Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: Problem with VPN configuration: The peer sent a TS that did not match the one in the SA config

$
0
0

H Matthias,

 

Please check KB https://kb.juniper.net/InfoCenter/index?page=content&id=KB5049&actp=search for the event logs. Do you see the same error for this VPN?

 

If yes, then please configure firewall security policy and mobile VPN profile in such a way so that the IPs match.

 

OR,  if you have only this policy based VPN then check the below settings:

 

get ike policy-checking
IKE Phase 2 ID payload checking is enabled   <----

 

Try disabling it using command : unset ike policy-checking

 

rollback : set ike policy-checking

 

Thanks,

Vikas


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>