This article provides information about the rules to follow when configuring a pre-shared key. At times, customers have issues with configuring the IPSEC tunnel across the devices; even after having the similar proposal, policy, and pre-shared key on both of the peer devices.
The output of the ike security-associations shows Phase-1 as DOWN ; even after receiving the responder cookie.
[edit] root# run show security ike security-associations Index State Initiator cookie Responder cookie Mode Remote Address 3052057 DOWN ee02735b2b594ef8 a3fa84c4338944a5 Main 10.10.10.1 3052056 DOWN bbccd36c7ee446ad 36f5fe01d20bdf88 Main 12.12.12.1
This issue occurs when the pre-shared key is not properly configured.
pre-shared-key (ascii-text key | hexadecimal key);