This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

received NO_PROPOSAL_CHOSEN notify, no CHILD_SA built issue

Admin - Merged thread from duplicate thread


 

Hi,

I am facing an issue that am not sure what i need to be checking on. I have an IPSEC connection that seems to be identical on both the sophos and the Cisco ASA end. When I attempt to start the connection, the phase1 comes up but the phase2 fails. When cisco ASA initiates the connection, the phase2 comes up and I can connect to devices on the remote side behind the ASA. If I terminate the connection, i cannot start the phase2 unless Cisco ASA initiates from their end by attempting to pass me traffic.

WHat do I need to check on?


 

Hi,

I am unable to initiate the IPSEC connection as much as I am set to be the initiator. The remote device is an ASA that is able to initiate the connection for it to work. Only logs I can find that are errors are:

2020-05-28 22:51:15 26[IKE] <vpn001-1|31> establishing CHILD_SA vpn001-8
2020-05-28 22:51:15 26[ENC] <vpn001-1|31> generating CREATE_CHILD_SA request 8 [ SA No TSi TSr ]
2020-05-28 22:51:15 26[NET] <vpn001-1|31> sending packet: from a.a.a.a[4500] to b.b.b.b[4500] (284 bytes)
2020-05-28 22:51:15 15[NET] <vpn001-1|31> received packet: from b.b.b.b[4500] to a.a.a.a[4500] (76 bytes)
2020-05-28 22:51:15 15[ENC] <vpn001-1|31> parsed CREATE_CHILD_SA response 8 [ N(NO_PROP) ]
2020-05-28 22:51:15 15[IKE] <vpn001-1|31> received NO_PROPOSAL_CHOSEN notify, no CHILD_SA built
2020-05-28 22:51:15 15[DMN] <vpn001-1|31> [GARNER-LOGGING] (child_alert) ALERT: the received CHILD_SA proposals did not match: ESP:AES_CBC_256/HMAC_SHA1_96/NO_EXT_SEQ, ESP:AES_CBC_256/AES_CBC_192/AES_CBC_128/HMAC_SHA2_512_256/HMAC_SHA2_384_192/HMAC_SHA2_256_128/AES_XCBC_96/NO_EXT_SEQ
2020-05-28 22:51:15 15[IKE] <vpn001-1|31> creating CHILD_SA failed, trying again in 69 seconds



This thread was automatically locked due to age.
Parents
  • Hello M@rik,

    Thank you for contacting the Sophos Community.

    This NO_PROPOSAL_CHOSEN usually means that there is one setting in the Policy not matching between both devices.

    Are the subnets matching in both ends?

    Please follow the recommendations in this KB for XG and ASA

    ===

    Sophos XG Firewall: How to setup IPSec between Sophos XG Firewall and Cisco ASA

    https://community.sophos.com/kb/en-us/127731

    ===

    If the issue persist, please put strongswan in debug mode (service strongswan:debug -ds nosync) and send us the output, also provide some screenshots of your configuration and Cisco ASA if you can.

    Regards,

  • For anyone else that faces a similar issue, @emmosophos  was correct.

     

    Also note that for connecting to ASA, they need to ensure their ACLs on their end on their end are properly configured. The subnets we specify on our end also need to be identical to what the ASA is configured 

Reply
  • For anyone else that faces a similar issue, @emmosophos  was correct.

     

    Also note that for connecting to ASA, they need to ensure their ACLs on their end on their end are properly configured. The subnets we specify on our end also need to be identical to what the ASA is configured 

Children
No Data