Our company is trying to establish a site to site VPN with another company using TMG 2010 on our end and a Cisco router on their end. We currently have another tunnel up with a different vendor that has been working for over a year so I am familiar with the setup. However with this one it seems to fail on Phase 2 (IKE Quick Mode). Here is the log (some information hidden). The first entry is a Audit Success for IPsec Main Mode (4650):
An IPsec main mode security association was established. Extended mode was not enabled. Certificate authentication was not used. Local Endpoint: Principal Name: - Network Address: 208.*.*.* Keying Module Port: 500 Remote Endpoint: Principal Name: - Network Address: 75.*.*.* Keying Module Port: 500 Security Association Information: Lifetime (minutes): 120 Quick Mode Limit: 0 Main Mode SA ID: 3 Cryptographic Information: Cipher Algorithm: (hidden) Integrity Algorithm: (hidden) Diffie-Hellman Group: (hidden) Additional Information: Keying Module Name: IKEv1 Authentication Method: Preshared key Role: Initiator Impersonation State: Not enabled
Then afterward I get a Audit Failure for IPsec Quick Mode (4654):
An IPsec quick mode negotiation failed. Local Endpoint: Network Address: 10.1.10.0 Network Address mask: 255.255.255.0 Port: 0 Tunnel Endpoint: 208.*.*.* Remote Endpoint: Network Address: 10.10.30.0 Address Mask: 255.255.255.0 Port: 0 Tunnel Endpoint: 75.*.*.* Private Address: 0.0.0.0 Additional Information: Protocol: 0 Keying Module Name: IKEv1 Virtual Interface Tunnel ID: 0 Traffic Selector ID: 0 Mode: Tunnel Role: Initiator Quick Mode Filter ID: 87602 Main Mode SA ID: 3 Failure Information: State: Sent first (SA) payload Message ID: 1 Failure Point: Remote computer Failure Reason: IKE security attributes are unacceptable
If they initiate the tunnel I get the exact same message about the IKE security attributes are unacceptable. We have gone over all the rules multiple times to verify they are correct. We even changed some Phase 2 settings on both ends (again making sure they match) to see if that was it ans still the same message. Anyone have any ideas why this would happen?
-Allan