Ipsec Tunnel Establishment Failed - HP MSR Series Configuration Manual

Hpe flexnetwork msr router series
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

Analysis
Certain IPsec policy settings are incorrect.
Solution
1.
Examine the IPsec configuration to see whether the two ends have matching IPsec transform
sets.
2.
Modify the IPsec configuration to make sure the two ends have matching IPsec transform sets.

IPsec tunnel establishment failed

Symptom
The ACLs and IKEv2 proposals are correctly configured on both ends. The two ends cannot
establish an IPsec tunnel or cannot communicate through the established IPsec tunnel.
Analysis
The IKEv2 SA or IPsec SAs on either end are lost. The reason might be that the network is unstable
and the device reboots.
Solution
1.
Use the display ikev2 sa command to examine whether an IKEv2 SA exists on both ends. If
the IKEv2 SA on one end is lost, delete the IKEv2 SA on the other end by using the reset ikev2
sa command and trigger new negotiation. If an IKEv2 SA exists on both ends, go to the next
step.
2.
Use the display ipsec sa command to examine whether IPsec SAs exist on both ends. If the
IPsec SAs on one end are lost, delete the IPsec SAs on the other end by using the reset ipsec
sa command and trigger new negotiation.
390

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents