Beruflich Dokumente
Kultur Dokumente
SRX.
This second official attempt requires to take a look on each previous setup step on Digibox
due to some network changes on SRX. Specially avoid IP overlapping because there are
alredy some routes on SRX using 192.168.2.0, hence the new internal network for Digibox
will be 192.168.3.0
There was also a big typo detected regarding pointing the SRXs public ip address.
User pass for device: username/password
Updating firmware
Before
After
http://www.digi.com/support/productdetail?pid=5501
Reset to defaults
Administrator > Factory Default Settings.
Second attempt
94.225.232.87/20
Configure IKE
IKE 0:
Encryption: AES 256
Autentication SHA1
Mode Main
Group phase 1 2
Group Phase 2 2
Renegotiation 8h
Configure Responder
AES 256
Authentication SHA1
Group 2 2
PSK configuration
Configuration - Security > Users > User 0 - 9 > User 3
94.255.234.251 (epic typo)
psk is juniper
After
Check routes
Not good
From Eroute 0
From Eroute 0
Session
From Eroute 0
Peer: ,Negotiation Failure
Failed. Peer: ,Retries
From Eroute 0
From Eroute 0
Session
From Eroute 0
Peer: ,Negotiation Failure
Failed. Peer: ,Retries
From Eroute 0
From Eroute 0
Session
From Eroute 0
Peer: ,Negotiation Failure
Failed. Peer: ,Retries
From Eroute 0
From Eroute 0
Session
94.255.234.251,Initiator
19:34:05, 05 Aug 2016,IKE Request Received From Eroute 0
19:34:05, 05 Aug 2016,(11) IKE SA Removed. Peer: ,Negotiation Failure
19:34:05, 05 Aug 2016,(11) IKE Negotiation Failed. Peer: ,Retries
Exceeded
19:33:55, 05 Aug 2016,IKE Request Received From Eroute 0
19:33:45, 05 Aug 2016,IKE Request Received From Eroute 0
19:33:35, 05 Aug 2016,(11) New Phase 1 IKE Session
94.255.234.251,Initiator
19:33:35, 05 Aug 2016,IKE Request Received From Eroute 0
19:33:35, 05 Aug 2016,(10) IKE SA Removed. Peer: ,Negotiation Failure
19:33:35, 05 Aug 2016,(10) IKE Negotiation Failed. Peer: ,Retries
Exceeded
19:33:25, 05 Aug 2016,IKE Request Received From Eroute 0
19:33:15, 05 Aug 2016,IKE Request Received From Eroute 0
19:33:05, 05 Aug 2016,(10) New Phase 1 IKE Session
94.255.234.251,Initiator
19:33:05, 05 Aug 2016,IKE Request Received From Eroute 0
19:33:05, 05 Aug 2016,(9) IKE SA Removed. Peer: ,Negotiation Failure
19:33:05, 05 Aug 2016,(9) IKE Negotiation Failed. Peer: ,Retries Exceeded
19:32:55, 05 Aug 2016,IKE Request Received From Eroute 0
19:32:45, 05 Aug 2016,IKE Request Received From Eroute 0
19:32:35, 05 Aug 2016,(9) New Phase 1 IKE Session
94.255.234.251,Initiator
19:32:35, 05 Aug 2016,IKE Request Received From Eroute 0
19:32:35, 05 Aug 2016,(8) IKE SA Removed. Peer: ,Negotiation Failure
19:32:35, 05 Aug 2016,(8) IKE Negotiation Failed. Peer: ,Retries Exceeded
19:32:25, 05 Aug 2016,IKE Request Received From Eroute 0
19:32:15, 05 Aug 2016,IKE Request Received From Eroute 0
19:32:05, 05 Aug 2016,(8) New Phase 1 IKE Session
94.255.234.251,Initiator
19:32:05, 05 Aug 2016,IKE Request Received From Eroute 0
19:32:05, 05 Aug 2016,(7) IKE SA Removed. Peer: ,Negotiation Failure
19:32:05, 05 Aug 2016,(7) IKE Negotiation Failed. Peer: ,Retries Exceeded
19:31:55, 05 Aug 2016,IKE Request Received From Eroute 0
19:31:45, 05 Aug 2016,IKE Request Received From Eroute 0
19:31:35, 05 Aug 2016,(7) New Phase 1 IKE Session
94.255.234.251,Initiator
19:31:35, 05 Aug 2016,IKE Request Received From Eroute 0
19:31:35, 05 Aug 2016,(6) IKE SA Removed. Peer: ,Negotiation Failure
19:31:35, 05 Aug 2016,(6) IKE Negotiation Failed. Peer: ,Retries Exceeded
19:31:25, 05 Aug 2016,IKE Request Received From Eroute 0
19:31:15, 05 Aug 2016,IKE Request Received From Eroute 0
19:31:05, 05 Aug 2016,(6) New Phase 1 IKE Session
94.255.234.251,Initiator
19:31:05, 05 Aug 2016,IKE Request Received From Eroute 0
19:31:05, 05 Aug 2016,(5) IKE SA Removed. Peer: ,Negotiation Failure
19:31:05, 05 Aug 2016,(5) IKE Negotiation Failed. Peer: ,Retries Exceeded
19:30:55, 05 Aug 2016,IKE Request Received From Eroute 0
19:30:45, 05 Aug 2016,IKE Request Received From Eroute 0
19:30:35, 05 Aug 2016,(5) New Phase 1 IKE Session
94.255.234.251,Initiator
19:30:35, 05 Aug 2016,IKE Request Received From Eroute 0
19:30:35, 05 Aug 2016,(4) IKE SA Removed. Peer: ,Negotiation Failure
19:30:35, 05 Aug 2016,(4) IKE Negotiation Failed. Peer: ,Retries Exceeded
19:30:25, 05 Aug 2016,IKE Request Received From Eroute 0
19:30:15, 05 Aug 2016,IKE Request Received From Eroute 0
19:30:05, 05 Aug 2016,(4) New Phase 1 IKE Session
94.255.234.251,Initiator
19:30:05, 05 Aug 2016,IKE Request Received From Eroute 0
19:30:05, 05 Aug 2016,(3) IKE SA Removed. Peer: ,Negotiation Failure
18:57:06, 05 Aug
255.255.255.0
18:57:06, 05 Aug
192.168.1.0
18:57:06, 05 Aug
255.255.255.0
18:57:06, 05 Aug
192.168.2.0
18:57:06, 05 Aug
94.255.234.251
18:57:06, 05 Aug
SRX
18:42:45, 05 Aug
18:41:01, 05 Aug
18:40:39, 05 Aug
18:39:53, 05 Aug
18:39:50, 05 Aug
18:39:14, 05 Aug
18:39:14, 05 Aug
18:39:14, 05 Aug
18:39:11, 05 Aug
18:39:11, 05 Aug
18:39:11, 05 Aug
18:39:11, 05 Aug
18:39:11, 05 Aug
18:39:11, 05 Aug
18:39:10, 05 Aug
18:39:06, 05 Aug
18:39:06, 05 Aug
18:39:06, 05 Aug
18:39:06, 05 Aug
18:39:00, 05 Aug
18:39:00, 05 Aug
Monitoring IKE SA
References
Release notes:
http://ftp1.digi.com/support/firmware/Digi%20TransPort%20Release%20Notes
%2052154.pdf
How to upgrade Firmware
http://knowledge.digi.com/articles/Knowledge_Base_Article/How-to-upgrade-the-firmwareon-a-Digi-TransPort-router-using-the-Web-interface/?
q=How+to+upgrade+the+firmware+on+a+Digi+TransPort+router+using+the+Web+interface
&l=en_US&c=Product_Category%3AEnterprise_Routers&fs=Search&pn=1