Hi Wolfgang,

Thanks for the reply. I've made some progress, the tunnel is now showing as up. I checked SecureXL but it isn't configured on the gateway. From the 3rd party endpoint to our gateway a 'child SA is successfully created' log entry is created, but going in the opposite direction I see a log message 'Child SA exchange: Peer's message is unacceptable'.

Is it a case that we have to use IKEv1 or is that less than ideal?


