This article shows a method to sync the SPU and RE time when these conditions are present: the output of the command show security ike security-association does not display any output, however the command show security ipsec security-association shows that the SA and VPN tunnel is up.
show security ike security-association
show security ipsec security-association
Symptoms :
how security ipsec security-association
In cases when configuring IPSec VPNs on SRX devices with multiple SPUs, it is required to configure NTP so that the timestamps are synchronized between the multiple SPU boards. If there is a mismatch between the SPU boards and system clock, there could be a time sync issue with the result that the IPSec SA will show the lifetime as expired, and there will be no IKE SA output. Example:
root@srx3600> show security ike security-associationroot@srx3600> show security ipsec security-association Total active tunnels: 1 ID Gateway Port Algorithm SPI Life:sec/kb Mon vsys <2 1.1.1.1 500 ESP:aes-128/md5 3566b635 expir/expir - 0 >2 1.1.1.1 500 ESP:aes-128/md5 a38860a expir/expir - 0