Hello, its been a while.
I am having problems setting up GRE over IPSEC. I have spent most of the day on it and I am stumped. Hoping someone on the forum can provide some guidance, as the web resources do not solve the issue.
Anyway the setup is MT 6.0rc11 connecting to NetScreen FW (not my choice).
MT public WAN IP is 63.224.89.XXX
Peer is 129.196.225.XXX
GRE TUNNEL FNET
Local 192.65.0.59
Remote 192.65.0.66
IP Address GRE FNET 192.65.1.94/30 other end is 192.65.1.93/30
The Peer setup is 129.196.XXX.XXX
IPSEC POLICY
SRC-ADDRESS = 192.65.0.59
DST-ADDRESS = 192.65.0.66
SA-SRC-ADDRESS = 63.224.XXX.XXX
SA-DST-ADDRESS = 129.196.XXX.XXX
When I ping via FNET to 192.65.1.93 the log shows nothing happening with IPSEC. If I change IPSEC POLICY to:
SRC-ADDRESS = 192.65.1.94
DST-ADDRESS = 192.65.1.93
And then ping via FNET to 192.5.1.93 the IPSEC tunnel passes Phase 1 and gets stuck on Phase 2 where the NetScreen FW complains about the policy not being correct. The MT shows two different SA certs that time out.
At this point I am stumped. I was certain that the SRC-ADDRESS needs to be 192.65.0.59 and DST-ADDRESS should be 192.65.0.66. I am hoping someone on the board can tell me what I am doing wrong. I have added the SRC-NAT ACCEPT RULES. I have also turned off all firewall rules to minimize other road blocks.
PS: IP addresses have been modified to protect the innocent .
Clinton W.