This article describes how to troubleshoot a site-to-site VPN where the SA is Up but the Monitor status is Down on an SRX Series device.
> show security ipsec security-associations Total active tunnels: 1 ID Algorithm SPI Life:sec/kb Mon lsys Port Gateway <268173356 ESP:aes-cbc-128/sha1 5895f48b 2086/ unlim D root 54017 10.10.10.10 >268173356 ESP:aes-cbc-128/sha1 16693188 2086/ unlim D root 54017 10.10.10.10
Perform the procedure below to troubleshoot a VPN Tunnel in which the SA is Active but the Monitor status is Down. (To view a flowchart of the procedure, see KB10104 [juniper.net] .)
Is this a Site-to-Site (or LAN-to-LAN) VPN? (A Site-to-Site VPN runs between two Juniper VPN devices or a Juniper VPN device and an OEM VPN device. A Site-to-Site VPN does not run between the Juniper VPN device and a PC client running VPN software.)
Yes - Proceed to Step 2 . No - See KB10089 - How to Troubleshoot a NetScreen-Remote or IPSec VPN client to a J Series or SRX device that will not come active [juniper.net] .
Is the IKE SA (Security Association) UP? Is the Mon Status DOWN? (For assistance, see KB10090 - How do I tell if a VPN Tunnel SA (Security Association) is active on a J Series or SRX Series device? [juniper.net] .)
If the IKE SA state is UP and the IPSec Mon status is D , proceed to Step 3. If the IKE SA state is UP and the IPSec Mon status is U or the symbol " - " is displayed, see KB10093 - How to Troubleshoot a VPN that is up, but, is not Passing Traffic on a J Series or SRX Series device [juniper.net] .
I s the VPN Monitor "Optimized" feature enabled for this VPN? ( For assistance, see KB10118 - How do you enable the optimized feature of VPN Monitor on a J Series or SRX Series device, and what does it do? [juniper.net] )
Yes - Proceed to Step 4 . No - Enable the VPN Monitor "Optimize" setting and test the VPN connection again.
From J-Web : Go to Configure > IPSec VPN >Auto Tunnel > Phase II >Auto Key VPN and uncheck the Enable VPN monitor box. From CLI : Enter this command: deactivate security ipsec vpn <vpn_name> vpn-monitor .
deactivate security ipsec vpn <vpn_name> vpn-monitor
With the VPN Monitor disabled, is the policy passing data? (For assistance with enabling logging, consult: KB10112 - Configuring the Junos Traffic Log [juniper.net] .
Yes - Proceed to Step 6. No - See KB10113 - How to troubleshoot a Policy that is not passing data on a J Series or SRX Series device [juniper.net] .
Is the remote VPN connection a non-Juniper VPN Firewall device, or is the remote VPN device configured to block ICMP Echo Requests?
Yes - Re-enable the VPN Monitor and reconfigure the VPN Monitor to use the Source interface and Destination IP options. (For assistance, see KB10119 - Configuring the Source Interface and Destination IP options of VPN Monitor on J-Series and SRX devices [juniper.net] .) No - Proceed to Step 7.
Collect logs and open a case with JTAC (Juniper Technical Assistance Center). (For assistance, see KB21781 - [SRX] Data Collection Checklist - Logs/data to collect for troubleshooting [juniper.net] .)
2020-03-26: Article reviewed for accuracy; it is valid and accurate