Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Setting up Tunnel connecting to Juniper ASG

I have been working with a hosting company for the last week trying to work out settings to get a tunnel established between our office and their company.  The tunnel is now established, but I am unable to connect to any of our servers.  I think it has something to do with the errors that I am receiving in my log file.  We desperately need this working.  Thank you for your help!

2014:05:15-09:50:09 knoxville-sophos-1 pluto[25492]: id="2204" severity="info" sys="SecureNet" sub="vpn" event="Site-to-site VPN down" variant="ipsec" connection="SiteOrganic_Peer1" address="192.168.0.1" local_net="192.168.0.0/24" remote_net="10.60.1.0/24"
2014:05:15-09:50:09 knoxville-sophos-1 pluto[25492]: "S_SiteOrganic_Peer1" #1897: DPD: Restarting connection "S_SiteOrganic_Peer1"
2014:05:15-09:50:09 knoxville-sophos-1 pluto[25492]: "S_SiteOrganic_Peer1" #1897: DPD: Terminating all SAs using this connection
2014:05:15-09:50:09 knoxville-sophos-1 pluto[25492]: "S_SiteOrganic_Peer1" #1897: deleting state (STATE_QUICK_I2)
2014:05:15-09:50:09 knoxville-sophos-1 pluto[25492]: id="2204" severity="info" sys="SecureNet" sub="vpn" event="Site-to-site VPN down" variant="ipsec" connection="SiteOrganic_Peer1" address="192.168.0.1" local_net="192.168.0.0/24" remote_net="192.168.100.0/24"
2014:05:15-09:50:09 knoxville-sophos-1 pluto[25492]: DPD: Restarting connection "S_SiteOrganic_Peer1"
2014:05:15-09:50:10 knoxville-sophos-1 pluto[25492]: "S_SiteOrganic_Peer1" #1899: initiating Main Mode
2014:05:15-09:50:10 knoxville-sophos-1 pluto[25492]: "S_SiteOrganic_Peer1" #1899: ignoring Vendor ID payload [1ebd0c4b9fc0adf036608456da16a98734c6fccd000000130000060a]
2014:05:15-09:50:10 knoxville-sophos-1 pluto[25492]: "S_SiteOrganic_Peer1" #1899: received Vendor ID payload [Dead Peer Detection]
2014:05:15-09:50:10 knoxville-sophos-1 pluto[25492]: "S_SiteOrganic_Peer1" #1899: ignoring Vendor ID payload [HeartBeat Notify 386b0100]
2014:05:15-09:50:10 knoxville-sophos-1 pluto[25492]: "S_SiteOrganic_Peer1" #1899: Peer ID is ID_IPV4_ADDR: '64.239.36.202'
2014:05:15-09:50:10 knoxville-sophos-1 pluto[25492]: "S_SiteOrganic_Peer1" #1899: Dead Peer Detection (RFC 3706) enabled
2014:05:15-09:50:10 knoxville-sophos-1 pluto[25492]: "S_SiteOrganic_Peer1" #1899: ISAKMP SA established
2014:05:15-09:50:10 knoxville-sophos-1 pluto[25492]: "S_SiteOrganic_Peer1" #1900: initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS+UP {using isakmp#1899}
2014:05:15-09:50:10 knoxville-sophos-1 pluto[25492]: "S_SiteOrganic_Peer1" #1901: initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS+UP {using isakmp#1899}
2014:05:15-09:50:10 knoxville-sophos-1 pluto[25492]: id="2203" severity="info" sys="SecureNet" sub="vpn" event="Site-to-site VPN up" variant="ipsec" connection="SiteOrganic_Peer1" address="192.168.0.1" local_net="192.168.0.0/24" remote_net="192.168.100.0/24"
2014:05:15-09:50:10 knoxville-sophos-1 pluto[25492]: "S_SiteOrganic_Peer1" #1900: sent QI2, IPsec SA established {ESP=>0x6534bb01 0x6534bb02 0x6534bb06 0x6534bb07 


This thread was automatically locked due to age.
  • Hi, Jeremy, and welcome to the User BB!

    This looks like an issue of an incorrect configuration.  Please click on [Go Advanced] and attach picture of the IPsec Connection and the Remote Gateway open in Edit mode.  Also pictures of the corresponding configuration for the Juniper.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA