Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: Site-to-site policy-based VPN between Juniper GT5 and Cisco 841

$
0
0

Hi,

 

GT% seems to be initiator and failing in message 6, cisco phase 1 is fine. Most probably it's ID mismatch so GT5 is failing in the peer auth. Can  you please check below :

 

1: What ids have you configured on the GT5 e.g:

 

-> set ike gateway test address x.x.x.x?
id                   Peer ID     <-- Cisco is supposed to send this ID, and should match with this config. e.g. IPs, certs etc.
local-id             Local Identity (optional)   <-- GT5 will send ID, by default it's source interface IP. This looks fine as Cisco is completing the phase 1.

 

2: Step 1 should fix the issues however, you can try reconfiguring the PSK on both the nodes.

 

Thanks,

Vikas


Viewing all articles
Browse latest Browse all 2577

Trending Articles