Hi aarseniev,
I set following:
set remote-id fqdn K9143116144.nokiasiemensnetworks.com
and this is a result:
ipsec-ike_log
Sep 21 08:21:53 [10.42.131.81 <-> 10.42.147.32] ike_get_sa: Invalid cookie, no sa found, SA = { 13bbb675 1d69b340 - bbaef3ce a9b3e4ec } / 00000000, remote = 10.42.147.32:500 Sep 21 08:21:53 [10.42.131.81 <-> 10.42.147.32] unknown (unknown) <-> unknown { unknown [unknown] / unknown } unknown; Packet to unknown Isakmp SA, ip = 10.42.147.32:500 Sep 21 08:22:09 [10.42.131.81 <-> 10.42.147.32] ikev2_fb_request_certificates_cb: No certificates found Sep 21 08:22:09 [10.42.131.81 <-> 10.42.147.32] 10.42.131.81:500 (Initiator) <-> 10.42.147.32:500 { a7d43999 ed5a640a - fcab90e7 e0842c4b [-1] / 0x00000000 } IP; Warning, junk after packet len = 208, decoded = 205 Sep 21 08:22:09 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet <1> ca parsing pos <4>, in len<2744>. Sep 21 08:22:09 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet ca <0> cert<0> parsing pos <8>. Sep 21 08:22:09 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet ca <0> cert<1> parsing pos <1282>. Sep 21 08:22:10 [10.42.131.81 <-> 10.42.147.32] kmd_policy_request_certificates: got certificate info Sep 21 08:22:13 [10.42.131.81 <-> 10.42.147.32] ike_get_sa: Invalid cookie, no sa found, SA = { 13bbb675 1d69b340 - bbaef3ce a9b3e4ec } / 00000000, remote = 10.42.147.32:500 Sep 21 08:22:13 [10.42.131.81 <-> 10.42.147.32] unknown (unknown) <-> unknown { unknown [unknown] / unknown } unknown; Packet to unknown Isakmp SA, ip = 10.42.147.32:500 Sep 21 08:23:05 [10.42.131.81 <-> 10.42.147.32] ike_retransmit_callback: Isakmp query retry limit reached, deleting Sep 21 08:23:05 [10.42.131.81 <-> 10.42.147.32] 10.42.131.81:500 (Initiator) <-> 10.42.147.32:500 { a7d43999 ed5a640a - fcab90e7 e0842c4b [-1] / 0x00000000 } IP; Error = Timeout (8197) Sep 21 08:23:05 [10.42.131.81 <-> 10.42.147.32] ike_send_notify: Private notification, do not send notification Sep 21 08:23:05 [10.42.131.81 <-> 10.42.147.32] IKE SA negotiation failed for remote-ip:10.42.147.32,do tunnel failover Sep 21 08:23:05 [10.42.131.81 <-> 10.42.147.32] IKEv1 Error : Timeout Sep 21 08:23:05 [10.42.131.81 <-> 10.42.147.32] kmd_pm_ipsec_sa_done_callback:IPSEC SA setup timedout Sep 21 08:23:05 [10.42.131.81 <-> 10.42.147.32] IKE SA not usable 1c77000, error 65540 Sep 21 08:23:05 [10.42.131.81 <-> 10.42.147.32] Removing DPD server entry for remote peer: 10.42.147.32:500 Sep 21 08:23:24 [10.42.131.81 <-> 10.42.147.32] ikev2_fb_request_certificates_cb: No certificates found Sep 21 08:23:24 [10.42.131.81 <-> 10.42.147.32] 10.42.131.81:500 (Initiator) <-> 10.42.147.32:500 { ab180428 13496ab9 - 5e40d82a 44407b35 [-1] / 0x00000000 } IP; Warning, junk after packet len = 208, decoded = 205 Sep 21 08:23:24 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet <1> ca parsing pos <4>, in len<2744>. Sep 21 08:23:24 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet ca <0> cert<0> parsing pos <8>. Sep 21 08:23:24 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet ca <0> cert<1> parsing pos <1282>. Sep 21 08:23:25 [10.42.131.81 <-> 10.42.147.32] kmd_policy_request_certificates: got certificate info Sep 21 08:23:34 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet <1> ca parsing pos <4>, in len<2744>. Sep 21 08:23:34 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet ca <0> cert<0> parsing pos <8>. Sep 21 08:23:34 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet ca <0> cert<1> parsing pos <1282>. Sep 21 08:23:35 [10.42.131.81 <-> 10.42.147.32] kmd_policy_request_certificates: got certificate info Sep 21 08:23:35 [10.42.131.81 <-> 10.42.147.32] kmd_pm_ike_match_remote_id: Remote ID check failed for received der_asn1_dn(any:0, [0..81]=CN=K9143116144.nokiasiemensnetworks.com, O=Nokia Siemens Networks) Sep 21 08:23:35 [10.42.131.81 <-> 10.42.147.32] kmd_pm_ike_match_remote_id: remote ID check failed Sep 21 08:23:35 [10.42.131.81 <-> 10.42.147.32] IKE SA negotiation failed for remote-ip:10.42.147.32,do tunnel failover Sep 21 08:23:35 [10.42.131.81 <-> 10.42.147.32] Removing DPD server entry for remote peer: 10.42.147.32:500
pki_log
Sep 21 08:21:43 CERT VERIFIED: /CN=K9143116144.nokiasiemensnetworks.com/O=Nokia Siemens Networks Sep 21 08:21:43 pkid_retrieve_obj_from_lhash, try retrieve obj from lhash type <2> for id <CA_Level_L1a> Sep 21 08:21:43 pkid_retrieve_obj_from_lhash, retrieved obj from lhash for id <CA_Level_L1a> Sep 21 08:21:43 Cert-Chain-Val> warning: Revocation Check skipped Sep 21 08:21:43 Sep 21 08:21:43 Cert-Chain-Val> Cert-Chian Validation Cur<0> Total<2> Sep 21 08:21:43 Cert-Chain-Val> at end Sep 21 08:21:43 ldapNotify_func Sep 21 08:21:43 Top of chain verified ok: /CN=K9143116144.nokiasiemensnetworks.com/O=Nokia Siemens Networks Sep 21 08:21:43 cert verified ok: /CN=K9143116144.nokiasiemensnetworks.com/O=Nokia Siemens Networks Sep 21 08:21:43 ldapIdleCleanup <28><104><243><22> Sep 21 08:21:43 pCert_no_buf: /CN=K9143116144.nokiasiemensnetworks.com/O=Nokia Siemens Networks Sep 21 08:21:43 pCert_with_buf: /CN=K9143116144.nokiasiemensnetworks.com/O=Nokia Siemens Networks Sep 21 08:21:43 pCaCert: /DC=NSN Ulm/CN=Root CA Sep 21 08:21:43 p_cert_stack: /CN=K9143116144.nokiasiemensnetworks.com/O=Nokia Siemens Networks Sep 21 08:21:43 scep_http_release_all: releasing LDAP-STATE 192ed00 Sep 21 08:21:43 pkid_ipc_send: Queued packet to IKED-Q, len 1324 Sep 21 08:21:43 pkid_ipc_write: Sending packet to IKED len 1324, total packets sent 60
when I added following command - nothing really changed:
ep 21 08:25:50 [10.42.131.81 <-> 10.42.147.32] ike_retransmit_callback: Isakmp query retry limit reached, deleting Sep 21 08:25:50 [10.42.131.81 <-> 10.42.147.32] 10.42.131.81:500 (Initiator) <-> 10.42.147.32:500 { 07236698 58cccc8f - 678d3943 52f1e262 [-1] / 0x00000000 } IP; Error = Timeout (8197) Sep 21 08:25:50 [10.42.131.81 <-> 10.42.147.32] ike_send_notify: Private notification, do not send notification Sep 21 08:25:50 [10.42.131.81 <-> 10.42.147.32] IKE SA negotiation failed for remote-ip:10.42.147.32,do tunnel failover Sep 21 08:25:50 [10.42.131.81 <-> 10.42.147.32] IKEv1 Error : Timeout Sep 21 08:25:50 [10.42.131.81 <-> 10.42.147.32] kmd_pm_ipsec_sa_done_callback:IPSEC SA setup timedout Sep 21 08:25:50 [10.42.131.81 <-> 10.42.147.32] IKE SA not usable 1c77000, error 65540 Sep 21 08:25:50 [10.42.131.81 <-> 10.42.147.32] Removing DPD server entry for remote peer: 10.42.147.32:500 Sep 21 08:25:54 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet <1> ca parsing pos <4>, in len<2744>. Sep 21 08:25:54 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet ca <0> cert<0> parsing pos <8>. Sep 21 08:25:54 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet ca <0> cert<1> parsing pos <1282>. Sep 21 08:25:55 [10.42.131.81 <-> 10.42.147.32] kmd_policy_request_certificates: got certificate info Sep 21 08:25:55 [10.42.131.81 <-> 10.42.147.32] kmd_pm_ike_match_remote_id: Remote ID check failed for received der_asn1_dn(any:0, [0..81]=CN=K9143116144.nokiasiemensnetworks.com, O=Nokia Siemens Networks) Sep 21 08:25:55 [10.42.131.81 <-> 10.42.147.32] kmd_pm_ike_match_remote_id: remote ID check failed Sep 21 08:25:55 [10.42.131.81 <-> 10.42.147.32] IKE SA negotiation failed for remote-ip:10.42.147.32,do tunnel failover Sep 21 08:25:55 [10.42.131.81 <-> 10.42.147.32] Removing DPD server entry for remote peer: 10.42.147.32:500 Sep 21 08:26:04 [10.42.131.81 <-> 10.42.147.32] ike_get_sa: Invalid cookie, no sa found, SA = { cfedc264 cc08f7ce - c1672a01 2f262e8a } / 00000000, remote = 10.42.147.32:500 Sep 21 08:26:04 [10.42.131.81 <-> 10.42.147.32] unknown (unknown) <-> unknown { unknown [unknown] / unknown } unknown; Packet to unknown Isakmp SA, ip = 10.42.147.32:500 Sep 21 08:26:09 [10.42.131.81 <-> 10.42.147.32] ikev2_fb_request_certificates_cb: No certificates found Sep 21 08:26:09 [10.42.131.81 <-> 10.42.147.32] 10.42.131.81:500 (Initiator) <-> 10.42.147.32:500 { f832cf2a fac168ba - c6246442 215a79b9 [-1] / 0x00000000 } IP; Warning, junk after packet len = 208, decoded = 205 Sep 21 08:26:09 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet <1> ca parsing pos <4>, in len<2744>. Sep 21 08:26:09 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet ca <0> cert<0> parsing pos <8>. Sep 21 08:26:09 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet ca <0> cert<1> parsing pos <1282>. Sep 21 08:26:10 [10.42.131.81 <-> 10.42.147.32] kmd_policy_request_certificates: got certificate info
For clarity, I added all security config after modyfication - attached in txt file
here is a status for ike:
run show services ipsec-vpn ike security-associations Remote Address State Initiator cookie Responder cookie Exchange type 10.42.147.32 Not matured c729818010bd4766 0000000000000000 Main