cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
6889
Views
0
Helpful
6
Replies

IPSEC ERROR: Failed to send the message to IKE

Alin Iorguta
Level 1
Level 1

Hello,

i have an ASA5516X [9.5(2)10] and i'm trying to make an IPSec vpn with an Juniper device.


The topology is like this:
172.16.32.0<--->Router<-->192.168.1.0<--->ASA<-----Internet---->Juniper<---->192.168.123.0

One problem is that only ipsec tunnel between 192.168.1.0-192.168.123.0 is created by default, and the traffic between these two subnets is working ok. When i initiate a ping from subnet 172.16.32.0 to 192.168.123.0, the ipsec tunnel between 192.168.1.0-192.168.123.0 is deleted and another one between 172.16.32.0-192.168.123.0 is created, traffic between 192.168.1.0-192.168.123.0 stops working until i issue clear crypto ipsec sa. Afther that tunnel between 192.168.1.0-192.168.123.0 is created and tunnel 172.16.32.0-192.168.123.0 is deleted.

The other one is that when i issue: debug crypto ipsec 128 i receive the following message with a frequency of one/second:
IPSEC ERROR: Failed to send the message to IKE
IPSEC ERROR: Failed to send the message to IKE
IPSEC ERROR: Failed to send the message to IKE

Anyone knows what that error message means? i searched allmost everywhere and no clue about that.

Thanks in advance,

Alin

6 Replies 6

Pawan Raut
Level 4
Level 4

Do you have two tunnel on same device?

Is just one ike peer and two subnets behind ASA (two SA are needed). I allready found that the problem resides in SRX configuration, and the soulution can be found here:

https://kb.juniper.net/InfoCenter/index?page=content&id=KB20543&actp=search

Remains the problem with the strange debug message: IPSEC ERROR: Failed to send the message to IKE

this will be interesting to find out what means.

Alin Iorguta
Level 1
Level 1

Afther ipsec problem with Juniper SRX was solved the strange message still pops-up:

IPSEC ERROR: Failed to send the  message to IKE
IPSEC ERROR: Failed to send the  message to IKE
IPSEC ERROR: Failed to send the  message to IKE
IPSEC ERROR: Failed to send the  message to IKE
IPSEC ERROR: Failed to send the  message to IKE

rweir0001
Level 1
Level 1

Alin,

Did you ever find out what causes the "IPSEC ERROR: Failed to send the message to IKE" message? My debugs are showing it right now but I don't know why and can't find any answers online.

Rick

Hi Rick, Alin,

Did any of you guys found out the reason for these errors? I am seeing these too...

Thanks 

Lorand

Praveen Kumar
Level 1
Level 1

I am seeing this "IPSEC ERROR: Failed to send the  message to IKE" on ASA 5585 with debug crypto ipsec  command...didn't find any answers online.