we have SSG-350M and ISG1000 at one site. The VPN tunnel was up till the time we reloaded our core switches as some routing was changed and everything was disrupted.
I have cleared the sa and ike-cookies, which didnt help.
We are able to learn the Phase I and Phase 2 on SSG-350:
vpn0001.brisbane-> get ike cookies | i 208.82.xx.xx
80522f/0003, 12.2.183.101:500->208.82.xx.xx:500, PRESHR/grp2/AES128/SHA, xchg(2) (fw1201.snv2-gw/grp-1/usr-1)
vpn0001.brisbane-> get sa | i 208.82.xx.xx
00000001< 208.82.xx.xx 500 esp:a128/sha1 2e4df364 3423 unlim A/D -1 0
00000001> 208.82.xx.xx 500 esp:a128/sha1 2df6b427 3423 unlim A/D -1 0.
Q.1) Does it means, all is good at SSG end?
Logs on ISG side:
Got an interesting error message:
2016-05-14 11:06:54 system crit 00040 VPN 'snv2-brisbane-ningops-vpn' from
12.2.183.101 is up.
2016-05-14 11:06:53 system info 00536 Rejected an IKE packet on ethernet1/
1.20 from 12.2.183.101:500 to
208.82.18.29:500 with cookies
fface3f0536c27a4 and c3c3cd73199b96eb
because There was a preexisting
session from the same peer.
2016-05-14 11:06:53 system info 00536 IKE 12.2.183.101 Phase 2 msg ID
0752155f: Responded to the peer's
first message.
2016-05-14 11:06:52 system crit 00041 VPN 'snv2-brisbane-ningops-vpn' from
12.2.183.101 is down.
2016-05-14 11:06:52 system crit 00040 VPN 'snv2-brisbane-ningops-vpn' from
12.2.183.101 is up.
2016-05-14 11:06:52 system info 00536 IKE 12.2.183.101 Phase 2 msg ID
791770d1: Completed negotiations with
SPI 2df6b60e, tunnel ID 50, and
lifetime 3600 seconds/0 KB.2016-05-14 11:06:54 system crit 00040 VPN 'snv2-brisbane-ningops-vpn' from
12.2.xx.xx is up.
2016-05-14 11:06:53 system info 00536 Rejected an IKE packet on ethernet1/
1.20 from 12.2.xx.xx:500 to
208.82.18.29:500 with cookies
fface3f0536c27a4 and c3c3cd73199b96eb
because There was a preexisting
session from the same peer.
2016-05-14 11:06:53 system info 00536 IKE 12.2.xx.xx Phase 2 msg ID
0752155f: Responded to the peer's
first message.
2016-05-14 11:06:52 system crit 00041 VPN 'snv2-brisbane-ningops-vpn' from
12.2.xx.xx is down.
2016-05-14 11:06:52 system crit 00040 VPN 'snv2-brisbane-ningops-vpn' from
12.2.xx.xx is up.
2016-05-14 11:06:52 system info 00536 IKE 12.2.xx.xx Phase 2 msg ID
791770d1: Completed negotiations with
SPI 2df6b60e, tunnel ID 50, and
lifetime 3600 seconds/0 KB.
I tried setting ike soft-lifetime-buffer to different times, which didn't.
Please Help.!!