Im trying to connect a MAC OS10 client to my Tipping Point x506 firewall. The connection never connects and each time I recieve the following message in the logs doe sayone know what the:
Rejecting phase 1 SA due to IKE proposal mismatch
means
Main mode responder received message 1 Rcvd Msg, 344 bytes: HDR[MM], [ SA(172) VENDOR_ID(24) VENDOR_ID(20) VENDOR_ID(20) VENDOR_ID(20)
VENDOR_ID(20) VENDOR_ID(20) VENDOR_ID(20)]| , cookies: 3398C2AD1339A8F3 / 0000000000000000, msg id: 0
Proposal 1 -- protocol ISAKMP, 4 transforms
Transform 1 KEY_IKE:AES_CBC | 32 bytes key | SHA_HASH | GroupDescription: unsupported 20 | PRESHARED_KEY | SECONDS | 28800 |
Transform 2 KEY_IKE:AES_CBC | 16 bytes key | SHA_HASH | GroupDescription: unsupported 19 | PRESHARED_KEY | SECONDS | 28800 |
Transform 3 KEY_IKE:TRIPLEDES_CBC | SHA_HASH | GroupDescription: unsupported 14 | PRESHARED_KEY | SECONDS | 28800 |
Transform 4 KEY_IKE:TRIPLEDES_CBC | SHA_HASH | DH_GROUP_2(MODP_1024) | PRESHARED_KEY | SECONDS | 28800 |
Rejecting phase 1 SA due to IKE proposal mismatch
Rejecting phase 1 SA due to IKE proposal mismatch
means
Main mode responder received message 1 Rcvd Msg, 344 bytes: HDR[MM], [ SA(172) VENDOR_ID(24) VENDOR_ID(20) VENDOR_ID(20) VENDOR_ID(20)
VENDOR_ID(20) VENDOR_ID(20) VENDOR_ID(20)]| , cookies: 3398C2AD1339A8F3 / 0000000000000000, msg id: 0
Proposal 1 -- protocol ISAKMP, 4 transforms
Transform 1 KEY_IKE:AES_CBC | 32 bytes key | SHA_HASH | GroupDescription: unsupported 20 | PRESHARED_KEY | SECONDS | 28800 |
Transform 2 KEY_IKE:AES_CBC | 16 bytes key | SHA_HASH | GroupDescription: unsupported 19 | PRESHARED_KEY | SECONDS | 28800 |
Transform 3 KEY_IKE:TRIPLEDES_CBC | SHA_HASH | GroupDescription: unsupported 14 | PRESHARED_KEY | SECONDS | 28800 |
Transform 4 KEY_IKE:TRIPLEDES_CBC | SHA_HASH | DH_GROUP_2(MODP_1024) | PRESHARED_KEY | SECONDS | 28800 |
Rejecting phase 1 SA due to IKE proposal mismatch