News: This forum is now permanently frozen.
Pages: [1]
Topic: IPsec to Juniper SRX  (Read 3035 times)
« on: April 13, 2010, 23:41:40 »
Jackass *
Posts: 8

We are trying to migrate off of Cisco 3000 VPN concentrators over to Juniper SRX boxes.  My m0n0wall was the first VPN to be moved and I am having all kinds of issues.  It appears that I cannot have more than two tunnels active at one time.  Every 10-30 seconds, the m0n0wall re-keys Phase 2.  So I currently have 5 tunnels to different internal IP ranges built and I have a ping going to an IP in each tunnel.  Only two of those ping sessions will response and those rotate through every 10-30 seconds as Phase 2 re-keys on each tunnel.  This configuration was rock solid on the Cisco devices.

When troubleshooting, I have multiple SAs (30+) showing on the m0n0wall while the Juniper only shows 1.

Syslog for the m0n0wall shows lots of interesting errors:

Apr 13 16:10:18 racoon: INFO: initiate new phase 2 negotiation: 9.9.9.81[500]<=>9.7.7.5[500]
Apr 13 16:10:18 racoon: INFO: IPsec-SA established: ESP/Tunnel 9.7.7.5[0]->9.9.9.81[0] spi=117090632(0x6faa948)
Apr 13 16:10:18 racoon: INFO: IPsec-SA established: ESP/Tunnel 9.9.9.81[500]->9.7.7.5[500] spi=690869026(0x292dd322)
Apr 13 16:10:19 racoon: INFO: purged IPsec-SA proto_id=ESP spi=959373207.
Apr 13 16:10:18 racoon: ERROR: failed to recv from pfkey (Resource temporarily unavailable)


Any ideas?
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines