Description

Sometimes, SD tries to push local and remote identity with the same FQDN while creating an IPSEC VPN from the UI. Due to this, the VPN tunnel will go down at the SRX end. This article explains how to fix it.

Symptoms

This issue will occur when we configure the IKE ID under Configure > IPSec VPN > Profiles > on advanced configuration inside the profile (Make sure that this profile is assigned to IPSec VPN, where devices are added)

Post that the SD will push both local and remote identity as the same. This is wrong behavior. Here is the screenshot to understand where we config:



This is a bug reported in 24.1 about this option to configure the IKE ID globally. However, we have a workaround to fix this issue.

Solution

To fix this issue, please configure the IKE ID separately by navigating to Configure > IPSec VPN > IPSec VPNs > select the problematic VPN, click the edit button > select one device > click Edit Tunnels, and configure the correct IKE ID of the device of that location.


Post that the preview will look fine



Modification History

2026-04-20 : Article Created