NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

Vas_aras's avatar
Vas_aras
Aspirant
Apr 28, 2016

site-to-site VPN: SRX5308 to CISCO 5515 ASA. No phase 2 Handle found

Hello, I'm trying to setup a site-to-site IPSec VPN using my SRX5308 to a remote CISCO 5515 ASA. the configurations are the same both sides and no matter how much we play around with them (changing encryption algorithms, SA lifetimes, etc) the error is always the same: No phase2 handle found. I've tried using the Wizard, removing all VPN and IKE policies and reconfiguring them manually but no luck. here's the full log: Thu Apr 28 10:15:53 2016 (GMT +0100): [SRX5308] [IKE] INFO: Purged ISAKMP-SA with proto_id=ISAKMP and spi=d440ae5a0fa65d16:996820ade8092fb8. Thu Apr 28 10:15:53 2016 (GMT +0100): [SRX5308] [IKE] ERROR: Unknown notify message from *remote IP*[500].No phase2 handle found. Thu Apr 28 10:15:53 2016 (GMT +0100): [SRX5308] [IKE] INFO: Initiating new phase 2 negotiation: *myPublicIP*[500]<=>109.94.141.10[0] Thu Apr 28 10:15:52 2016 (GMT +0100): [SRX5308] [IKE] INFO: Sending Informational Exchange: notify payload[INITIAL-CONTACT] Thu Apr 28 10:15:52 2016 (GMT +0100): [SRX5308] [IKE] INFO: ISAKMP-SA established for *myPublicIP*[500]-*remote IP*[500] with spi:d440ae5a0fa65d16:996820ade8092fb8 Thu Apr 28 10:15:52 2016 (GMT +0100): [SRX5308] [IKE] INFO: Received Vendor ID: DPD Thu Apr 28 10:15:52 2016 (GMT +0100): [SRX5308] [IKE] INFO: NAT not detected Thu Apr 28 10:15:52 2016 (GMT +0100): [SRX5308] [IKE] INFO: NAT-D payload matches for *remote IP*[500] Thu Apr 28 10:15:52 2016 (GMT +0100): [SRX5308] [IKE] INFO: NAT-D payload matches for *myPublicIP*[500] Thu Apr 28 10:15:52 2016 (GMT +0100): [SRX5308] [IKE] INFO: Received unknown Vendor ID Thu Apr 28 10:15:52 2016 (GMT +0100): [SRX5308] [IKE] INFO: Received unknown Vendor ID Thu Apr 28 10:15:52 2016 (GMT +0100): [SRX5308] [IKE] INFO: Received Vendor ID: draft-ietf-ipsra-isakmp-xauth-06.txt Thu Apr 28 10:15:52 2016 (GMT +0100): [SRX5308] [IKE] INFO: For *remote IP*[500], Selected NAT-T version: RFC 3947 Thu Apr 28 10:15:52 2016 (GMT +0100): [SRX5308] [IKE] INFO: Received unknown Vendor ID Thu Apr 28 10:15:52 2016 (GMT +0100): [SRX5308] [IKE] INFO: Received Vendor ID: RFC 3947 Thu Apr 28 10:15:52 2016 (GMT +0100): [SRX5308] [IKE] INFO: [isakmp_ident.c:190]: XXX: setting vendorid: 9 Thu Apr 28 10:15:52 2016 (GMT +0100): [SRX5308] [IKE] INFO: [isakmp_ident.c:190]: XXX: setting vendorid: 8 Thu Apr 28 10:15:52 2016 (GMT +0100): [SRX5308] [IKE] INFO: [isakmp_ident.c:190]: XXX: setting vendorid: 4 Thu Apr 28 10:15:52 2016 (GMT +0100): [SRX5308] [IKE] INFO: [isakmp_ident.c:186]: XXX: NUMNATTVENDORIDS: 3 Thu Apr 28 10:15:52 2016 (GMT +0100): [SRX5308] [IKE] INFO: Beginning Identity Protection mode. Thu Apr 28 10:15:52 2016 (GMT +0100): [SRX5308] [IKE] INFO: Initiating new phase 1 negotiation: *myPublicIP*[500]<=>*remote IP*[500] Thu Apr 28 10:15:52 2016 (GMT +0100): [SRX5308] [IKE] INFO: Configuration found for *remote IP*. Thu Apr 28 10:15:52 2016 (GMT +0100): [SRX5308] [IKE] INFO: Configuration found for *remote IP*. Thu Apr 28 10:15:52 2016 (GMT +0100): [SRX5308] [IKE] INFO: accept a request to establish IKE-SA: *remote IP* At this point I can only assume that the problem is some sort of incompatibility between the two devices. Has anyone any experience with anything similar? The only similar issues I found suggested solutions that I've already tried and failed (eg. re-create the policies manually, rename the Policies to much the remote host address, etc) Thanks.

3 Replies

  • JohnRo's avatar
    JohnRo
    NETGEAR Employee Retired

    Hello Vas_aras, 

     

    Welcome to the community! 

     

    I have found an old thread that might be related to your issue, see here. Usually, phase2 errors are caused by unmatched encryptions on both ends of the tunnel. Try the things that have been suggested by other members. It is very rare that we get cases like these because mostly they use the same brand on both ends. 

     

    Hope this helps. 

     

    Thanks, 

    • Vas_aras's avatar
      Vas_aras
      Aspirant

      Thanks for the reply,  I appreciate the help

       

      I'll check it out

      • JohnRo's avatar
        JohnRo
        NETGEAR Employee Retired

        Hello Vas_aras, 

         

        You are welcome! Let us know if this helps. Let's also wait if some community members can share thier thoughts on this. :) 

         

        Thanks,