NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
MBau
Dec 19, 2016Aspirant
SRX5308 Only two IPSEC Channels working over same IKE
Hello,
I have configured two SRX5308 (R1, R2) to connect over a IKE Channel (IKE1). This channel were used by three IP-Sec Channels (IPSEC1 - IPSEC3). All Channels are configured with the same subnet on R1 side and different subnets on R2 side. Anything else are common configured.
As soon as I enabled the IPSec Channels, two channels are up and one not. If I disabled and reenabled the channels, sometimes two other channels up and one not.
Summary I mean: Maximum two random channels are up.
Is the SRX5308 limited to two IPSECs per IKE Channel?
Best regards
7 Replies
- DaneANETGEAR Employee Retired
Hi MBau,
Welcome to the community! :)
Kindly post a .img or .png image of your detailed network diagram as well as the settings you have configured on both SRX5308.
What is the current firmware version of both SRX5308?
Regards,
DaneA
NETGEAR Community Team
- MBauAspirant
Hello DaneA,
thank you for your fast reply.
Here´s a simplified image. Through one IKE Tunnel should routed three IPSec Tunnels with different subnets.
Following the full detailed image to show the real wireing.
Most routers don´t (or didn´t) support routing from vpn to vpn. And if they do, debugging is nearly not possible. So our department build up a IKE Connections to a separeted Router behind the main router realized with destination NAT (Portforwarding on matching source IP). Now it is possible to route to customer VPNs usinge a transfer network.
It works! But only with two of three IPSEC Tunnels. With two random tunnels! Sometimes tunnel one and two. Sometime tunnel two and three.Best regards
P.S: Firmware: 4.3.4-2
IKE: Preshared Key - Aggressive - AES256 - SHA1 - DH5 - 28800s Lifetime - DPD on
IPSEC: AES256 - SHA1 - DH5 - 3600s- DaneANETGEAR Employee Retired
MBau,
I have inquired your concern to a higher tier of NETGEAR Support. On the SRX5308, 125 IPSec VPN policies can run concurrently using the same IKE policy, but the remote endpoint should be same for all IPSec VPN policies using the same IKE policy.
Kindly check that all remote endpoint are the same for all IPSec VPN policies. Also, when one of the policies does not connect, kindly provide the VPN logs relating to this policy to be reviewed.
Regards,
DaneA
NETGEAR Community Team
Related Content
NETGEAR Academy
Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!