <-> <remote IP>] ikev2_fb_spd_select_sa_cb: IKEv2 SA select failed with error No proposal chosen (neg df8800)
Here's what I have configured for IKE gateways:
set security ike gateway gw-aws-193 ike-policy ike-pol-aws-193
set security ike gateway gw-aws-193 address <remote IP>
set security ike gateway gw-aws-193 dead-peer-detection interval 10
set security ike gateway gw-aws-193 dead-peer-detection threshold 3
set security ike gateway gw-aws-193 external-interface ge-0/0/1
I've checked and double checked the config. AWS has a standard set of IKE proposal options:
set security ike proposal ike-prop-aws authentication-method pre-shared-keys
set security ike proposal ike-prop-aws dh-group group2
set security ike proposal ike-prop-aws authentication-algorithm sha1
set security ike proposal ike-prop-aws encryption-algorithm aes-128-cbc
set security ike proposal ike-prop-aws lifetime-seconds 28800
The majority of the config comes straight from Amazon. There's nothing exotic going on. What am I missing?