05-11-2022 08:11 AM
Dears
Please help me to get it fix site to site vpn with FCM7.0.1 added FTD6.4 to SonicWALL
IKEV2 SHA256/AES-256/DH-2 Lifetime 28800 already tried tunnel is not up still
Solved! Go to Solution.
05-12-2022 05:01 AM
Can you ping sonicwall ?
05-12-2022 05:21 AM
05-12-2022 05:24 AM
is ICMP blocked in the path?
If not, then they must be replying to ping, if they are not then this is a communication issue to resolve first and then into the ipsec
05-12-2022 05:42 AM
05-12-2022 06:21 AM
What I meant was are you able to reach the external IP address of both Devices in question from each other?
Another test we can perform is : if this box is not in production, can you revert to Ikev1 and then test if this is working
OR
Do this :
1. Login to FTD CLI
2. Go into diagnostic mode by typing system support diagnostic-cli and then hit enter
3. Start debug (debugs are heavy sometimes for prod , so a condition is good) : a) put a condition for peer by typing
a)debug crypto condition peer <SONICWALL FIREWALL EXTERNAL IP>
b) debug crypto ikev2 platform 127
c) debug crypto ikev2 protocol 127
This should give you the output about what is happening in exchange of first few packets
05-12-2022 07:47 AM
05-12-2022 08:00 AM
05-12-2022 05:14 AM
my initial thought is the same, are they reachable
also i see that you have pfs enabled on FTD but not on Sonicwall side, although PFS comes into play for phase 2, can you make them same as well
05-12-2022 11:20 PM
05-13-2022 12:44 AM
05-13-2022 09:27 AM - edited 05-13-2022 10:09 AM
Hello Sharath, as i showed you the changes we made were good, the Integrity and PRF on FTD needs to match with Integrity on the Sonicwall, Sonicawall does not have any setting for PRF, it takes the value from Integrity
In order to test the tunnel, generate some traffic and as i showed you, it worked.
****
Please accept this as solution if this resolved your problem
Thanks
Raminder
05-13-2022 10:28 AM
Dear Singh
THANK YOU SO MUCH THE KIND SUPPORT
YOU DONE IT WELL DONE
THAKS AGAIN
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide