IPsec VPN Tunnel Phase 1 negotiation fails due to a mismatch in the IKE version

IPsec VPN Tunnel Phase 1 negotiation fails due to a mismatch in the IKE version

11924
Created On 07/22/24 17:17 PM - Last Modified 07/25/24 20:39 PM


Symptom


 
  • Tunnel not coming up and getting error in the ikemgr.log showing the following message:
    2023-11-02 14:53:07.007 -0700  [PWRN]: 10.46.36.137[500] - 10.46.36.240[500]:0x5592efa62240 unknown ikev2 peer


Environment


  • IPsec tunnel


Cause


A mismatch in the configuration of the IKE gateway IKE version.

Resolution


  1. Ensure that the IKE Gateway IKE version is configured to match on both side of the IPsec tunnel.
    1. Look under the UI:
      1. For standalone firewall: Navigate to NETWORK > Network Profiles > IKE Gateways.
      2. For Panorama managed firewall: Navigate to Templates > NETWORK, select the right Template then look under Network Profiles > IKE Gateways.
      3. For Strata Cloud Manager managed firewalls: Navigate to Manage > Configuration > NGFW and Prisma Access, select the right Configuration Scope then look under Device Settings > IPsec tunnel.
    2. Check the IKE Gateway configuration of the tunnel which is down due to IKE gateway peer identification mismatch:IKE version
    3. If you select IKEv2 preferred mode, the two peers will use IKEv2 if the remote peer supports it; otherwise they’ll use IKEv1.


Additional Information


For more details refer to VPN Failing with Error 'Unknown ikev2 peer'.
Other useful article: How to check Status, Clear, Restore, and Monitor an IPSec VPN Tunnel.
If needing to restart the tunnel after committing the configuration change refer to Enable, Disable, Refresh, or Restart an IKE Gateway or IPSec Tunnel
 



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HDgzCAG&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language