Hi All,
we have our Microsoft ISA 2004 ugraded to TMG 2010 (on a new machine). The Astaro FW is 7.507.
Now our Site2Site IPSec VPN (ASG110 TMG) have trouble in IPSEC Phase 2. We play around with the settings; but no success. Does anybody have an idea or the same problem?
Here are the log:
##############################################################
:
: | NAT-T: new mapping 172.172.172.172:4500/500)
: "S_Unknown Object" #6027: pfkey_msg_build of Add SA esp.8eb8e95@172.20.109.20 failed, code -22
: "S_Unknown Object" #6026: pfkey_msg_build of Add SA esp.8eb8e94@172.20.109.20 failed, code -22
: "S_Unknown Object" #6030: NAT-Traversal: Result using RFC 3947: i am NATed
: "S_Unknown Object" #6030: Peer ID is ID_IPV4_ADDR: '172.172.172.172'
: | NAT-T: new mapping 172.172.172.172:500/4500)
: "S_Unknown Object" #6027: pfkey_msg_build of Add SA esp.8eb8e95@172.20.109.20 failed, code -22
: "S_Unknown Object" #6030: sent MR3, ISAKMP SA established
: "S_Unknown Object" #6030: cannot respond to IPsec SA request because no connection is known for 192.168.2.0/24===172.20.109.20:4500...172.172.172.172:4500
: "S_Unknown Object" #6030: sending encrypted notification INVALID_ID_INFORMATION to 172.172.172.172:4500
: "S_Unknown Object" #6031: responding to Quick Mode
: "S_Unknown Object" #6031: IPsec SA established {ESP=>0x162cef84 0x14176a70 0xdeb7f205 0x404a9d59 0xc7387f9a 0x8a60ad5b 0x1d2e88eb
This thread was automatically locked due to age.