[x]
Posted via EE Mobile

Search, ask, and monitor your questions on the go with EE Mobile. Visit Experts Exchange from your mobile device and never be out of touch again.

Question
[x]
Attachment Details

SonicWALL TZ 210 to TZ 170 - VPN will not establish

Asked by camwyncwru in Networking Hardware Firewalls

Tags: SonicWALL, VPN

I am attempting to create a site-to-site VPN between two SonicWALL devices in my organization. One is a TZ 210, the other a TZ170. I cannot seem to get a live tunnel between the two sites. Here are the errors in our TZ 210's log when it tries to raise the tunnel:

11/04/2009 11:41:14.720 - Info - VPN IKE -       IKE negotiation aborted due to timeout -       XX.104.42.126, 500 -       XX.244.98.165, 500 -       VPN Policy: Local Site to Remote Site
11/04/2009 11:41:23.000 - Info - VPN IKE -       IKE Initiator: Start Main Mode negotiation (Phase 1) -       XX.104.42.126, 500 -       XX.244.98.165, 500 -       VPN Policy: Local Site to Remote Site
11/04/2009 11:41:23.272 - Info - VPN IKE -       NAT Discovery :  No NAT/NAPT device detected between IPSec Security gateways -       XX.104.42.126, 500 -       XX.244.98.165, 500 -       VPN Policy: Local Site to Remote Site
11/04/2009 11:41:29.720 - Info - VPN IKE -       IKE Initiator: Remote party timeout - Retransmitting IKE request. -       XX.104.42.126, 500 -       XX.244.98.165, 500 -       VPN Policy: Local Site to Remote Site
11/04/2009 11:41:29.720 - Warning - VPN IKE -       Received unencrypted packet in crypto active state -       XX.244.98.165, 500 -       XX.104.42.126, 500 -       VPN Policy: Local Site to Remote Site
11/04/2009 11:41:29.720 - Info - VPN IKE -       Received notify: INVALID_COOKIES -       XX.104.42.126, 500 -       XX.244.98.165, 500 -       VPN Policy: Local Site to Remote Site
11/04/2009 11:41:39.944 - Info - VPN IKE -       IKE Responder: Received Main Mode request (Phase 1) -       XX.244.98.165, 500 -       XX.104.42.126, 500 -       
11/04/2009 11:41:40.224 - Warning - VPN IKE -       IKE Responder: Proposed IKE ID mismatch -       XX.244.98.165, 500 -       XX.104.42.126, 500 -       VPN Policy: Local Site to Remote Site; Local ID type: USER FQDN; Remote ID type: IP Address
11/04/2009 11:41:41.720 - Info - VPN IKE -       IKE Initiator: Remote party timeout - Retransmitting IKE request. -       XX.104.42.126, 500 -       XX.244.98.165, 500 -       VPN Policy: Local Site to Remote Site
11/04/2009 11:41:41.720 - Warning - VPN IKE -       Received unencrypted packet in crypto active state -       XX.244.98.165, 500 -       XX.104.42.126, 500 -       VPN Policy: Local Site to Remote Site
11/04/2009 11:41:41.720 - Info - VPN IKE -       Received notify: INVALID_COOKIES -       XX.104.42.126, 500 -       XX.244.98.165, 500 -       VPN Policy: Local Site to Remote Site
11/04/2009 11:41:57.256 - Notice - Network Access -       Web management request allowed -       XX.168.0.103, 4814, X0 (admin) -       XX.168.103.1, 8888, X0 -       TCP HTTP Management
11/04/2009 11:41:59.720 - Info - VPN IKE -       IKE Initiator: Remote party timeout - Retransmitting IKE request. -       XX.104.42.126, 500 -       XX.244.98.165, 500 -       VPN Policy: Local Site to Remote Site
11/04/2009 11:41:59.720 - Warning - VPN IKE -       Received unencrypted packet in crypto active state -       XX.244.98.165, 500 -       XX.104.42.126, 500 -       VPN Policy: Local Site to Remote Site
11/04/2009 11:41:59.720 - Info - VPN IKE -       Received notify: INVALID_COOKIES -       XX.104.42.126, 500 -       XX.244.98.165, 500 -       VPN Policy: Local Site to Remote Site
11/04/2009 11:42:33.720 - Info - VPN IKE -       IKE negotiation aborted due to timeout -       XX.104.42.126, 500 -       XX.244.98.165, 500 -       VPN Policy: Local Site to Remote Site
[+][-]11/04/09 07:46 PM, ID: 25746592Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]11/19/09 10:42 AM, ID: 25863461Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20091021-EE-VQP-81 - Hierarchy / EE_QW_3_20080625