Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SIte to Site VPN to external organization

Hi,

I need help in setting up a s2s vpn to another site (not part of my company).

We're using SG430 and I've setup all the config for vpn according to the other site's configuration. The policies and encryption etc. are correct based on the information they provided, only one thing I can't confirm is the preshared key because just by asking this information it has to go to a lot of process in their company. But I am getting the error below in the live log.

 

S_to Telus Wolf Production" #1508: max number of retransmissions (2) reached STATE_MAIN_I3. Possible authentication failure: no acceptable response to our first encrypted message
2017:05:03-10:21:06 calfirewall pluto[23128]: "S_to Telus Wolf Production" #1508: starting keying attempt 2 of an unlimited number
2017:05:03-10:21:06 calfirewall pluto[23128]: "S_to Telus Wolf Production" #1510: initiating Main Mode to replace #1508
2017:05:03-10:21:06 calfirewall pluto[23128]: "S_to Telus Wolf Production" #1510: received Vendor ID payload [Dead Peer Detection]
2017:05:03-10:21:06 calfirewall pluto[23128]: "S_to Telus Wolf Production" #1510: received Vendor ID payload [RFC 3947]
2017:05:03-10:21:06 calfirewall pluto[23128]: "S_to Telus Wolf Production" #1510: ignoring Vendor ID payload [699369228741c6d4ca094c93e242c9de19e7b7c60000000500000500]
2017:05:03-10:21:06 calfirewall pluto[23128]: "S_to Telus Wolf Production" #1510: enabling possible NAT-traversal with method 3
2017:05:03-10:21:06 calfirewall pluto[23128]: "S_to Telus Wolf Production" #1510: NAT-Traversal: Result using RFC 3947: no NAT detected
2017:05:03-10:21:06 calfirewall pluto[23128]: "S_to Telus Wolf Production" #1510: Informational Exchange message must be encrypted

 

Does anyone know what this error points to? Thanks in advance.



This thread was automatically locked due to age.
Parents
  • Hi, Richard, and welcome to the UTM Community!

    Possible authentication failure: no acceptable response to our first encrypted message

    If neither endpoint is behind a NATting router, then you're probably right that the PSK is incorrect.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Hi, Richard, and welcome to the UTM Community!

    Possible authentication failure: no acceptable response to our first encrypted message

    If neither endpoint is behind a NATting router, then you're probably right that the PSK is incorrect.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data