09-19-2016 02:27 PM - edited 02-21-2020 08:58 PM
Hello,
i have an ASA5516X [9.5(2)10] and i'm trying to make an IPSec vpn with an Juniper device.
One problem is that only ipsec tunnel between 192.168.1.0-192.168.123.0 is created by default, and the traffic between these two subnets is working ok. When i initiate a ping from subnet 172.16.32.0 to 192.168.123.0, the ipsec tunnel between 192.168.1.0-192.168.123.0 is deleted and another one between 172.16.32.0-192.168.123.0 is created, traffic between 192.168.1.0-192.168.123.0 stops working until i issue clear crypto ipsec sa. Afther that tunnel between 192.168.1.0-192.168.123.0 is created and tunnel 172.16.32.0-192.168.123.0 is deleted.
The other one is that when i issue: debug crypto ipsec 128 i receive the following message with a frequency of one/second:
IPSEC ERROR: Failed to send the message to IKE
IPSEC ERROR: Failed to send the message to IKE
IPSEC ERROR: Failed to send the message to IKE
Anyone knows what that error message means? i searched allmost everywhere and no clue about that.
Thanks in advance,
Alin
09-20-2016 12:06 AM
Do you have two tunnel on same device?
09-20-2016 12:51 AM
Is just one ike peer and two subnets behind ASA (two SA are needed). I allready found that the problem resides in SRX configuration, and the soulution can be found here:
https://kb.juniper.net/InfoCenter/index?page=content&id=KB20543&actp=search
Remains the problem with the strange debug message: IPSEC ERROR: Failed to send the message to IKE
this will be interesting to find out what means.
09-20-2016 11:43 PM
Afther ipsec problem with Juniper SRX was solved the strange message still pops-up:
IPSEC ERROR: Failed to send the message to IKE
IPSEC ERROR: Failed to send the message to IKE
IPSEC ERROR: Failed to send the message to IKE
IPSEC ERROR: Failed to send the message to IKE
IPSEC ERROR: Failed to send the message to IKE
12-01-2016 10:02 AM
Alin,
Did you ever find out what causes the "IPSEC ERROR: Failed to send the message to IKE" message? My debugs are showing it right now but I don't know why and can't find any answers online.
Rick
01-31-2017 09:13 AM
Hi Rick, Alin,
Did any of you guys found out the reason for these errors? I am seeing these too...
Thanks
Lorand
09-21-2018 01:22 PM
I am seeing this "IPSEC ERROR: Failed to send the message to IKE" on ASA 5585 with debug crypto ipsec command...didn't find any answers online.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide