Having a hard time getting a vpn up and running. THe other side is a Sonicwall(which we don't/can't control).
We seem to get most of the connection up, but we see the following, and no traffic flows:
Code: Select all
/ip ipsec remote-peers print
0 local-address= remote-address= state=established side=initiator established=6m30s
Code: Select all
> /ip ipsec installed-sa print
Flags: A - AH, E - ESP, P - pfs
0 E spi=0 src-address= dst-address= auth-algorithm=none enc-algorithm=none replay=0 state=larval add-lifetime=0s/30s
1 E spi=0x34B00AB src-address= dst-address= auth-algorithm=none enc-algorithm=none replay=0 state=larval
Code: Select all
echo: ipsec,debug fatal INVALID-ID-INFORMATION notify messsage, phase1 should be deleted.
echo: ipsec,debug,packet notification message 18:INVALID-ID-INFORMATION, doi=1 proto_id=3 spi=0c431bd2(size=4).
Code: Select all
Flags: T - template, X - disabled, D - dynamic, I - inactive
0 src-address= src-port=any dst-address= dst-port=any protocol=all action=encrypt level=require
ipsec-protocols=esp tunnel=yes sa-src-address= sa-dst-address= proposal=sonicwall-asa priority=0
Code: Select all
address= passive=no port=500 auth-method=pre-shared-key secret="password" generate-policy=no exchange-mode=main
send-initial-contact=yes nat-traversal=yes proposal-check=obey hash-algorithm=sha1 enc-algorithm=3des dh-group=modp1024 lifetime=8h
lifebytes=0 dpd-interval=2m dpd-maximum-failures=5
Code: Select all
echo: ipsec IPsec-SA expired: ESP/Tunnel[0]->[0] spi=234896348(0xe003bdc
Code: Select all
0 chain=srcnat action=accept src-address= dst-address=
Code: Select all
4 11/14/2013 08:09:49.512 Warning VPN IKE IKE Responder: Peer's network does not match VPN policy's Network, 500, 500 VPN Policy: AAA;
.255.255.0;Local: ->10.8
1.25.0 /
5 11/14/2013 08:09:49.496 Info VPN IKE IKE Responder: Received Quick Mode Request (Phase 2), 500, 500 VPN Policy: AAA
6 11/14/2013 08:09:39.144 Warning VPN IKE IKE Responder: IPSec proposal does not match (Phase 2), 500, 500 VPN Policy: AAA
Any thoughts?
Thanks in advance,