Description

Customer facing issues with packets traversing through a vpn tunnel that is suspected to be dropping with each attempt.

Symptoms

  • Customer has the following traffic selector configured within a single vpn:

traffic-selector ts-1 {

 local-ip 10.10.10.0/24;

 remote-ip 20.20.20.0/24;

}

 

traffic-selector ts-2 {

 local-ip 10.10.10.0/24;

 remote-ip 20.20.20.0/24;



  • Grepping within the messages log for both of these values, we can see the following occurring where ts-1 is established and ts-2 is seen being torn down:

 

Jul 12 19:10:27 SRX kmd[10237]: KMD_PM_SA_ESTABLISHED: Local gateway: 30.30.30.1, Remote gateway: 40.40.40.1, Local ID: ipv4(10.10.10.0-10.10.10.255), Remote ID: ipv4(20.20.20.0-20.20.20.255), Direction: inbound, SPI: 0x754f2eff, AUX-SPI: 0, Mode: Tunnel, Type: dynamic, Traffic-selector: ts-1 FC Name: 

 

Jul 12 19:10:27 SRX kmd[10237]: KMD_PM_SA_ESTABLISHED: Local gateway: 30.30.30.1, Remote gateway: 40.40.40.1, Local ID: ipv4(10.10.10.0-10.10.10.255), Remote ID: ipv4(20.20.20.0-20.20.20.255), Direction: outbound, SPI: 0xdb2412fe, AUX-SPI: 0, Mode: Tunnel, Type: dynamic, Traffic-selector: ts-1 FC Name: 

 

Jul 12 19:10:27 SRX kmd[10237]: KMD_VPN_UP_ALARM_USER: VPN Customer_LAN from 40.40.40.1 is up. Local-ip: 30.30.30.1, gateway name: Customer_LAN, vpn name: Customer_LAN, tunnel-id: 67108873, local tunnel-if: st0.0, remote tunnel-ip: Not-Available, Local IKE-ID: 169.48.68.90, Remote IKE-ID: 40.40.40.1, AAA username: Not-Applicable, VR id: 0, Traffic-selector: ts-1, Traffic-selector local ID: ipv4(10.10.10.0-10.10.10.255), Traffic-selector remote ID: ipv4(20.20.20.0-20.20.20.255), SA Type: Static

 

Jul 12 19:10:28 SRX kmd[10237]: KMD_VPN_DOWN_ALARM_USER: VPN Customer_LAN from 40.40.40.1 is down. Local-ip: 30.30.30.1, gateway name: Customer_LAN, vpn name: Customer_LAN, tunnel-id: 67108868, local tunnel-if: st0.0, remote tunnel-ip: Not-Available, Local IKE-ID: 169.48.68.90, Remote IKE-ID: 40.40.40.1, AAA username: Not-Applicable, VR id: 0, Traffic-selector: ts-2, Traffic-selector local ID: ipv4(10.10.10.0-10.10.10.255), Traffic-selector remote ID: ipv4(20.20.20.0-20.20.20.255), SA Type: Static, Reason: IPSec SA delete payload received from peer, corresponding IPSec SAs cleared

 

  • A few moments later, ts-2 establishes and it's ts-1 that is torn down:

 

Jul 12 19:10:33 SRX kmd[10237]: KMD_PM_SA_ESTABLISHED: Local gateway: 30.30.30.1, Remote gateway: 40.40.40.1, Local ID: ipv4(10.10.10.0-10.10.10.255), Remote ID: ipv4(20.20.20.0-20.20.20.255), Direction: inbound, SPI: 0x89429e93, AUX-SPI: 0, Mode: Tunnel, Type: dynamic, Traffic-selector: ts-2 FC Name: 

 

Jul 12 19:10:33 SRX kmd[10237]: KMD_PM_SA_ESTABLISHED: Local gateway: 30.30.30.1, Remote gateway: 40.40.40.1, Local ID: ipv4(10.10.10.0-10.10.10.255), Remote ID: ipv4(20.20.20.0-20.20.20.255), Direction: outbound, SPI: 0x6da59b71, AUX-SPI: 0, Mode: Tunnel, Type: dynamic, Traffic-selector: ts-2 FC Name: 

 

Jul 12 19:10:33 SRX kmd[10237]: KMD_VPN_UP_ALARM_USER: VPN Customer_LAN from 40.40.40.1 is up. Local-ip: 30.30.30.1, gateway name: Customer_LAN, vpn name: Customer_LAN, tunnel-id: 67108868, local tunnel-if: st0.0, remote tunnel-ip: Not-Available, Local IKE-ID: 169.48.68.90, Remote IKE-ID: 40.40.40.1, AAA username: Not-Applicable, VR id: 0, Traffic-selector: ts-2, Traffic-selector local ID: ipv4(10.10.10.0-10.10.10.255), Traffic-selector remote ID: ipv4(20.20.20.0-20.20.20.255), SA Type: Static

 

Jul 12 19:10:35 SRX kmd[10237]: KMD_VPN_DOWN_ALARM_USER: VPN Customer_LAN from 40.40.40.1 is down. Local-ip: 30.30.30.1, gateway name: Customer_LAN, vpn name: Customer_LAN, tunnel-id: 67108873, local tunnel-if: st0.0, remote tunnel-ip: Not-Available, Local IKE-ID: 169.48.68.90, Remote IKE-ID: 40.40.40.1, AAA username: Not-Applicable, VR id: 0, Traffic-selector: ts-1, Traffic-selector local ID: ipv4(10.10.10.0-10.10.10.255), Traffic-selector remote ID: ipv4(20.20.20.0-20.20.20.255), SA Type: Static, Reason: IPSec SA delete payload received from peer, corresponding IPSec SAs cleared

 

  • Pattern repeats as ts-1 is up and ts-2 is affected once more

 

Jul 12 19:10:50 SRX kmd[10237]: KMD_PM_SA_ESTABLISHED: Local gateway: 30.30.30.1, Remote gateway: 40.40.40.1, Local ID: ipv4(10.10.10.0-10.10.10.255), Remote ID: ipv4(20.20.20.0-20.20.20.255), Direction: inbound, SPI: 0x4da68c0b, AUX-SPI: 0, Mode: Tunnel, Type: dynamic, Traffic-selector: ts-1 FC Name: 

 

Jul 12 19:10:50 SRX kmd[10237]: KMD_PM_SA_ESTABLISHED: Local gateway: 30.30.30.1, Remote gateway: 40.40.40.1, Local ID: ipv4(10.10.10.0-10.10.10.255), Remote ID: ipv4(20.20.20.0-20.20.20.255), Direction: outbound, SPI: 0xc98bc09c, AUX-SPI: 0, Mode: Tunnel, Type: dynamic, Traffic-selector: ts-1 FC Name: 

 

Jul 12 19:10:50 SRX kmd[10237]: KMD_VPN_UP_ALARM_USER: VPN Customer_LAN from 40.40.40.1 is up. Local-ip: 30.30.30.1, gateway name: Customer_LAN, vpn name: Customer_LAN, tunnel-id: 67108873, local tunnel-if: st0.0, remote tunnel-ip: Not-Available, Local IKE-ID: 169.48.68.90, Remote IKE-ID: 40.40.40.1, AAA username: Not-Applicable, VR id: 0, Traffic-selector: ts-1, Traffic-selector local ID: ipv4(10.10.10.0-10.10.10.255), Traffic-selector remote ID: ipv4(20.20.20.0-20.20.20.255), SA Type: Static

 

Jul 12 19:10:50 SRX kmd[10237]: KMD_VPN_DOWN_ALARM_USER: VPN Customer_LAN from 40.40.40.1 is down. Local-ip: 30.30.30.1, gateway name: Customer_LAN, vpn name: Customer_LAN, tunnel-id: 67108868, local tunnel-if: st0.0, remote tunnel-ip: Not-Available, Local IKE-ID: 169.48.68.90, Remote IKE-ID: 40.40.40.1, AAA username: Not-Applicable, VR id: 0, Traffic-selector: ts-2, Traffic-selector local ID: ipv4(10.10.10.0-10.10.10.255), Traffic-selector remote ID: ipv4(20.20.20.0-20.20.20.255), SA Type: Static, Reason: IPSec SA delete payload received from peer, corresponding IPSec SAs cleared

Solution

The issue was due to having two identical traffic selectors within the vpn configuration that were conflicting with one another. 

 

Removal of one resolved the issue and the tunnel was observed to be stable with no dropped packets any longer.

Modification History

2023-10-10