I am trying to set-up a policy based VPN between a Netscreen 208 OS 5.0 & a Cisco PIX 506E 6.3
Phase proposals are working fine, it fails on phase 2 error on the Netscreen is:
Received a notification message for DOI <1> <14> <NO-PROPOSAL-CHOSEN>.
Phase 2: Initiated negotiations.
Phase 1: Completed Main mode negotiations with a <28800>-second lifetime.
Phase 2 on the NS is set vpn "PIX" gateway "PIX" no-replay tunnel idletime 0 proposal "g2-esp-des-sha"
Phase 2 on the PIX is
crypto ipssec transform-set netscreen esp-des esp-sha-hmac
crypto ipsec security-association lifetime seconds 3600
crypto map netscreen 10 ipsec-isakmp
crypto map netscreen 10 match address vpn
crypto map netscreen 10 set peer *.*.*.* (IP address removed)
crypto map netscreen 10 set security-association lifetime seconds 28800
crypto map netscreen interface outside
Any help with this would be very greatfully recieved, fast losing what little hair I have left!!
Start Free Trial