I created a new IPSec Roadwarrior tunnel, using a PSK. I created a new PSK for this tunnel. After I made it active, all the tunnels, except for those that had static IP's on both ends dropped and would not reconnect.
I have 10 IPSec tunnels. 2 of them have the static IP's at both ends. The rest have dynamic at the remote end. I tried restarting the tunnels at the remote end and I was getting authentication errors as if the PSK was not matching the one at my end. In the log on the main firewall, I was getting this message:
"multiple ipsec.secrets entries with distinct secrets match endpoints: first secret used"
I looked at the remote keys and found that the new PSK was listed before the PSK used in the other connections. I removed it and all the dynamic tunnels came up!!
Why is this?? Why would the static tunnels use the correct key and the dynamic ones would not even though is was specified in the connection? Why was it using the first PSK listed when it was not supposed to?
I was on Astaro 3.212 when this happened. I since updated it to 3.216 to see if that would fix the problem and it did not. Could anyone give me an answer to this one??
thanks
This thread was automatically locked due to age.