Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: IKE V2 NOTIFY_MSG_NAT_DETECTION_DESTINATION_IP

$
0
0

Did anyone get this working ? I am trying to setup Azure Route VPN with SSG5 ( with 6.1 software however - I realise that only 6.2 is verified with Azure) 

 

set sa-filter <Azure VPN IP>

debug ike detail

get db stream

 

## 2019-05-03 21:59:34 : IKEv2: 258c2b0 AZURE-GW reset DPD, no active p2 SA.
## 2019-05-03 21:59:45 : IKEv2: 258c2b0 AZURE-GW reset DPD, no active p2 SA.
## 2019-05-03 21:59:55 : IKEv2: 258c2b0 AZURE-GW reset DPD, no active p2 SA.

 

set ike p1-proposal "AZURE-P1_Proposal" preshare group2 esp aes256 sha-1 hour 8
set ike p2-proposal "AZURE-P2_Proposal" group2 esp aes256 sha-1 hour 3

set ike gateway "AZURE-GW" dpd-liveness interval 10
set ike respond-bad-spi 1
set ike gateway ikev2 "AZURE-GW" auth-method self preshare peer preshare
set ike ikev2 ike-sa-soft-lifetime 60

set vpn "AZURE-VPN" gateway "AZURE-GW" no-replay tunnel idletime 0 sec-level compatible
set vpn "AZURE-VPN" id 0x1 bind interface tunnel.1


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>