Hello,
I am using a Juniper-Netscreen20 to connect to a CISCO asa with a VPN tunnel.
I am using a routed mode VPN on my Netscreen and I am trying to connect to the cofiguration below
My Tunnel interface is setup as 10.2.300.224 255.255.255.224. When I try to connect to the remote cisco gateway
I pass pahse 1 and right after phase 2 I get the following message
<*.*.*.*>Received notification message for DOI <1><18> <INVALID -ID-NOTIFICATION>, that message makes me think
that my proxy ID values are not matching. as you know I only have one place to enter the remote network address on the Juniper
How could I match the remote Proxy ID information with the infor below?
I see 192.168.3.XX and 172.16.2.XX
Acls for interesting traffic;
access-list client-vpn-2-us permit tcp host 192.168.3.54 10.2.300.224 255.255.255.224 eq 1433
access-list client-vpn-2-us permit tcp host 192.168.3.56 10.2.300.224 255.255.255.224 eq 1433
access-list client-vpn-2-us permit tcp host 192.168.3.93 10.2.300.224 255.255.255.224 eq 1433
access-list client-vpn-2-us permit tcp host 192.168.3.175 10.2.300.224 255.255.255.224 eq 1433
access-list client-vpn-2-us permit tcp host 172.16.2.165 10.2.300.224 255.255.255.224 eq 1433
access-list client-vpn-2-us permit tcp host 192.168.3.56 10.2.300.224 255.255.255.224 eq 137
access-list client-vpn-2-us permit tcp host 192.168.3.56 10.2.300.224 255.255.255.224 eq 139
access-list client-vpn-2-us permit tcp host 192.168.3.56 10.2.300.224 255.255.255.224 eq 445
access-list client-vpn-2-us permit udp host 192.168.3.56 10.2.300.224 255.255.255.224 eq 137
access-list client-vpn-2-us permit udp host 192.168.3.56 10.2.300.224 255.255.255.224 eq 138
access-list client-vpn-2-us permit tcp host 192.168.3.57 10.2.300.224 255.255.255.224 eq 137
access-list client-vpn-2-us permit tcp host 192.168.3.57 10.2.300.224 255.255.255.224 eq 139
access-list client-vpn-2-us permit tcp host 192.168.3.57 10.2.300.224 255.255.255.224 eq 445
access-list client-vpn-2-us permit udp host 192.168.3.57 10.2.300.224 255.255.255.224 eq 137
access-list client-vpn-2-us permit udp host 192.168.3.57 10.2.300.224 255.255.255.224 eq 138
access-list client-vpn-2-us permit tcp host 192.168.3.93 10.2.300.224 255.255.255.224 eq 137
access-list client-vpn-2-us permit tcp host 192.168.3.93 10.2.300.224 255.255.255.224 eq 139
access-list client-vpn-2-us permit tcp host 192.168.3.93 10.2.300.224 255.255.255.224 eq 445
access-list client-vpn-2-us permit udp host 192.168.3.93 10.2.300.224 255.255.255.224 eq 137
access-list client-vpn-2-us permit udp host 192.168.3.93 10.2.300.224 255.255.255.224 eq 138
access-list client-vpn-2-us permit tcp host 192.168.3.175 10.2.300.224 255.255.255.224 eq 137
access-list client-vpn-2-us permit tcp host 192.168.3.175 10.2.300.224 255.255.255.224 eq 139
access-list client-vpn-2-us permit tcp host 192.168.3.175 10.2.300.224 255.255.255.224 eq 445
access-list client-vpn-2-us permit udp host 192.168.3.175 10.2.300.224 255.255.255.224 eq 137
access-list client-vpn-2-us permit udp host 192.168.3.175 10.2.300.224 255.255.255.224 eq 138
access-list client-vpn-2-us permit tcp host 172.16.2.165 10.2.300.224 255.255.255.224 eq 137
access-list client-vpn-2-us permit tcp host 172.16.2.165 10.2.300.224 255.255.255.224 eq 139
access-list client-vpn-2-us permit tcp host 172.16.2.165 10.2.300.224 255.255.255.224 eq 445
access-list client-vpn-2-us permit udp host 172.16.2.165 10.2.300.224 255.255.255.224 eq 137
access-list client-vpn-2-us permit udp host 172.16.2.165 10.2.300.224 255.255.255.224 eq 138
Crypto map etc
crypto ipsec transform-set client-strong esp-3des esp-sha-hmac
crypto map client-vpn 5 match address Client-vpn-2-US
crypto map client-vpn 5 set peer 28.9.111.129
crypto map client-vpn 5 set transform-set Client-strong
crypto map client-vpn interface outside
crypto isakmp identity address
crypto isakmp enable outside
crypto isakmp policy 5
authentication pre-share
encryption 3des
hash sha
group 2
lifetime 28800
Start Free Trial