So i have a need for connecting a remote site (trailer) using cellular to our main SSG140 @ our datacenter. We purchased a Netgear LTE modem and put it in bridge mode and put a SSG5 behind it. Plugging in behind the SSG5 we get internet access no problem. The SSG5 shows a ethernet0/0 ip of 10.129.215.93 which is a private IP that it seems to get from the modem. Going to ipchicken.com and checking the WAN IP there, i get 107.77.210.83.
So i created the ipsec tunnel setup in aggressive mode and finally get some "completed negotiations" but the tunnel never shows as coming up. Plus, the SSG140 shows the connecting IP as: 166.170.220.223...which isn't the originating IP but its ATT cellular IP.
Relevant events from SSG140:
2019-12-03 15:01:14 info IKE 166.170.220.223 Phase 1: Retransmission limit has been reached.
2019-12-03 15:00:32 info IKE 166.170.221.15 Phase 2 msg ID 44e3690b: Completed negotiations with SPI 90fc9f72, tunnel ID 43, and lifetime 3600 seconds/0 KB.
2019-12-03 15:00:32 info IKE 166.170.221.15 phase 2:The symmetric crypto key has been generated successfully.
2019-12-03 15:00:32 info IKE 166.170.221.15: Received a notification message for DOI 1 40001 NOTIFY_NS_NHTB_INFORM.
2019-12-03 15:00:32 info IKE 166.170.221.15 Phase 2 msg ID 44e3690b: Responded to the peer's first message.
2019-12-03 15:00:32 info IKE 166.170.221.15 Phase 1: Completed Aggressive mode negotiations with a 28800-second lifetime.
2019-12-03 15:00:31 info IKE 166.170.221.15 phase 1:The symmetric crypto key has been generated successfully.
2019-12-03 15:00:31 info IKE 166.170.221.15 Phase 1: Responder starts AGGRESSIVE mode negotiations.
2019-12-03 15:00:26 info IKE1xx.xxx.xxx.xxx 166.170.220.223 Phase 1: Initiated negotiations in aggressive mode.
2019-12-03 14:59:41 info IKE 166.170.220.223 Phase 2: Initiated negotiations.
2019-12-03 13:59:51 info IKE 166.170.220.223 Phase 2 msg ID 34e835d3: Completed negotiations with SPI 90fc9f61, tunnel ID 43, and lifetime 3600 seconds/0 KB.
2019-12-03 13:59:51 info IKE 166.170.220.223 phase 2:The symmetric crypto key has been generated successfully.
2019-12-03 13:59:50 info IKE 166.170.220.223: Received a notification message for DOI 1 40001 NOTIFY_NS_NHTB_INFORM.
2019-12-03 13:59:50 info IKE 166.170.220.223 Phase 2 msg ID 34e835d3: Responded to the peer's first message.
2019-12-03 13:59:50 info IKE 166.170.220.223 Phase 1: Completed Aggressive mode negotiations with a 28800-second lifetime.
2019-12-03 13:59:50 info IKE 166.170.220.223 phase 1:The symmetric crypto key has been generated successfully.
2019-12-03 13:59:50 info IKE 166.170.220.223 Phase 1: Responder starts AGGRESSIVE mode negotiations.
2019-12-03 13:59:26 info IKE1xx.xxx.xxx.xxx 166.170.220.223 Phase 1: Initiated negotiations in aggressive mode.
2019-12-03 13:58:46 info IKE 166.170.220.223 Phase 2: Initiated negotiations.
2019-12-03 12:58:52 info IKE 166.170.220.223 Phase 2 msg ID 22fbaa20: Completed negotiations with SPI 90fc9f4f, tunnel ID 43, and lifetime 3600 seconds/0 KB.
2019-12-03 12:58:52 info IKE 166.170.220.223 phase 2:The symmetric crypto key has been generated successfully.
2019-12-03 12:58:52 info IKE 166.170.220.223: Received a notification message for DOI 1 40001 NOTIFY_NS_NHTB_INFORM.
2019-12-03 12:58:52 info IKE 166.170.220.223 Phase 2 msg ID 22fbaa20: Responded to the peer's first message.
2019-12-03 12:58:52 info IKE 166.170.220.223 Phase 1: Completed Aggressive mode negotiations with a 28800-second lifetime.
2019-12-03 12:58:52 info IKE 166.170.220.223 phase 1:The symmetric crypto key has been generated successfully.
2019-12-03 12:58:52 info IKE 166.170.220.223 Phase 1: Responder starts AGGRESSIVE mode negotiations.
And the remote SSG5 (about 15mins ahead)
2019-12-03 15:13:33 info IKE 1xx.xxx.xxx.xxx Phase 2 msg ID 44e3690b: Completed negotiations with SPI d5310d59, tunnel ID 1, and lifetime 3600 seconds/0 KB.
2019-12-03 15:13:33 info IKE 1xx.xxx.xxx.xxx phase 2:The symmetric crypto key has been generated successfully.
2019-12-03 15:13:33 info IKE 1xx.xxx.xxx.xxx: Received a notification message for DOI 1 40001 NOTIFY_NS_NHTB_INFORM.
2019-12-03 15:13:33 info IKE 1xx.xxx.xxx.xxx Phase 2: Initiated negotiations.
2019-12-03 15:13:33 info IKE 1xx.xxx.xxx.xxx Phase 1: Completed Aggressive mode negotiations with a 28800-second lifetime.
2019-12-03 15:13:33 info IKE 1xx.xxx.xxx.xxx phase 1:The symmetric crypto key has been generated successfully.
2019-12-03 15:13:33 info IKE10.129.215.93 1xx.xxx.xxx.xxx Phase 1: Initiated negotiations in aggressive mode.
2019-12-03 15:12:51 info IKE 1xx.xxx.xxx.xxx Phase 2: Initiated negotiations.
2019-12-03 14:12:52 info IKE 1xx.xxx.xxx.xxx Phase 2 msg ID 34e835d3: Completed negotiations with SPI d5310d57, tunnel ID 1, and lifetime 3600 seconds/0 KB.
2019-12-03 14:12:52 info IKE 1xx.xxx.xxx.xxx phase 2:The symmetric crypto key has been generated successfully.
2019-12-03 14:12:52 info IKE 1xx.xxx.xxx.xxx: Received a notification message for DOI 1 40001 NOTIFY_NS_NHTB_INFORM.
2019-12-03 14:12:52 info IKE 1xx.xxx.xxx.xxx Phase 2: Initiated negotiations.
2019-12-03 14:12:52 info IKE 1xx.xxx.xxx.xxx Phase 1: Completed Aggressive mode negotiations with a 28800-second lifetime.
2019-12-03 14:12:52 info IKE 1xx.xxx.xxx.xxx phase 1:The symmetric crypto key has been generated successfully.
2019-12-03 14:12:52 info IKE10.129.215.93 1xx.xxx.xxx.xxx Phase 1: Initiated negotiations in aggressive mode.
2019-12-03 13:11:55 info IKE 1xx.xxx.xxx.xxx Phase 2 msg ID 22fbaa20: Completed negotiations with SPI d5310d55, tunnel ID 1, and lifetime 3600 seconds/0 KB.
2019-12-03 13:11:55 info IKE 1xx.xxx.xxx.xxx phase 2:The symmetric crypto key has been generated successfully.
2019-12-03 13:11:55 info IKE 1xx.xxx.xxx.xxx: Received a notification message for DOI 1 40001 NOTIFY_NS_NHTB_INFORM.
2019-12-03 13:11:55 info IKE 1xx.xxx.xxx.xxx Phase 2: Initiated negotiations.
2019-12-03 13:11:55 info IKE 1xx.xxx.xxx.xxx Phase 1: Completed Aggressive mode negotiations with a 28800-second lifetime.
2019-12-03 13:11:55 info IKE 1xx.xxx.xxx.xxx phase 1:The symmetric crypto key has been generated successfully.
2019-12-03 13:11:55 info IKE10.129.215.93 1xx.xxx.xxx.xxx Phase 1: Initiated negotiations in aggressive mode.
It seems the tunnel negotiates but the tunnel that it's bound to never comes up and passes traffic. On the SSG140 it shows Ready and on the SSG5 it shows Link Down.
I've attached both config files, scrubbed what i could.
Appreciate any help