Description

SRX 15000 send syslog messages with inverted "remote tunnel-ip: d.c.b.a whereas it should have been a.b.c.d

Symptoms

In SRX devices running IPsec VPN and the St0 interface is configured with an IP address, then device is showing the remote-tunnel-ip in inverted format.

For example: The actual IP which is configured on the st0 interface on the remote side is a.b.c.d, however device might display this output in reversed format i.e, d.c.b.a in the logs.

 

Jun 7 05:45:21 2023 srx kmd[19184]: KMD_VPN_UP_ALARM_USER: VPN IPSEC-VPN-322 from x.x.x.x is up. Local-ip: y.y.y.y, gateway name: IKE-GW-322, vpn name: IPSEC-VPN-322, tunnel-id: 131077, local tunnel-if: st0.322, remote tunnel-ip: d.c.b.a, Local IKE-ID: y.y.y.y, Remote IKE-ID: x.x.x.x, AAA username: Not-Applicable, VR id: 5, Traffic-selector: , Traffic-selector local ID: ipv4_subnet(any:0,[0..7]=0.0.0.0/0), Traffic-selector remote ID: ipv4_subnet(any:0,[0..7]=0.0.0.0/0), SA Type: Static

Solution

This is a Software issue and is fixed from 22.4 R1 and above codes.

 

Modification History

content published