JuniperForum.com
September 09, 2010, 02:44:11 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: If you have an interesting idea for an article or knowledgebase entry, please submit it!
 
  Home Help Login Register  
* *
Pages: [1]
  Print  
Author Topic: Netscreen-10 and 5GT peer VPN  (Read 382 times)
lil_tud
Newbie
*
Posts: 2


View Profile
« on: March 08, 2010, 09:19:49 PM »

Hi All

I'm a bit of a newbie to Netscreen VPN's, I have inherited a network with some 5GT's with peer VPN's already configured and working between sites, and I am trying to add an additional site with a Netscreen-10 connecting to a 5GT with a peer to peer vpn, I have found a few sites with details on getting peer vpns working with 5GT and similar devices taking, so with  the combination of looking at my existing setup and reading the doco I think I have the 5GT end set up correctly, but where I am stick is with the Netscreen-10 I don't seem to be able to bind the phase 2 to a Tunnel interface (or create one for that matter)

can anyone point me in the direction of some doco on peer VPN's with netscreen-10's or any of the older sceen-os netscreens.

I know this sounds vague, but any help is appreciated

Cheers
Logged
lil_tud
Newbie
*
Posts: 2


View Profile
« Reply #1 on: March 09, 2010, 08:19:51 PM »

it seems that phase 2 negotiations aren't working, the even't log below form the 5GT may help with some more info?

2010-03-10 11:14:48   info   IKE<xxx.xxx.xxx.xxx>: Received a notification message for DOI <1> <16> <PAYLOAD_MALFORMED>.
2010-03-10 11:14:48   info   IKE<xxx.xxx.xxx.xxx> Phase 2: Received a message but did not check a policy because id-mode was set to IP or policy-checking was disabled.
2010-03-10 11:14:48   info   IKE<xxx.xxx.xxx.xxx> Phase 2 msg ID <311a304b>: Responded to the peer's first message.
2010-03-10 11:14:44   info   IKE<xxx.xxx.xxx.xxx2>: Received a notification message for DOI <1> <16> <PAYLOAD_MALFORMED>.
2010-03-10 11:14:44   info   IKE<xxx.xxx.xxx.xxx> Phase 2: Received a message but did not check a policy because id-mode was set to IP or policy-checking was disabled.
2010-03-10 11:14:44   info   IKE<xxx.xxx.xxx.xxx> Phase 2 msg ID <311a304b>: Responded to the peer's first message.
2010-03-10 11:14:40   info   IKE<xxx.xxx.xxx.xxx>: Received a notification message for DOI <1> <16> <PAYLOAD_MALFORMED>.
2010-03-10 11:14:40   info   IKE<xxx.xxx.xxx.xxx> Phase 2: Received a message but did not check a policy because id-mode was set to IP or policy-checking was disabled.
2010-03-10 11:14:40   info   IKE<xxx.xxx.xxx.xxx> Phase 2 msg ID <311a304b>: Responded to the peer's first message.
2010-03-10 11:14:36   info   IKE<xxx.xxx.xxx.xxx>: Received a notification message for DOI <1> <16> <PAYLOAD_MALFORMED>.
2010-03-10 11:14:36   info   IKE<xxx.xxx.xxx.xxx> Phase 2: Received a message but did not check a policy because id-mode was set to IP or policy-checking was disabled.
2010-03-10 11:14:36   info   IKE<xxx.xxx.xxx.xxx> Phase 2 msg ID <311a304b>: Responded to the peer's first message.
2010-03-10 11:14:32   info   IKE<xxx.xxx.xxx.xxx>: Received a notification message for DOI <1> <16> <PAYLOAD_MALFORMED>.
2010-03-10 11:14:32   info   IKE<xxx.xxx.xxx.xxx> Phase 2: Received a message but did not check a policy because id-mode was set to IP or policy-checking was disabled.
2010-03-10 11:14:32   info   IKE<xxx.xxx.xxx.xxx> Phase 2 msg ID <311a304b>: Responded to the peer's first message.
2010-03-10 11:14:30   info   IKE<xxx.xxx.xxx.xxx> Phase 1: Completed Aggressive mode negotiations with a <28800>-second lifetime.
2010-03-10 11:14:28   info   IKE<xxx.xxx.xxx.xxx> Phase 1: Responder starts AGGRESSIVE mode negotiations.


Does this help for any suggestions?

Cheers
Logged
Pages: [1]
  Print  
 
Jump to:  

Navigation

Donate

Please consider donating if we've saved you time or money. It helps pay for the bandwidth, equipment, and hosting charges to keep this site running

Tools

Submit Article/KB - Do not submit questions here.

Recent

Stats

Members
Stats
  • Total Posts: 40719
  • Total Topics: 11389
  • Online Today: 82
  • Online Ever: 393
  • (August 06, 2008, 07:40:57 AM)
Users Online
Users: 0
Guests: 58
Total: 58
TinyPortal v1.0 beta 4 © Bloc
Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!

Sponsored in part by CollarWise

Page created in 0.253 seconds with 38 queries.