Description

This article covers the "NO_ADDITIONAL_SAS error message sent to peer as there is already active IPSec SAs" error

Symptoms

SRX sees the tunnel as up while the peer sees it as down.

The error shows in the "messages" log.

From time to time, the tunnel will be established.

If the peer is checked, there are Proxy-ID/Traffic Selector error messages.

Solution

This is seen when there's a Proxy-ID/Traffic Selector mismatch.


Please check that the configuration between the peers matches.

Modification History

2024-04-30 : Article Created