Stormshield SN series Configuration Manual page 414

Hide thumbs Also See for SN series:
Table of Contents

Advertisement

Solution : Check the routing between the hosts (client workstation, intranet server) and their
respective gateways (static routing or default gateway). Check your filter rules on the
"initiator".  Also ensure that the "initiator"'s tunnel is not in "responder only" mode (Peers tab in the
menu Configuration > VPN > IPSec VPN).
Symptom: The tunnel cannot be set up.
A message "Negotiation failed due to timeout" in phase 1 appears in the module Logs > VPN
l
in Stormshield Network Realtime Monitor on the "initiator" IPS-Firewall
No message appears in the module Logs > VPN in Stormshield Network Realtime Monitor on
l
the "responder" IPS-Firewall.
Solution: The remote IPSec gateway ("responder") is not responding to requests. Check that the
IPSec VPN policy has been enabled on the "responder" IPS-Firewall. Check that the objects
corresponding to tunnel endpoints have been entered with the right IP addresses.
Symptom: The tunnel cannot be set up.
The messages "Negotiation failed" and "Certificate with serial XXX from issuer YYY: unable to
l
get local issuer certificate" in phase 1 appear in the module Logs > VPN in Stormshield
Network Realtime Monitor on the "responder" IPS-Firewall
Solution: the "responder" IPS-Firewall cannot verify the validity of the "initiator" IPS-Firewall's
certificate. Ensure that you have indeed defined the CA as the trusted CA on the "responder"
(Identification tab in the menu Configuration > VPN > IPSec VPN).
Symptom: The tunnel cannot be set up.
The messages "Negotiation failed" and "Certificate with serial XXX from issuer YYY: unable to
l
get local issuer certificate" in phase 1 appear in the module Logs > VPN in Stormshield
Network Realtime Monitor on the "initiator" IPS-Firewall
Solution: the "initiator" IPS-Firewall cannot verify the validity of the "responder" IPS-Firewall's
certificate. Ensure that you have indeed defined the CA as the trusted CA on the "initiator"
(Identification tab in the menu Configuration > VPN > IPSec VPN).
Page 414/448
SNS - USER CONFIGURATION MANUAL V.3
HOW TO: IPSEC VPN - AUTHENTICATION BY CERTIFICATE
sns-en-user_configuration_manual-v3 - Copyright © Stormshield 2016

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents