cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1873
Views
0
Helpful
0
Replies

Route based IPSEC VPN between ASA to Juniper SRX1500 - traffic selector mismatch

handsy
Level 1
Level 1

I have a route based VPN between my Cisco ASA 5555-X and a Juniper SRX1500. I am seeing some errors coming in. The following log entries were from either end of the VPN at the exact same time:

 

Juniper log entries:

Nov 11 15:36:09 firewall02 kmd[40699]: KMD_VPN_TS_MISMATCH: Traffic-selector mismatch, vpn name: PHASE2, Peer Proposed traffic-selector local-ip: ipv4(10.140.90.48),ipv4(10.140.90.48-10.140.90.63), Peer Proposed traffic-selector remote-ip: ipv4(10.140.91.0),ipv4(10.140.91.0-10.140.91.7)
Nov 11 15:36:09 firewall02 kmd[40699]: IPSec negotiation failed with error: Peer proposed unsupported multiple traffic-selector attributes for a single IPSec SA. Negotiation failed.. IKE Version: 2, VPN: PHASE2 Gateway: PHASE1, Local: [removed-ip]/500, Remote: [removed-ip]/500, Local IKE-ID: [removed-ip], Remote IKE-ID: [removed-ip], VR-ID: 0

 

Cisco log entries:

Nov 11 2020 15:36:09 cisco-fw01 : %ASA-5-750001: Local:[removed-ip]:500 Remote:[removed-ip]:500 Username:[removed-ip] IKEv2 Received request to rekey an IPsec tunnel; local traffic selector = Address Range: 10.140.91.0-10.140.91.0 Protocol: 0 Port Range: 0-65535; remote traffic selector = Address Range: 10.140.90.48-10.140.90.48 Protocol: 0 Port Range: 0-65535
Nov 11 2020 15:36:09 cisco-fw01 : %ASA-4-750003: Local:[removed-ip]:500 Remote:[removed-ip]:500 Username:[removed-ip] IKEv2 Negotiation aborted due to ERROR: Detected unsupported failover version

 

Doing some googling I found this Juniper forum post citing Cisco sending >1 proxy ID for every SA:

https://forums.juniper.net/t5/SRX-Services-Gateway/Peer-proposed-unsupported-multiple-traffic-selector-attributes/m-p/461455/highlight/true#M53132

The Juniper SRX does not appear to be capable of handling this. Is there a way of disabling that behaviour on Cisco, or has anyone found any other workaround?

 

0 Replies 0