Description

IPSEC is configured on the SSR, however interface currently down

Symptoms


As part of troubleshooting, tried changing the psk, rebooted sdwan, restarted tunnel but it did not fix.

Ping from SSR to IP sec Server is successful.

Tunnel negotiation is not making it in the FW


Solution

Review of IPSEC logs

Per SSR ipsec service logs, SSR is sending tunnel request to the remote end , however there is no response from remote end to SSR and SSR IPsec clients timeout.

 

xxx nodename pluto[24069]: "ipsec-client-tunnel-prisma-prisma-srv" #1868: STATE_PARENT_I1: 60 second timeout exceeded after 7 retransmits. No response (or no acceptable response) to our first IKEv2 message

 

Running pcaket capture in SSR

Collected packet capture in E-gress interface to to the remote end , and confirmed that there are no response to the from remote end to SSR

 

Modification History

2025-08-11 : Article Created