Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Re: Replacing a SSG5 with SRX100H2 in branch office

$
0
0

I deleted the VPN monitor config and started getting 2 SA:

login@Dallas_SRX> show security ike security-associations
Index   State  Initiator cookie  Responder cookie  Mode           Remote Address
4733962 DOWN   d7731d80bcc3eb2f  c21467dc73b9c078  Main           1.1.1.1
4733963 DOWN   eead14a237a74d60  0000000000000000  Main           1.1.1.1

Then in the KMD log i was getting Invalid syntax

May 22 18:05:48  Dallas_SRX kmd[1458]: Config download time: 0 seconds
May 22 18:05:52  Dallas_SRX kmd[1458]: IKE negotiation failed with error: SA unusable. IKE Version: 1, VPN: Not-Available Gateway: Not-Available, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0
May 22 18:06:20  Dallas_SRX kmd[1458]: IKE negotiation failed with error: Invalid syntax. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0
May 22 18:06:52  Dallas_SRX kmd[1458]: IKE negotiation failed with error: SA unusable. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0
May 22 18:07:15  Dallas_SRX kmd[1458]: IKE negotiation failed with error: Invalid syntax. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0
May 22 18:07:52  Dallas_SRX kmd[1458]: IKE negotiation failed with error: SA unusable. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0
May 22 18:08:17  Dallas_SRX kmd[1458]: IKE negotiation failed with error: Invalid syntax. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0
May 22 18:08:52  Dallas_SRX kmd[1458]: IKE negotiation failed with error: SA unusable. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0
May 22 18:09:14  Dallas_SRX kmd[1458]: IKE negotiation failed with error: Invalid syntax. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0
May 22 18:09:52  Dallas_SRX kmd[1458]: IKE negotiation failed with error: SA unusable. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0
May 22 18:10:14  Dallas_SRX kmd[1458]: IKE negotiation failed with error: Invalid syntax. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0
May 22 18:10:52  Dallas_SRX kmd[1458]: IKE negotiation failed with error: SA unusable. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0
May 22 18:11:14  Dallas_SRX kmd[1458]: IKE negotiation failed with error: Invalid syntax. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0
May 22 18:11:52  Dallas_SRX kmd[1458]: IKE negotiation failed with error: SA unusable. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0
May 22 18:12:17  Dallas_SRX kmd[1458]: IKE negotiation failed with error: Invalid syntax. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0
May 22 18:12:52  Dallas_SRX kmd[1458]: IKE negotiation failed with error: SA unusable. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0

I have re-entered the PSK twice and had the hosting company re-enter the PSK on the SSG140 and still getting this.

 

ARGH!


Viewing all articles
Browse latest Browse all 17645

Trending Articles