Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Re: ipsec vpn config on MX80 MIC card

$
0
0

Hi aarseniev, 

 

I set following: 

 

set remote-id fqdn K9143116144.nokiasiemensnetworks.com

and this is a result: 

 

ipsec-ike_log

 

Sep 21 08:21:53 [10.42.131.81 <-> 10.42.147.32] ike_get_sa: Invalid cookie, no sa found, SA = { 13bbb675 1d69b340 - bbaef3ce a9b3e4ec 

} / 00000000, remote = 10.42.147.32:500
Sep 21 08:21:53 [10.42.131.81 <-> 10.42.147.32] unknown (unknown) <-> unknown { unknown [unknown] / unknown } unknown; Packet to 

unknown Isakmp SA, ip = 10.42.147.32:500
Sep 21 08:22:09 [10.42.131.81 <-> 10.42.147.32] ikev2_fb_request_certificates_cb: No certificates found
Sep 21 08:22:09 [10.42.131.81 <-> 10.42.147.32] 10.42.131.81:500 (Initiator) <-> 10.42.147.32:500 { a7d43999 ed5a640a - fcab90e7 

e0842c4b [-1] / 0x00000000 } IP; Warning, junk after packet len = 208, decoded = 205
Sep 21 08:22:09 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet <1> ca parsing pos <4>, in len<2744>.
Sep 21 08:22:09 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet ca <0> cert<0> parsing pos <8>.
Sep 21 08:22:09 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet ca <0> cert<1> parsing pos <1282>.
Sep 21 08:22:10 [10.42.131.81 <-> 10.42.147.32] kmd_policy_request_certificates: got certificate info

Sep 21 08:22:13 [10.42.131.81 <-> 10.42.147.32] ike_get_sa: Invalid cookie, no sa found, SA = { 13bbb675 1d69b340 - bbaef3ce a9b3e4ec 

} / 00000000, remote = 10.42.147.32:500
Sep 21 08:22:13 [10.42.131.81 <-> 10.42.147.32] unknown (unknown) <-> unknown { unknown [unknown] / unknown } unknown; Packet to 

unknown Isakmp SA, ip = 10.42.147.32:500
Sep 21 08:23:05 [10.42.131.81 <-> 10.42.147.32] ike_retransmit_callback: Isakmp query retry limit reached, deleting
Sep 21 08:23:05 [10.42.131.81 <-> 10.42.147.32] 10.42.131.81:500 (Initiator) <-> 10.42.147.32:500 { a7d43999 ed5a640a - fcab90e7 

e0842c4b [-1] / 0x00000000 } IP; Error = Timeout (8197)
Sep 21 08:23:05 [10.42.131.81 <-> 10.42.147.32] ike_send_notify: Private notification, do not send notification
Sep 21 08:23:05 [10.42.131.81 <-> 10.42.147.32] IKE SA negotiation failed for remote-ip:10.42.147.32,do tunnel failover
Sep 21 08:23:05 [10.42.131.81 <-> 10.42.147.32]   IKEv1 Error : Timeout
Sep 21 08:23:05 [10.42.131.81 <-> 10.42.147.32] kmd_pm_ipsec_sa_done_callback:IPSEC SA setup timedout
Sep 21 08:23:05 [10.42.131.81 <-> 10.42.147.32] IKE SA not usable 1c77000, error 65540
Sep 21 08:23:05 [10.42.131.81 <-> 10.42.147.32] Removing DPD server entry for remote peer: 10.42.147.32:500
Sep 21 08:23:24 [10.42.131.81 <-> 10.42.147.32] ikev2_fb_request_certificates_cb: No certificates found
Sep 21 08:23:24 [10.42.131.81 <-> 10.42.147.32] 10.42.131.81:500 (Initiator) <-> 10.42.147.32:500 { ab180428 13496ab9 - 5e40d82a 

44407b35 [-1] / 0x00000000 } IP; Warning, junk after packet len = 208, decoded = 205
Sep 21 08:23:24 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet <1> ca parsing pos <4>, in len<2744>.
Sep 21 08:23:24 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet ca <0> cert<0> parsing pos <8>.
Sep 21 08:23:24 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet ca <0> cert<1> parsing pos <1282>.
Sep 21 08:23:25 [10.42.131.81 <-> 10.42.147.32] kmd_policy_request_certificates: got certificate info

Sep 21 08:23:34 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet <1> ca parsing pos <4>, in len<2744>.
Sep 21 08:23:34 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet ca <0> cert<0> parsing pos <8>.
Sep 21 08:23:34 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet ca <0> cert<1> parsing pos <1282>.
Sep 21 08:23:35 [10.42.131.81 <-> 10.42.147.32] kmd_policy_request_certificates: got certificate info

Sep 21 08:23:35 [10.42.131.81 <-> 10.42.147.32] kmd_pm_ike_match_remote_id: Remote ID check failed for received der_asn1_dn(any:0,

[0..81]=CN=K9143116144.nokiasiemensnetworks.com, O=Nokia Siemens Networks)
Sep 21 08:23:35 [10.42.131.81 <-> 10.42.147.32] kmd_pm_ike_match_remote_id: remote ID check failed
Sep 21 08:23:35 [10.42.131.81 <-> 10.42.147.32] IKE SA negotiation failed for remote-ip:10.42.147.32,do tunnel failover
Sep 21 08:23:35 [10.42.131.81 <-> 10.42.147.32] Removing DPD server entry for remote peer: 10.42.147.32:500

pki_log

 

Sep 21 08:21:43 CERT VERIFIED: /CN=K9143116144.nokiasiemensnetworks.com/O=Nokia Siemens Networks
Sep 21 08:21:43 pkid_retrieve_obj_from_lhash, try retrieve obj from lhash type <2> for id <CA_Level_L1a>
Sep 21 08:21:43 pkid_retrieve_obj_from_lhash, retrieved obj from lhash for id <CA_Level_L1a>
Sep 21 08:21:43 Cert-Chain-Val> warning: Revocation Check skipped
Sep 21 08:21:43
Sep 21 08:21:43 Cert-Chain-Val> Cert-Chian Validation Cur<0> Total<2>
Sep 21 08:21:43 Cert-Chain-Val> at end
Sep 21 08:21:43 ldapNotify_func
Sep 21 08:21:43 Top of chain verified ok: /CN=K9143116144.nokiasiemensnetworks.com/O=Nokia Siemens Networks
Sep 21 08:21:43 cert verified ok: /CN=K9143116144.nokiasiemensnetworks.com/O=Nokia Siemens Networks
Sep 21 08:21:43 ldapIdleCleanup <28><104><243><22>
Sep 21 08:21:43 pCert_no_buf: /CN=K9143116144.nokiasiemensnetworks.com/O=Nokia Siemens Networks
Sep 21 08:21:43 pCert_with_buf: /CN=K9143116144.nokiasiemensnetworks.com/O=Nokia Siemens Networks
Sep 21 08:21:43 pCaCert: /DC=NSN Ulm/CN=Root CA
Sep 21 08:21:43  p_cert_stack: /CN=K9143116144.nokiasiemensnetworks.com/O=Nokia Siemens Networks
Sep 21 08:21:43 scep_http_release_all: releasing LDAP-STATE 192ed00
Sep 21 08:21:43 pkid_ipc_send: Queued packet to IKED-Q, len 1324
Sep 21 08:21:43 pkid_ipc_write: Sending packet to IKED len 1324, total packets sent 60

when I added following command - nothing really changed: 

 

ep 21 08:25:50 [10.42.131.81 <-> 10.42.147.32] ike_retransmit_callback: Isakmp query retry limit reached, deleting
Sep 21 08:25:50 [10.42.131.81 <-> 10.42.147.32] 10.42.131.81:500 (Initiator) <-> 10.42.147.32:500 { 07236698 58cccc8f - 678d3943 

52f1e262 [-1] / 0x00000000 } IP; Error = Timeout (8197)
Sep 21 08:25:50 [10.42.131.81 <-> 10.42.147.32] ike_send_notify: Private notification, do not send notification
Sep 21 08:25:50 [10.42.131.81 <-> 10.42.147.32] IKE SA negotiation failed for remote-ip:10.42.147.32,do tunnel failover
Sep 21 08:25:50 [10.42.131.81 <-> 10.42.147.32]   IKEv1 Error : Timeout
Sep 21 08:25:50 [10.42.131.81 <-> 10.42.147.32] kmd_pm_ipsec_sa_done_callback:IPSEC SA setup timedout
Sep 21 08:25:50 [10.42.131.81 <-> 10.42.147.32] IKE SA not usable 1c77000, error 65540
Sep 21 08:25:50 [10.42.131.81 <-> 10.42.147.32] Removing DPD server entry for remote peer: 10.42.147.32:500
Sep 21 08:25:54 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet <1> ca parsing pos <4>, in len<2744>.
Sep 21 08:25:54 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet ca <0> cert<0> parsing pos <8>.
Sep 21 08:25:54 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet ca <0> cert<1> parsing pos <1282>.
Sep 21 08:25:55 [10.42.131.81 <-> 10.42.147.32] kmd_policy_request_certificates: got certificate info

Sep 21 08:25:55 [10.42.131.81 <-> 10.42.147.32] kmd_pm_ike_match_remote_id: Remote ID check failed for received der_asn1_dn(any:0,

[0..81]=CN=K9143116144.nokiasiemensnetworks.com, O=Nokia Siemens Networks)
Sep 21 08:25:55 [10.42.131.81 <-> 10.42.147.32] kmd_pm_ike_match_remote_id: remote ID check failed
Sep 21 08:25:55 [10.42.131.81 <-> 10.42.147.32] IKE SA negotiation failed for remote-ip:10.42.147.32,do tunnel failover
Sep 21 08:25:55 [10.42.131.81 <-> 10.42.147.32] Removing DPD server entry for remote peer: 10.42.147.32:500
Sep 21 08:26:04 [10.42.131.81 <-> 10.42.147.32] ike_get_sa: Invalid cookie, no sa found, SA = { cfedc264 cc08f7ce - c1672a01 2f262e8a 

} / 00000000, remote = 10.42.147.32:500
Sep 21 08:26:04 [10.42.131.81 <-> 10.42.147.32] unknown (unknown) <-> unknown { unknown [unknown] / unknown } unknown; Packet to 

unknown Isakmp SA, ip = 10.42.147.32:500
Sep 21 08:26:09 [10.42.131.81 <-> 10.42.147.32] ikev2_fb_request_certificates_cb: No certificates found
Sep 21 08:26:09 [10.42.131.81 <-> 10.42.147.32] 10.42.131.81:500 (Initiator) <-> 10.42.147.32:500 { f832cf2a fac168ba - c6246442 

215a79b9 [-1] / 0x00000000 } IP; Warning, junk after packet len = 208, decoded = 205
Sep 21 08:26:09 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet <1> ca parsing pos <4>, in len<2744>.
Sep 21 08:26:09 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet ca <0> cert<0> parsing pos <8>.
Sep 21 08:26:09 [10.42.131.81 <-> 10.42.147.32] parse_request_certificate_rep_packet ca <0> cert<1> parsing pos <1282>.
Sep 21 08:26:10 [10.42.131.81 <-> 10.42.147.32] kmd_policy_request_certificates: got certificate info

For clarity, I added all security config after modyfication - attached in txt file

 

here is a status for ike: 

 

run show services ipsec-vpn ike security-associations
Remote Address  State         Initiator cookie  Responder cookie  Exchange type
10.42.147.32    Not matured   c729818010bd4766  0000000000000000  Main

 

 

 

 


Viewing all articles
Browse latest Browse all 17645

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>