<< Prev Question Next Question >>

Question 24/36

-- Exhibit --
[edit]
user@SRX-1# show security ike traceoptions
file ike-trace;
flag all;
[edit]
user@SRX-1# show security ipsec traceoptions
flag all;
user@SRX-1> show log ike-trace
...
Jun 13 17:00:33 :500 (Responder) -> 192.168.1.11:500 { 15276b72 6656c3b6 - 4ea713e7 d2487276 [1] /
0x9828a32e } QM; Invalid protocol_id = 0
Jun 13 17:00:34 Received authenticated notification payload unknown from local:192.168.1.10 remote:192.168.1.11 IKEv1 for P1 SA 3075335 Jun 13 17:00:34 iked_pm_ike_spd_notify_receiveD. Negotiation is already failed. Reason: TS unacceptable.
Jun 13 17:00:34 QM notification `(null)' (40001) (size 8 bytes) from 192.168.1.11 for protocol Reserved spi
[0...3]=0f f0 ce d3
Jun 13 17:00:34 ike_st_i_private: Start
Jun 13 17:00:34 ike_st_o_qm_hash_2: Start
Jun 13 17:00:34 ike_st_o_qm_sa_values: Start
Jun 13 17:00:34 :500 (Responder) -> 192.168.1.11:500 { 15276b72 6656c3b6 - 4ea713e7 d2487276 [1] /
0x9828a32e } QM; Error = No proposal chosen (14)
Jun 13 17:00:34 ike_alloc_negotiation: Start, SA = { 15276b72 6656c3b6 - 4ea713e7 d2487276} Jun 13 17:00:34 ike_encode_packet: Start, SA = { 0x15276b72 6656c3b6 - 4ea713e7 d2487276 } /
65407839, nego = 2
Jun 13 17:00:34 ike_send_packet: Start, send SA = { 15276b72 6656c3b6 - 4ea713e7 d2487276}, nego
2, dst = 192.168.1.11:500, routing table id = 0
Jun 13 17:00:34 ike_delete_negotiation: Start, SA = { 15276b72 6656c3b6 - 4ea713e7 d2487276}, nego
2
Jun 13 17:00:34 ike_free_negotiation_info: Start, nego = 2
Jun 13 17:00:34 ike_free_negotiation: Start, nego = 2
Jun 13 17:00:34 IPSec negotiation failed for SA-CFG Unknown for local:192.168.1.10, remote:192.168.1.11 IKEv1. status: TS unacceptable Jun 13 17:00:34 P2 ed info: flags 0x0, P2 error: TS unacceptable Jun 13 17:00:34 iked_pm_ipsec_sa_done: Phase2 failed 2/3 times for P1 SA 3075335
-- Exhibit --
Click the Exhibit button.
The IPsec tunnel is not establishing between SRX-1 and a remote device.
Referring to the exhibit, what is causing this problem?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (36q)
Question 1: -- Exhibit -- Apr 27 19:11:09 company-fw init: low_mem_signa...
Question 2: -- Exhibit - (Exhibit) -- Exhibit -- Click the Exhibit butto...
Question 3: -- Exhibit -- user@host&gt; request services application-ide...
Question 4: -- Exhibit -- [edit security utm] user@host# show custom-obj...
Question 5: LAN 1 and LAN 2 are experiencing network communication probl...
Question 6: Click the Exhibit button. (Exhibit) A customer wants to crea...
Question 7: -- Exhibit -- user@host&gt; show security flow session ... S...
Question 8: -- Exhibit -- user@host&gt; show log ibgp-trace ... Jun 12 1...
Question 9: -- Exhibit -- user@host&gt; show log ike-test ... Jun 13 10:...
Question 10: Click the Exhibit button. (Exhibit) A customer configured DH...
Question 11: -- Exhibit -- user@host&gt; show log flow.log Jun 12 20:00:4...
Question 12: -- Exhibit -- user@R1&gt; show security ike security-associa...
Question 13: Click the Exhibit button. (Exhibit) You configured a route-b...
Question 14: Click the Exhibit button. (Exhibit) You are implementing a h...
Question 15: Click the Exhibit button. (Exhibit) You recently configured ...
Question 16: You have deployed AppID on your SRX Series device. You want ...
Question 17: Click the Exhibit button. (Exhibit) You are implementing UTM...
Question 18: -- Exhibit -- user@R1&gt; show log ike-trace Jun 13 07:45:10...
Question 19: Click the Exhibit button. (Exhibit) A customer created a sec...
Question 20: -- Exhibit -- user@host&gt; show security flow session inter...
Question 21: -- Exhibit -- user@host&gt; show configuration security utm ...
Question 22: -- Exhibit - (Exhibit) -- Exhibit -- Click the Exhibit butto...
Question 23: Click the Exhibit button. (Exhibit) A customer is using a de...
Question 24: -- Exhibit -- [edit] user@SRX-1# show security ike traceopti...
Question 25: -- Exhibit - (Exhibit) -- Exhibit -- Click the Exhibit butto...
Question 26: -- Exhibit -- user@host&gt; show configuration security poli...
Question 27: -- Exhibit -- {primary:node0} user@host&gt; show configurati...
Question 28: Click the Exhibit button. (Exhibit) Your customer reports th...
Question 29: -- Exhibit -- {hold:node0} user@host1&gt; show chassis clust...
Question 30: While attempting to commit a configuration for a new address...
Question 31: Click the Exhibit button. (Exhibit) You are troubleshooting ...
Question 32: Click the Exhibit button. (Exhibit) A customer wants to comm...
Question 33: -- Exhibit - (Exhibit) -- Exhibit -- Click the Exhibit butto...
Question 34: -- Exhibit -- user@host&gt; show configuration ... security ...
Question 35: -- Exhibit -- user@SRX-1&gt; show configuration security ike...
Question 36: Users begin complaining that they are not able to access res...