Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Re: ike SA unusable and ike No proposal chosen

$
0
0

Hello,

 

217.12.253.226 <-> 83.234.107.110]  iked_pm_phase1_sa_cfg_lookup_by_addr: Address based phase 1 SA-CFG lookup failed for local:217.12.253.226, remote:83.234.107.110 IKEv1 
[Jan 30 17:52:24][217.12.253.226 <-> 83.234.107.110]  iked_pm_ike_spd_select_ike_sa failed. rc 1, error_code: No proposal chosen
[Jan 30 17:52:24][217.12.253.226 <-> 83.234.107.110]  ikev2_fb_spd_select_sa_cb: IKEv2 SA select failed with error No proposal chosen (neg dfe000)

Translation: 217.12.253.226 does not know anything about 83.234.107.110.

Please post here the following output FROM 217.12.253.226 , sanitized if You care:

 

show configuration security ike | display set | match 83.234.107.110 | no-more

If there is an output, then "restart ipsec-key-management" on 217.12.253.226 could help.

Another but rare possibility is that You may have duplicate IPs in Your network.

HTH

Thx

Alex


Viewing all articles
Browse latest Browse all 17645

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>