IPSec IKE Phase One Doesnt establish

Ignat 1 Reputation point
2022-06-03T15:26:00.447+00:00

Having issues with a LAN-2-LAN setup with Juniper SRX. Getting zero response from the VPN Gateway.

Checked everything multiple times:

[Jun 3 21:41:24]ikev2_udp_send_packet: [104d800/10ac800] <-------- Sending packet - length = 346 VR id 0

[Jun 3 21:41:34]ikev2_udp_send_packet: [104d800/10ac800] <-------- Sending packet - length = 346 VR id 0

[Jun 3 21:41:44]ikev2_udp_send_packet: [104d800/10ac800] <-------- Sending packet - length = 346 VR id 0

[Jun 3 21:41:54]P1 SA 3213912 timer expiry. ref cnt 2, timer reason Force delete timer expired (1), flags 0x0.
[Jun 3 21:41:54]Initiate IKE P1 SA 3213912 delete. curr ref count 2, del flags 0x3. Reason: Internal Error: Unknown event (0)
[Jun 3 21:41:54]IKE SA delete called for p1 sa 3213912 (ref cnt 3) local:x.x.x.x, remote:20.211.21.170, IKEv2
[Jun 3 21:41:54]Freeing all P2 SAs for IKEv2 p1 SA 3213912
[Jun 3 21:41:54]P1 SA 3213912 reference count is not zero (1). Delaying deletion of SA
[Jun 3 21:41:54]iked_pm_p1_sa_destroy: p1 sa 3213912 (ref cnt 0), waiting_for_del 0x10c3600
[Jun 3 21:41:54]iked_pm_ike_sa_delete_done_cb: For null p1 sa, status: Error ok
[Jun 3 21:41:54]iked_deferred_free_inactive_peer_entry: Free 1 peer_entry(s)
[Jun 3 21:41:54]ssh_ikev2_ipsec_send: Creating IKE and IPsec SA 20.211.21.170;500

Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,775 questions
{count} votes

6 answers

Sort by: Most helpful
  1. Ignat 1 Reputation point
    2022-06-04T00:02:29.553+00:00

    I am using route-based and have checked all my proposal settings match the requirements.

    As you can see in the above trace I am sending packets out and getting no response.

    0 comments No comments

  2. Ignat 1 Reputation point
    2022-06-04T01:28:47.67+00:00

    When doing a packet capture I get the following error:

    Failed to stop packet capture on the Connection.
    Failed to stop packet capture on the Connection 'Site-to-Site'. Error: An internal error occured. The response did not contain any data. Please check storage for the capture.

    0 comments No comments

  3. Ignat 1 Reputation point
    2022-06-04T01:51:06.767+00:00

    Looking at the details the VPN gateway has sent zero packets out and received zero, so im sure the issue is on the azure side

    Please investigate

    0 comments No comments

  4. risolis 8,741 Reputation points
    2022-06-04T20:30:11.893+00:00

    Hi @Ignat

    I just wanted to ask few questions...

    Since it is an SRX FW, I am wondering if you are doing a monitor traffic command on your ST interface(Secure interface)....

    Are you running trace option for this?

    Cheers,


  5. Ignat 1 Reputation point
    2022-06-05T03:51:07.587+00:00

    The only other thing I can think of is there is a routing issue between me and the Azure gateway ..

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.