I've added the MD with correct model and mac-adress that shows up in activate EDIT: Labeled eth0 in activate.
I've used factory cert as ipsec security, seems I cannot add PSK into activate ?
show datapath:
Source IP Destination IP Prot SPort DPort Cntr Prio ToS Age Destination TAge Packets Bytes Flags CPU ID
--------------- --------------- ---- ----- ----- -------- ---- --- --- ----------- ---- --------- --------- --------------- -------
branch-ip mm-ip 17 4500 4500 0/0 0 0 1 0/0/0 479 1791 1426432 FC 7
mm-ip branch-ip 17 4500 4500 0/0 0 0 0 0/0/0 479 738 209831 F 7
#show crypto ipsec sa
IPSEC SA (V2) Active Session Information
-----------------------------------
Initiator IP Responder IP SPI(IN/OUT) Flags Start Time Inner IP
------------ ------------ ---------------- ----- --------------- --------
branch-ip mm-ip 4e65ea00/5f836600 UT2 Mar 12 10:05:40 -
Here is some log entry's when connecting the branchcontroller:
Mar 12 09:59:26 fpapps[5120]: <399815> <5123> <INFO> |fpapps| Added ipsec map default-local-master-ipsecmap-xx:xx:xx:xx:xx:xx
Mar 12 09:59:26 fpapps[5120]: <399815> <5123> <INFO> |fpapps| Deleting ipsec map default-local-master-ipsecmap-xx:xx:xx:xx:xx:xx
Mar 12 09:59:26 fpapps[5120]: <399815> <5123> <INFO> |fpapps| Duplicate MAP_ADD from IKE for default-local-master-ipsecmap-xx:xx:xx:xx:xx:xx (gw x.x.x.x) mapid 17570 vlanid 0 flags 0x0 addr x.x.x.x mask 255.255.255.255 prio 0
Mar 12 09:59:26 fpapps[5120]: <399838> <5123> <WARN> |fpapps| Received TUN_DOWN from IKE for default-local-master-ipsecmap-xx:xx:xx:xx:xx:xx
Mar 12 09:59:26 fpapps[5120]: <399838> <5123> <WARN> |fpapps| Received TUN_UP from IKE for default-local-master-ipsecmap-xx:xx:xx:xx:xx:xx mapid 0x44a2, vlanid 0, flags = 0x0 uplink_priority 0
Mar 12 09:59:26 isakmpd[5139]: <103076> <5139> <INFO> |ike| IKEv2 IPSEC Tunnel created for peer x.x.x.x:4500
Mar 12 09:59:26 isakmpd[5139]: <103077> <5139> <INFO> |ike| IKEv2 IKE_SA succeeded for peer x.x.x.x:4500
Mar 12 09:59:26 isakmpd[5139]: <103078> <5139> <INFO> |ike| IKEv2 CHILD_SA successful for peer x.x.x.x:4500
Mar 12 09:59:26 isakmpd[5139]: <103101> <5139> <INFO> |ike| IPSEC SA deleted for peer x.x.x.x
Mar 12 09:59:26 isakmpd[5139]: <103102> <5139> <INFO> |ike| IKE SA deleted for peer x.x.x.x