Proposal Mismatch; Failure To Establish An Ipsec Tunnel; Acl Configuration Error - 3Com MSR 50 Series Configuration Manual

3com msr 30-16: software guide
Hide thumbs Also See for MSR 50 Series:
Table of Contents

Advertisement

Proposal Mismatch

Failure to Establish an
IPSec Tunnel

ACL Configuration Error

drop message from A.B.C.D due to notification type INVALID_ID_INFORMATION
Solution
Check whether the ACLs of the IPSec policies configured on the interfaces at both
ends are compatible. It is recommended to configure the ACLs to mirror each
other. For more information about ACL mirroring, refer to
page 1881
in IPSec Configuration.
Symptom
Proposal mismatch
Analysis
Following is the debugging information:
got NOTIFY of type NO_PROPOSAL_CHOSEN
Or
drop message from A.B.C.D due to notification type NO_PROPOSAL_CHOSEN
The two parties in the negotiation have no matched proposal.
Solution
For the negotiation in phase 1, you can look up the IKE proposals for a match. For
the negotiation in phase 2, you can check whether the parameters of the IPSec
policies applied on the interfaces are matched, and whether the referred IPSec
proposals have a match in protocol, encryption and authentication algorithms.
Symptom

Failure to establish an IPSec tunnel

Analysis
Sometimes this may happen that an IPSec tunnel cannot be established or there is
no way to communicate in the presence of an IPSec tunnel in an unstable
network. According to examination results, however, ACLs of both parties are
configured correctly, and proposals are also matched.
In this case, the problem is usually caused by the reboot of one router after the
IPSec tunnel is established.
Solution
Use the display ike sa command to check whether both parties have
established an SA in phase 1.
Use the display ipsec sa policy command to check whether the IPSec policy
on the interface has established IPSec SA.
If the above two results display that one party has an SA but the other does
not, then use the reset ike sa command to clear SA with error and restart
negotiation.
Symptom
ACL configuration error results in data flow blockage
Troubleshooting IKE
1917
"Configuring ACLs" on

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading
Need help?

Need help?

Do you have a question about the MSR 50 Series and is the answer not in the manual?

Questions and answers

Subscribe to Our Youtube Channel

Table of Contents