I deleted the VPN monitor config and started getting 2 SA:
login@Dallas_SRX> show security ike security-associations Index State Initiator cookie Responder cookie Mode Remote Address 4733962 DOWN d7731d80bcc3eb2f c21467dc73b9c078 Main 1.1.1.1 4733963 DOWN eead14a237a74d60 0000000000000000 Main 1.1.1.1
Then in the KMD log i was getting Invalid syntax
May 22 18:05:48 Dallas_SRX kmd[1458]: Config download time: 0 seconds May 22 18:05:52 Dallas_SRX kmd[1458]: IKE negotiation failed with error: SA unusable. IKE Version: 1, VPN: Not-Available Gateway: Not-Available, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0 May 22 18:06:20 Dallas_SRX kmd[1458]: IKE negotiation failed with error: Invalid syntax. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0 May 22 18:06:52 Dallas_SRX kmd[1458]: IKE negotiation failed with error: SA unusable. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0 May 22 18:07:15 Dallas_SRX kmd[1458]: IKE negotiation failed with error: Invalid syntax. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0 May 22 18:07:52 Dallas_SRX kmd[1458]: IKE negotiation failed with error: SA unusable. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0 May 22 18:08:17 Dallas_SRX kmd[1458]: IKE negotiation failed with error: Invalid syntax. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0 May 22 18:08:52 Dallas_SRX kmd[1458]: IKE negotiation failed with error: SA unusable. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0 May 22 18:09:14 Dallas_SRX kmd[1458]: IKE negotiation failed with error: Invalid syntax. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0 May 22 18:09:52 Dallas_SRX kmd[1458]: IKE negotiation failed with error: SA unusable. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0 May 22 18:10:14 Dallas_SRX kmd[1458]: IKE negotiation failed with error: Invalid syntax. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0 May 22 18:10:52 Dallas_SRX kmd[1458]: IKE negotiation failed with error: SA unusable. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0 May 22 18:11:14 Dallas_SRX kmd[1458]: IKE negotiation failed with error: Invalid syntax. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0 May 22 18:11:52 Dallas_SRX kmd[1458]: IKE negotiation failed with error: SA unusable. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0 May 22 18:12:17 Dallas_SRX kmd[1458]: IKE negotiation failed with error: Invalid syntax. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0 May 22 18:12:52 Dallas_SRX kmd[1458]: IKE negotiation failed with error: SA unusable. IKE Version: 1, VPN: Colo_VPN Gateway: gw_Colo_VPN, Local: 2.2.2.2/500, Remote: 1.1.1.1/500, Local IKE-ID: Not-Available, Remote IKE-ID: Not-Available, VR-ID: 0
I have re-entered the PSK twice and had the hosting company re-enter the PSK on the SSG140 and still getting this.
ARGH!