NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

MBau's avatar
MBau
Aspirant
Dec 19, 2016

SRX5308 Only two IPSEC Channels working over same IKE

Hello,

 

I have configured two SRX5308 (R1, R2) to connect over a IKE Channel (IKE1). This channel were used by three IP-Sec Channels (IPSEC1 - IPSEC3). All Channels are configured with the same subnet on R1 side and different subnets on R2 side. Anything else are common configured.

 

As soon as I enabled the IPSec Channels, two channels are up and one not. If I disabled and reenabled the channels, sometimes two other channels up and one not.

Summary I mean: Maximum two random channels are up.

 

Is the SRX5308 limited to two IPSECs per IKE Channel? 

 

Best regards

 

7 Replies

  • DaneA's avatar
    DaneA
    NETGEAR Employee Retired

    Hi MBau,

     

    Welcome to the community! :) 

     

    Kindly post a .img or .png image of your detailed network diagram as well as the settings you have configured on both SRX5308. 

     

    What is the current firmware version of both SRX5308?

     

     

    Regards,

     

    DaneA

    NETGEAR Community Team

    • MBau's avatar
      MBau
      Aspirant

      Hello DaneA,

       

      thank you for your fast reply.

       

      Here´s a simplified image. Through one IKE Tunnel should routed three IPSec Tunnels with different subnets.

       

      Simplyfied.png

       

      Following the full detailed image to show the real wireing.

      Full Detail.png

       

      Most routers don´t (or didn´t) support routing from vpn to vpn. And if they do, debugging is nearly not possible. So our department build up a IKE Connections to a separeted Router behind the main router realized with destination NAT (Portforwarding on matching source IP). Now it is possible to route to customer VPNs usinge a transfer network.

      It works! But only with two of three IPSEC Tunnels. With two random tunnels! Sometimes tunnel one and two. Sometime tunnel two and three.

       

       

      Best regards

       

      P.S: Firmware: 4.3.4-2
      IKE: Preshared Key - Aggressive - AES256 - SHA1 - DH5 - 28800s Lifetime - DPD on
      IPSEC:   AES256 - SHA1 - DH5 - 3600s

      • DaneA's avatar
        DaneA
        NETGEAR Employee Retired

        MBau,

         

        I have inquired your concern to a higher tier of NETGEAR Support.  On the SRX5308, 125 IPSec VPN policies can run concurrently using the same IKE policy, but the remote endpoint should be same for all IPSec VPN policies using the same IKE policy.  

         

        Kindly check that all remote endpoint are the same for all IPSec VPN policies.  Also, when one of the policies does not connect, kindly provide the VPN logs relating to this policy to be reviewed.

         

         

        Regards,

         

        DaneA

        NETGEAR Community Team

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More