Comware

 View Only
last person joined: yesterday 

Return Phase 2 IKE Packets dropping from MSR 958

This thread has been viewed 3 times
  • 1.  Return Phase 2 IKE Packets dropping from MSR 958

    Posted Jan 11, 2023 11:23 AM

    I have a MSR 958 router running 7.10 that is dropping phase 2 ike packets at the start of an IPSEC/L2TP tunnel.

    The setup is as follows:

    MSR 958 connects through a couple layer 2 switches to a Juniper then through a couple more layer 2 switches to our client. If I directly connect to the MSR router I am able to setup a VPN tunnel with phase 1, phase 2 and then ESP traffic going through successfully. However, when I attempt the connection from the client the connection fails with no response phase 2 packets coming from the router.

    The relevant protocols and ports are allowed on the Juniper, this device serves as the gateway for the client and regardless of VPN connection we are able to ping/SSH/HTTP.

    Anyone got any ideas here? Can share an obfuscated copy of the config if needed.