This article documents an issue observed on vSRX devices where OSPF adjacency fails when IPsec VPN (IKEv2) is configured using AES-GCM encryption along with the extended-sequence-number option.
extended-sequence-number
Trigger:
This issue is observed when all of the following conditions are met:
aes-128-gcm
aes-192-gcm
aes-256-gcm
Root Cause:
When PMI is enabled on vSRX, IPsec traffic with AES-GCM encryption is expected to be processed in hardware (PMI mode). However:
Workaround:
To mitigate the issue:
This issue is resolved in the following Junos OS versions:
For more details, refer to the Problem Report: