- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- IKE failure: Child SA exchange Issue
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IKE failure: Child SA exchange Issue
I have a L-71 unit that we are trying to connect to our other office. We managed to get connection after many hours of testing but we keep getting this error on both ends despite a good connection. So much as a single ping causes this error to fire. What is this and how do we fix it?
Description
IKE failure: Child SA exchange: Received notification from peer: Traffic selectors unacceptable
IKE Phase2 Message ID: 00000001
Reject Category: IKE failure
Encryption Scheme: IKEv2
VPN Feature: IKE
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Versions used on both ends, details about your VPN config? What do you call "a good connection" in this context?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Traffic selectors are generally when one side proposes a host/subnet that is not defined on the other side. The log file should tell you which traffic selectors is providing the error, otherwise you'll have to do a debug to get that information.
If you send 10.20.30.0/24, that's how it needs to be defined on both sides. You would get an error if one side was 10.20.30.0/23 for example.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
L-71 is a 1400 Series for those playing along at home.
This message means the remote site doesn’t accept the proposed encryption domain (Traffic selectors) by current gateway.
This can indicate a configuration problem, such as:
- Missing subnets on either of the peers
- Unaligned tunnel sharing configurations (tunnel per gateway \ subnet \ address)
- Route all traffic configured on a site where other peer is oblivious.
Verify the following :
- Encryption domains are configured correctly on both peers.
- Tunnel sharing is aligned on both peers
- If route all traffic is configured on the site, confirm that "Allow traffic to the internet from remote site through this Security Gateway" is enabled under "advanced" tab on peer WebUI site configuration.
