jamesjames1
Technical User
Hi,
I am trying to get a tunnel up between a Cisco 800 series router and a Netscreen SSG box.
I am failing on Phase 1 of the negotiations. From what I can work out the initiating VPN box (netscreen) isnt receiving a reply from the cisco and therefore failing on phase 1.
I know that both machines are seeing each other as on botht eh NS and cisco are logging the same type of thing. I dont have access to the cisco but do the NS.
The logs on the NS are not good but are basically a debug on the IKE.
I have chedked the SA life times on both, I have checked that the phase 1 proposals are matching and they are. I am fairly familiar with juniper and am used to seeing some sort of useful error.
Does anyone have any ideas where to look, what is up?
I have succesfully initiated a tunel between the same router and a different Juniper SSG box with out any issues....
Here are my logs..
## 2008-08-06 22:43:45 : IKE<2.2.2.2> re-trans timer expired, msg retry (9) (10003/1)
## 2008-08-06 22:43:45 : IKE<2.2.2.2> Responder sending IPv4 IP 2.2.2.2/port 500
## 2008-08-06 22:43:45 : IKE<2.2.2.2> Send Phase 1 packet (len=160)
## 2008-08-06 22:43:45 : IKE<2.2.2.2> ike packet, len 208, action 1
## 2008-08-06 22:43:45 : IKE<2.2.2.2> Catcher: received 180 bytes from socket.
## 2008-08-06 22:43:45 : IKE<2.2.2.2> ****** Recv packet if <ethernet1/1> of vsys <Root> ******
## 2008-08-06 22:43:45 : IKE<2.2.2.2> Catcher: get 180 bytes. src port 500
## 2008-08-06 22:43:45 : IKE<0.0.0.0 > ISAKMP msg: len 180, nxp 1[SA], exch 2[MM], flag 00
## 2008-08-06 22:43:45 : IKE<2.2.2.2 > Recv : [SA] [VID] [VID] [VID]
## 2008-08-06 22:43:45 : IKE<2.2.2.2> Receive re-transmit IKE packet phase 1 SA(2.2.2.2) exchg(2) len(180)
## 2008-08-06 22:43:49 : IKE<2.2.2.2> re-trans timer expired, msg retry (10) (10003/1)
## 2008-08-06 22:43:49 : IKE<2.2.2.2> Responder sending IPv4 IP 2.2.2.2/port 500
## 2008-08-06 22:43:49 : IKE<2.2.2.2> Send Phase 1 packet (len=160)
I am trying to get a tunnel up between a Cisco 800 series router and a Netscreen SSG box.
I am failing on Phase 1 of the negotiations. From what I can work out the initiating VPN box (netscreen) isnt receiving a reply from the cisco and therefore failing on phase 1.
I know that both machines are seeing each other as on botht eh NS and cisco are logging the same type of thing. I dont have access to the cisco but do the NS.
The logs on the NS are not good but are basically a debug on the IKE.
I have chedked the SA life times on both, I have checked that the phase 1 proposals are matching and they are. I am fairly familiar with juniper and am used to seeing some sort of useful error.
Does anyone have any ideas where to look, what is up?
I have succesfully initiated a tunel between the same router and a different Juniper SSG box with out any issues....
Here are my logs..
## 2008-08-06 22:43:45 : IKE<2.2.2.2> re-trans timer expired, msg retry (9) (10003/1)
## 2008-08-06 22:43:45 : IKE<2.2.2.2> Responder sending IPv4 IP 2.2.2.2/port 500
## 2008-08-06 22:43:45 : IKE<2.2.2.2> Send Phase 1 packet (len=160)
## 2008-08-06 22:43:45 : IKE<2.2.2.2> ike packet, len 208, action 1
## 2008-08-06 22:43:45 : IKE<2.2.2.2> Catcher: received 180 bytes from socket.
## 2008-08-06 22:43:45 : IKE<2.2.2.2> ****** Recv packet if <ethernet1/1> of vsys <Root> ******
## 2008-08-06 22:43:45 : IKE<2.2.2.2> Catcher: get 180 bytes. src port 500
## 2008-08-06 22:43:45 : IKE<0.0.0.0 > ISAKMP msg: len 180, nxp 1[SA], exch 2[MM], flag 00
## 2008-08-06 22:43:45 : IKE<2.2.2.2 > Recv : [SA] [VID] [VID] [VID]
## 2008-08-06 22:43:45 : IKE<2.2.2.2> Receive re-transmit IKE packet phase 1 SA(2.2.2.2) exchg(2) len(180)
## 2008-08-06 22:43:49 : IKE<2.2.2.2> re-trans timer expired, msg retry (10) (10003/1)
## 2008-08-06 22:43:49 : IKE<2.2.2.2> Responder sending IPv4 IP 2.2.2.2/port 500
## 2008-08-06 22:43:49 : IKE<2.2.2.2> Send Phase 1 packet (len=160)