12-22-2017 04:27 AM - edited 03-12-2019 04:51 AM
Hi,
I try to configure VPN between ASA and Juniper (initiator). The Parameters are the follow:
Phase1:
- AES-256
- SHA1
- DH Gr. 2
- Lifetime7800
Phase2:
- ESP-AES-256-SHA
- Group 2
- Lifetime 3600
In log I can see, that ASA sends MM2, but doesn't receive MM3 from Juniper.
And ASA has MM_WAIT_MSG3 state.
Can somebody say what ist the problem.
Best regards
12-22-2017 05:48 AM
Hello @Jewgeni Uschegow,
The state MM_WAIT_MSG3 means you receive the first packet, respond with the second one but you don´t receive anything back from the initiator. This means the second packet is lost/blocked somewhere in the path, I would suggest to initiate a capture on Juniper side in order to see if your response gets into that FW.
Another thing you should do is to involve your ISP and verify if the traffic is being allowed, one more thing... if you have a device in front of the ASA verify if it's not dropping the packets.
HTH
Gio
12-22-2017 06:42 AM
12-26-2017 02:44 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide