Fails to build IPSec connection (3rd Party connection)

|
  • 214
  • 10

Issue Description

Customer configured IPSec 3rd party connection between 2 NGAF, VPN tunnel is not online and system log shows following error.
Primary NGAF: IKE SPI is invalid.
Secondary NGAF: Sent notifications, Format is invalid.

Error/Warning Information

Handling Process

1. Understand the situation, previously the VPN is build up with 3rd party device and now changed to NGAF - NGAF.
2. Check on the branch NGAF configurations, Phase 1 settings shows different public IP compared on the logs.

3. Confirmed with user and changed the branch NGAF Phase 1 peer IP address.

4. Compared Phase 1 settings on both side, it matches.

5. VPN still fails to build up, each side showing different error.

6. Checking on primary NGAF, found that the WAN network is a private IP. (192.168.x.x). It is then learnt that the primary NGAF connect to an ISP router. (NAT environment)
An illustration of the said topology:
NGAF A -- ISP Router -- ISP Modem <-------> ISP Modem -- NGAF B

7. Configured Local ID and Peer ID on both sides of NGAF. (This is required when either side of WAN zone has NAT configured).

Root Cause

Environment issue, NAT exist on either side WAN network.

Solution

Configure Local ID and Peer ID on both sides.
Hamid Hussain Lv2Posted 10 Mar 2022 22:23
  
well defined
Apriyanto Lv5Posted 14 Mar 2022 20:38
  
very helpful      
Faisal Posted 03 Apr 2022 16:41
  
Raza Islam Lv3Posted 11 Jun 2022 13:37
  
Thanks for sharing.
Raza Islam Lv3Posted 19 Jul 2022 19:42
  
thanks for command.
Faisal P Posted 19 Sep 2022 21:32
  
Thank you very much for the information ...
Faisal P Posted 19 Sep 2022 21:33
  
Nice article ...
Faisal P Posted 19 Sep 2022 21:33
  
Great info ...
Faisal P Posted 19 Sep 2022 21:33
  
Very informative ...

I want to write a case
Doc ID: 5858
Author: Sangfor_Siva
Updated: 2022-03-07 12:59
Version: