VPN3K L2L Netscreen with X.509

Unanswered Question
Apr 27th, 2007
User Badges:

Hi all,

we try to establish a site-to-site vpn with VPN3015 and Netscreen Firewall with

RSA Certificates.The tunnel comes up, if it is initiated by the side of Netscreen,

but it fails when the VPN3K tries to open it.Here is what we see in the Netscreenlog :

IKE<-.-.-.- > Process [ID]:

IKE<-.-.-.- > ID received: type=ID_DER_ASN1_DN, DN = Email=... CN=...,OU=...,O=...,C=..., port = 0, protocol=0

IKE<-.-.-.-> Received incorrect ID payload: ID type mismatch.

IKE<-.-.-.-> ID processed. return 1. sa->p1_state = 2.

IKE<-.-.-.-> Error processing ID

IKE<-.-.-.- > Phase 1: Main mode

negotiations have failed.

The Netscreen is awaiting to get the ID type ID_FQDN,but the VPN3K sends the ID ID_DER_ASN1_DN. We also changed the value of the DN Field in Configuration|Usermanagement|Groups|IPSec,but nothing changed.How will it possible to send the right ID to Netscreen ?

Thanks and regards


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
drolemc Thu, 05/03/2007 - 11:27
User Badges:
  • Silver, 250 points or more

Try using ip address instead of DN and see if it works.


This Discussion