Hi everyone,
I´m new on this community so excuse me if I post something wrongly.
I´m finding the same issue discussed on this thread of several years ago and I´m really interested on finding a solution.
The remote device is a Checkpoint and the problem is that remote hosts can´t reach local hosts, like for someone at the begining of this thread. Let me show some screenshots:
And from the remote side:
About the INVALID_MESSAGE_ID, this is an example of several days ago:
2019:08:06-09:54:54 asg220 pluto[16211]: "S_VPN_xxx_yyy" #97425: Quick Mode I1 message is unacceptable because it uses a previously used Message ID 0x61462fd7 (perhaps this is a duplicated packet)
2019:08:06-09:54:54 asg220 pluto[16211]: "S_VPN_xxx_yyy" #97425: sending encrypted notification INVALID_MESSAGE_ID to 217.x.y.65:500
Many thanks in advance and best regards,
Antonio
Hola Antonio and welcome to the UTM Community!
Your IKE Phase 1 timeout is different than the selection on the Checkpoint, 21600 vs. 360.
You presently have both DPD and NAT-T disabled. It's rare that you don't want NAT-T enabled. Try with both enabled. These selections in the UTM should match those in the Checkpoint.
Just looking at two lines from the IPsec log is too few. Since all 120 IPsec SAs are established, I'm confused about what problem you're seeing.
Cheers - Bob