We are trying to migrate off of Cisco 3000 VPN concentrators over to Juniper SRX boxes. My m0n0wall was the first VPN to be moved and I am having all kinds of issues. It appears that I cannot have more than two tunnels active at one time. Every 10-30 seconds, the m0n0wall re-keys Phase 2. So I currently have 5 tunnels to different internal IP ranges built and I have a ping going to an IP in each tunnel. Only two of those ping sessions will response and those rotate through every 10-30 seconds as Phase 2 re-keys on each tunnel. This configuration was rock solid on the Cisco devices.
When troubleshooting, I have multiple SAs (30+) showing on the m0n0wall while the Juniper only shows 1.
Syslog for the m0n0wall shows lots of interesting errors:
Apr 13 16:10:18 racoon: INFO: initiate new phase 2 negotiation: 9.9.9.81[500]<=>9.7.7.5[500] Apr 13 16:10:18 racoon: INFO: IPsec-SA established: ESP/Tunnel 9.7.7.5[0]->9.9.9.81[0] spi=117090632(0x6faa948) Apr 13 16:10:18 racoon: INFO: IPsec-SA established: ESP/Tunnel 9.9.9.81[500]->9.7.7.5[500] spi=690869026(0x292dd322) Apr 13 16:10:19 racoon: INFO: purged IPsec-SA proto_id=ESP spi=959373207. Apr 13 16:10:18 racoon: ERROR: failed to recv from pfkey (Resource temporarily unavailable)
Any ideas?
|