Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

22,000 Errors/day site-to-site Sonicwalls

Status
Not open for further replies.

brokenhalo

IS-IT--Management
Feb 24, 2008
169
0
0
US
Hey guys,

I am getting these errors between two Sonicwall's in a site-to-site config and it's becoming really frustrating. Over 22,000 of the same exact two errors per day being logged. Now, I am beginning to believe that these errors are erronneous because the VPN itself works great. Here they are...

Network 1 Logs:
IKE Responder: No match for proposed remote network address
IKE Responder: IPSec proposal does not match (Phase 2)

Netwrok 2 Logs:
IKE Initiator: Start Quick Mode (Phase 2).
IKE Initiator: Received notify. NO_PROPOSAL_CHOSEN

I have read the big PDF provided by Sonicwall with common error messages and misc messages, and they say that the VPN settings on both sides don't match, even though they do... Perfectly! Exactly the same authentication, encryption, etc for both phase 1 and phase 2. I have checked and re-checked, and have also tried every other possible combination of different types of authentication, encryption, etc and still no joy. Any help at all is greatly appreciated.

Side Note: I have multiple other site-to-sites setup that work perfectly with no errors.

Brad L.
Systems Engineer
Prestige Technologies
bradlaszlo[at]prestigetech.com

"Some things Man was never meant to know. For everything else, there's Google.
 
That is exactly what the messages mean, but I would bet on an OS/firmware bug, no doubt. I would look on some SonicWall forums...

Burt
 
UPDATE:

Just in case anyone else comes across these errors, here is an answer I recieved from a Sonicwall support ticket...

Created By: Kris Robinson (5/7/2009 4:44 PM)
There is no problem with the configuration of your Site to Site, the problem you are having is related to Standard firmware. To be honest I would just ignore these messages, this wont cause issues with your tunnel and is related to the unit being in transparent mode. If the transparent unit was running Enhanced firmware you wouldnt see this behavior. Let me know if you have any more questions.

Sounds like a load of BS to me as both end of the tunnel have been updated with the latest firmware, but whatever. I will keep trying to find an answer to this, and if I get it figured out, will post back here with the results.

Brad L.
Systems Engineer
Prestige Technologies
bradlaszlo[at]prestigetech.com

"Some things Man was never meant to know. For everything else, there's Google.
 
I would downgrade to a known stable (or "mostly stable") firmware level. I really think it is firmware. There are no actual errors---just a bug that reports errors that are not there!

/
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top