Quantcast
Viewing all articles
Browse latest Browse all 3822

Cannot create Site to Site (B2B) VPN using IPSec

Our company is trying to establish a site to site VPN with another company using TMG 2010 on our end and a Cisco router on their end.  We currently have another tunnel up with a different vendor that has been working for over a year so I am familiar with the setup.  However with this one it seems to fail on Phase 2 (IKE Quick Mode).  Here is the log (some information hidden).  The first entry is a Audit Success for IPsec Main Mode (4650):

An IPsec main mode security association was established. Extended mode was not enabled.  Certificate authentication was not used.

Local Endpoint:
    Principal Name:    -    Network Address:    208.*.*.*    Keying Module Port:    500

Remote Endpoint:
    Principal Name:    -    Network Address:    75.*.*.*    Keying Module Port:    500

Security Association Information:
    Lifetime (minutes):    120    Quick Mode Limit:    0    Main Mode SA ID:    3

Cryptographic Information:
    Cipher Algorithm:    (hidden)    Integrity Algorithm:    (hidden)    Diffie-Hellman Group:    (hidden)

Additional Information:
    Keying Module Name:    IKEv1    Authentication Method:    Preshared key    Role:    Initiator    Impersonation State:    Not enabled

Then afterward I get a Audit Failure for IPsec Quick Mode (4654):

An IPsec quick mode negotiation failed.

Local Endpoint:
    Network Address:    10.1.10.0    Network Address mask:    255.255.255.0    Port:            0    Tunnel Endpoint:        208.*.*.*

Remote Endpoint:
    Network Address:    10.10.30.0    Address Mask:        255.255.255.0    Port:            0    Tunnel Endpoint:        75.*.*.*    Private Address:        0.0.0.0

Additional Information:
    Protocol:        0    Keying Module Name:    IKEv1    Virtual Interface Tunnel ID:    0    Traffic Selector ID:    0    Mode:            Tunnel    Role:            Initiator    Quick Mode Filter ID:    87602    Main Mode SA ID:    3

Failure Information:
    State:            Sent first (SA) payload    Message ID:        1    Failure Point:        Remote computer    Failure Reason:        IKE security attributes are unacceptable

If they initiate the tunnel I get the exact same message about the IKE security attributes are unacceptable.  We have gone over all the rules multiple times to verify they are correct.  We even changed some Phase 2 settings on both ends (again making sure they match) to see if that was it ans still the same message.  Anyone have any ideas why this would happen?

-Allan




Viewing all articles
Browse latest Browse all 3822

Trending Articles