This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Site to Site IPsec VPN between two XG Firewall: IPsec connection could not be established

Hi guys.

 

I'm trying to configure a Site to Site IPsec VPN between two XG Firewall.

I followed all the steps to do it but the tunnel is not up (IPsec connection could not be established message).

 

On the strongswan.log file I found this error:

 

[GARNER-LOGGING] (child_alert) ALERT: peer did not respond to initial message 2
establishing IKE_SA failed, peer not responding
no files found matching '/_conf/ipsec/connections/*.conf'

 

Can someone help me ?

 

Thanks in advance to all.

 

Regards,

Michele



This thread was automatically locked due to age.
Parents
  • Hi Michele,

    You may have a NAT which is forwarding IPSEC packets or the IPSEC packets are not getting to their destination.

    Can you get the logs from both sides at the same time?

  • Thank you for your help.

     

    On the other side is the same:

    generating ID_PROT request 0 [ SA V V V V V V ]

    sending retransmit 1 of request message ID 0, seq 1

    sending retransmit 2 of request message ID 0, seq 1

    sending retransmit 3 of request message ID 0, seq 1

     

    Seems to be that both sides are not communicating .

     

    What do you mean in deep ''You may have a NAT'' ?

     

    Thanks.

Reply
  • Thank you for your help.

     

    On the other side is the same:

    generating ID_PROT request 0 [ SA V V V V V V ]

    sending retransmit 1 of request message ID 0, seq 1

    sending retransmit 2 of request message ID 0, seq 1

    sending retransmit 3 of request message ID 0, seq 1

     

    Seems to be that both sides are not communicating .

     

    What do you mean in deep ''You may have a NAT'' ?

     

    Thanks.

Children