Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: Phase2 failure message with there was preexisting session from the same peer

$
0
0

Another question - do all these 3 spokes sit behind the same NAT device or different ones?

 

There is a small chance that the NAT entry on the NAT-ing box expired. So, when P2 gets renegotiated, it would PAT to a different port that might cause this issue. You can turn ON DPD or Heartbeat to keep the IKE session active on the NAT-ing device.

 

It is a fairly long shot, but worth considering Smiley WinkSmiley WinkSmiley Wink


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>