Juniper Log:
2008-05-21 11:56:26 system warn 00519 Admin user "netscreen" logged in for Web(http) management (port 80) from 206.47.254.242:2275
2008-05-21 11:28:29 system info 00536 IKE<206.47.254.242> Phase 1: Aborted negotiations because the time limit has elapsed. (0000/8460303)
2008-05-21 11:27:26 system info 00536 IKE<206.47.254.242> Phase 1: Responder starts AGGRESSIVE mode negotiations.
2008-05-21 11:11:21 system warn 00519 Admin user "n******n" logged in for Web(http) management (port 80) from 206.47.254.242:1992
2008-05-21 11:00:44 system info 00767 System configuration saved by netscreen via web from host 10.10.20.105 to 10.10.20.1:80 by netscreen.
2008-05-21 11:00:44 system notif 00017 VPN VPNHome with gateway VPNDynamic and P2 proposal nopfs-esp-aes128-sha has been modified by netscreen via web from host 10.10.20.105 to 10.10.20.1:80.
2008-05-21 11:00:44 system notif 00017 Gateway VPNDynamic at 0.0.0.0 in main mode with ID markm@tsi-cn.ca has been modified by netscreen via web from host 10.10.20.105 to 10.10.20.1:80.
2008-05-21 10:58:12 system warn 00519 Admin user "netscreen" logged in for Web(http) management (port 80) from 10.10.20.105:2016
2008-05-21 10:53:36 system notif 00531 No NTP server could be contacted.
2008-05-21 10:28:17 system notif 00029 DNS has been refreshed.
2008-05-21 10:28:17 system info 00004 DNS entries have been automatically refreshed.
2008-05-21 10:25:46 system info 00767 System configuration saved by netscreen via web from host 10.10.20.105 to 10.10.20.1:80 by netscreen.
2008-05-21 10:25:38 system info 00767 System configuration saved by netscreen via web from host 10.10.20.105 to 10.10.20.1:80 by netscreen.
2008-05-21 10:25:29 system info 00767 System configuration saved by netscreen via web from host 10.10.20.105 to 10.10.20.1:80 by netscreen.
2008-05-21 10:25:20 system info 00767 System configuration saved by netscreen via web from host 10.10.20.105 to 10.10.20.1:80 by netscreen.
2008-05-21 10:18:08 system warn 00519 Admin user "netscreen" logged in for Web(http) management (port 80) from 10.10.20.105:1861
2008-05-21 10:04:07 system warn 00519 Admin user "netscreen" logged in for Web(http) management (port 80) from 10.10.20.105:1831
2008-05-21 08:08:37 system notif 00564 Wireless station event: station 00164470975d is associated, SSID: TSICNAP1.
2008-05-21 08:08:36 system notif 00564 Wireless station event: Station 00164470975d Open authentication passed, SSID: TSICNAP1.
2008-05-21 08:08:07 system notif 00564 Wireless station event: station 001f3a29b455 is associated, SSID: TSICNAP1.
2008-05-21 08:08:07 system notif 00564 Wireless station event: Station 001f3a29b455 Open authentication passed, SSID: TSICNAP1.
2008-05-21 07:45:45 system notif 00564 Wireless station event: station 001c2639e343 is associated, SSID: TSICNAP1.
2008-05-21 07:45:45 system notif 00564 Wireless station event: Station 001c2639e343 Open authentication passed, SSID: TSICNAP1.
2008-05-21 06:28:40 system notif 00029 DNS has been refreshed.
2008-05-21 06:28:40 system info 00004 DNS entries have been automatically refreshed.
2008-05-21 02:28:03 system notif 00029 DNS has been refreshed.
2008-05-21 02:28:03 system info 00004 DNS entries have been automatically refreshed.
Netscreen Remote Log:
5-21: 11:56:02.778 My Connections\Work - message not received! Retransmitting!
5-21: 11:56:02.778 My Connections\Work - SENDING>>>> ISAKMP OAK AG (Retransmission)
5-21: 11:56:18.757 My Connections\Work - message not received! Retransmitting!
5-21: 11:56:18.757 My Connections\Work - SENDING>>>> ISAKMP OAK AG (Retransmission)
5-21: 11:56:34.736 My Connections\Work - message not received! Retransmitting!
5-21: 11:56:34.736 My Connections\Work - SENDING>>>> ISAKMP OAK AG (Retransmission)
5-21: 11:56:50.715 My Connections\Work - Exceeded 3 IKE SA negotiation attempts
5-21: 11:57:06.866
5-21: 11:57:06.866 My Connections\Work - Initiating IKE Phase 1 (IP ADDR=1.1.1.1)
5-21: 11:57:07.007 My Connections\Work - SENDING>>>> ISAKMP OAK AG (SA, KE, NON, ID, VID 6x)
5-21: 11:57:22.674 My Connections\Work - message not received! Retransmitting!
5-21: 11:57:22.674 My Connections\Work - SENDING>>>> ISAKMP OAK AG (Retransmission)
5-21: 11:57:24.843 My Connections\Work - Disconnecting IPSec SA
5-21: 11:57:24.843 My Connections\Work - Disconnecting IKE SA negotiation
5-21: 11:57:25.810
5-21: 11:57:25.810 My Connections\Work - Initiating IKE Phase 1 (IP ADDR=1.1.1.1)
5-21: 11:57:26.013 My Connections\Work - SENDING>>>> ISAKMP OAK AG (SA, KE, NON, ID, VID 6x)
OK ... I know there must be something simple I'm missing. I changed the setting to AGGRESSIVE MODE as you said. Something is still not right. I know it's me doing something wrong here. I included today's logs as well as screen shots of Netscreen Remote settings.
I will also try to get some shots of the Juniper Appliance settings as well.
Main Topics
Browse All Topics





by: dpk_walPosted on 2008-05-21 at 00:38:49ID: 21612798
Ok, I see the problem upfront:
>>SENDING>>>> ISAKMP OAK AG (SA, KE, NON, ID, VID 6x)
>> <VPNDynamic> has a dynamic IP address and negotiations are in Main mode.
The remote clients always use aggressive mode because the remote cilent has DHCP or dynamic IP and main mode cannot be used; but on the firewall you have configured main mode; change this to aggressive mode and then observe the results.
Please implement and update.
I really appreciate you posting logs from both ends as it gives a quick insight as to what is happening.
Thank you.