IPSec VPN Cannot Build Due To Received Too Many Payload From Peer

|
  • 153
  • 7

Issue Description

NGAF and Mikrotik build IPSec VPN unsuccesful. In NGAF system log show warning received too many payload as figure shown below:
Noted: Mikrotik in aggressive mode.

Handling Process

  • Check the phase 1 and phase 2 setting in both side is same.
  • Try packet capture found out Mikrotik request to NGAF first.
  • Analyse the packet capture found out the receive many payload.
  • Consult with specialist get conclusion that in dlan version 6.2.0 and above there is limitation in payload number.





Root Cause

New dlan version has limit the number of payload during phase 1 negotiation.

Solution

  • If user environment is not a NAT environment can disable the NAT travesal.
  • Get patch form Sangfor Support to increase the limit.





Faisal Posted 22 Aug 2020 06:58
  
Thank you very much for the information ...
Muhammad Bilal Lv4Posted 18 Sep 2020 01:28
  

Good solution
Faisal Posted 21 Oct 2020 08:41
  
Nice article ...
Faisal Posted 19 Dec 2020 10:37
  
Great info ...
Ellechar Lv4Posted 25 Jan 2021 16:45
  
Very nice infoooooooooooooooooooooooooooooo
Faisal Posted 20 Mar 2021 08:55
  
Very informative …
Faisal Posted 05 Jun 2021 00:10
  
Nice guidance ...

I want to write a case
Doc ID: 2367
Author: Niubility
Updated: 2019-12-22 16:47
Version: