i wanted to know if anyone seen this problem before?
i have a netscreen with a route base vpn to a Cisco PIX.
the netscreen events log show this error.
2006-09-12 10:54:35 system info 00536 Rejected an IKE packet on untrust from
216.x.x.x:500 to 66.x.x.x:500
with cookies e3fc249085575b09 and
322131e403c7141a because there were no
acceptable Phase 1 proposals.
Ok so i check to make sure the Phase 1 match on both sides.
Netscreen----
fw1-> get ike p1-proposal
Id Name Auth Grp ESP-e ESP-a Lifetime
-- ------------------ -------- --- ------ ----- ----------
20 p1 Preshare 2 DES MD5 86400
Total Phase 1 proposals: 21
fw1->
PIX--------
isakmp identity address
isakmp policy 10 authentication pre-share
isakmp policy 10 encryption des
isakmp policy 10 hash md5
isakmp policy 10 group 2
isakmp policy 10 lifetime 86400
The debug from the netscreen show's this.
## 2006-09-12 10:20:51 : IKE<216.x.x.x> Construct ISAKMP header.
## 2006-09-12 10:20:51 : IKE<216.x.x.x> Msg header built (next payload #11)
## 2006-09-12 10:20:51 : IKE<216.x.x.x> Construct [NOTIF]
NO-PROPOSAL-CHOSEN)
## 2006-09-12 10:20:51 : IKE<216.x.x.x> P1 message header:
## 2006-09-12 10:20:51 : IKE<0.0.0.0 > ISAKMP msg: len 64, nxp 11[NOTIF], exch
## 2006-09-12 10:20:51 : IKE<216.x.x.x> responder create sa: 216.x.x.x->66.x.x.x
## 2006-09-12 10:20:51 : IKE<216.x.x.x> Phase 1: Responder starts MAIN mode negotiations.
## 2006-09-12 10:20:51 : IKE<216.x.x.x> MM in state OAK_MM_NO_STATE.
## 2006-09-12 10:20:51 : IKE<216.x.x.x> Process [SA]:
## 2006-09-12 10:20:51 : IKE<216.x.x.x> Proposal received: xauthflag 0
## 2006-09-12 10:20:51 : IKE<216.x.x.x> auth(1)<PRESHRD>, encr(1)<DES>, hash(1)<MD5>, group(2)
## 2006-09-12 10:20:51 : IKE<216.x.x.x> xauth attribute: disabled
## 2006-09-12 10:20:51 : IKE<216.x.x.x> [0] expect: xauthflag 0
## 2006-09-12 10:20:51 : IKE<216.x.x.x> auth(1)<PRESHRD>, encr(1)<DES>, hash(2)<SHA>, group(1)
## 2006-09-12 10:20:51 : IKE<216.x.x.x> xauth attribute: disabled
## 2006-09-12 10:20:51 : IKE<216.x.x.x> Phase 1: Rejected proposals from peer. Negotiations failed.
Thank you for any help.
i have a netscreen with a route base vpn to a Cisco PIX.
the netscreen events log show this error.
2006-09-12 10:54:35 system info 00536 Rejected an IKE packet on untrust from
216.x.x.x:500 to 66.x.x.x:500
with cookies e3fc249085575b09 and
322131e403c7141a because there were no
acceptable Phase 1 proposals.
Ok so i check to make sure the Phase 1 match on both sides.
Netscreen----
fw1-> get ike p1-proposal
Id Name Auth Grp ESP-e ESP-a Lifetime
-- ------------------ -------- --- ------ ----- ----------
20 p1 Preshare 2 DES MD5 86400
Total Phase 1 proposals: 21
fw1->
PIX--------
isakmp identity address
isakmp policy 10 authentication pre-share
isakmp policy 10 encryption des
isakmp policy 10 hash md5
isakmp policy 10 group 2
isakmp policy 10 lifetime 86400
The debug from the netscreen show's this.
## 2006-09-12 10:20:51 : IKE<216.x.x.x> Construct ISAKMP header.
## 2006-09-12 10:20:51 : IKE<216.x.x.x> Msg header built (next payload #11)
## 2006-09-12 10:20:51 : IKE<216.x.x.x> Construct [NOTIF]
## 2006-09-12 10:20:51 : IKE<216.x.x.x> P1 message header:
## 2006-09-12 10:20:51 : IKE<0.0.0.0 > ISAKMP msg: len 64, nxp 11[NOTIF], exch
## 2006-09-12 10:20:51 : IKE<216.x.x.x> responder create sa: 216.x.x.x->66.x.x.x
## 2006-09-12 10:20:51 : IKE<216.x.x.x> Phase 1: Responder starts MAIN mode negotiations.
## 2006-09-12 10:20:51 : IKE<216.x.x.x> MM in state OAK_MM_NO_STATE.
## 2006-09-12 10:20:51 : IKE<216.x.x.x> Process [SA]:
## 2006-09-12 10:20:51 : IKE<216.x.x.x> Proposal received: xauthflag 0
## 2006-09-12 10:20:51 : IKE<216.x.x.x> auth(1)<PRESHRD>, encr(1)<DES>, hash(1)<MD5>, group(2)
## 2006-09-12 10:20:51 : IKE<216.x.x.x> xauth attribute: disabled
## 2006-09-12 10:20:51 : IKE<216.x.x.x> [0] expect: xauthflag 0
## 2006-09-12 10:20:51 : IKE<216.x.x.x> auth(1)<PRESHRD>, encr(1)<DES>, hash(2)<SHA>, group(1)
## 2006-09-12 10:20:51 : IKE<216.x.x.x> xauth attribute: disabled
## 2006-09-12 10:20:51 : IKE<216.x.x.x> Phase 1: Rejected proposals from peer. Negotiations failed.
Thank you for any help.