DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Lan to Lan - IKE link timeout: state linking IKEV1
- jamiedean83
- Topic Author
- Offline
- New Member
Less
More
- Posts: 2
- Thank you received: 0
02 Oct 2023 10:08 #102890
by jamiedean83
Lan to Lan - IKE link timeout: state linking IKEV1 was created by jamiedean83
Hi all,
First off, thanks for reading!
HQ: Vigor 3300
Remote site: Vigor 2862
I have a client with multiple sites (13 sites), each site has a LAN-to-LAN VPN's to an older Vigor 3300 at HQ. All other sites but one works fine and has done for years, recently one branch was refurbished and the builders damaged the phone line which was replaced by BT OpenReach. After refurbishment all equipment has gone back in (all original) the LAN to LAN VPN which is IKE1 will not connect. The SysLog doesn't seem to indicate much. The ISP are being unhelpful - a speed test reveals poor down/up .4Mbps D and .25Mbps up
I've tried changing the Phase 1 mode to aggressive but still nothing. I had a backup of a working config which i've also restored but same issue, doesn't connect.
Just trying to work out if there is anything i'm missing or if the log's are showing me something I'm just not understanding!
2023-10-02 09:41:29 [IPSEC][L2L][1:HQQGoring][@xx.xx.xxx.x] IKE link timeout: state linking
2023-10-02 09:41:26 [IPSEC/IKE][L2L][1:HQQGoring][@xx.xx.xxx.x] state transition fail: STATE_AGGR_I1
2023-10-02 09:41:26 NAT-Traversal: Using RFC 3947, no NAT detected
2023-10-02 09:41:26 Accept Phase1 proposals : ENCR OAKLEY_DES_CBC, HASH OAKLEY_MD5
2023-10-02 09:41:26 IKE <==, Next Payload=ISAKMP_NEXT_SA, Exchange Type = 0x4, Message ID = 0x0
2023-10-02 09:41:16 [IPSEC/IKE][L2L][1:HQQGoring][@xx.xx.xxx.x] state transition fail: STATE_AGGR_I1
2023-10-02 09:41:16 NAT-Traversal: Using RFC 3947, no NAT detected
2023-10-02 09:41:16 Accept Phase1 proposals : ENCR OAKLEY_DES_CBC, HASH OAKLEY_MD5
2023-10-02 09:41:16 IKE <==, Next Payload=ISAKMP_NEXT_SA, Exchange Type = 0x4, Message ID = 0x0
2023-10-02 09:41:16 IKE ==>, Next Payload=ISAKMP_NEXT_SA, Exchange Type = 0x4, Message ID = 0x0
2023-10-02 09:41:16 Initiating IKE Aggressive Mode to xx.xx.xxx.x
2023-10-02 09:41:16 Dialing Node1 (HQQGoring) : xx.xx.xxx.x
First off, thanks for reading!
HQ: Vigor 3300
Remote site: Vigor 2862
I have a client with multiple sites (13 sites), each site has a LAN-to-LAN VPN's to an older Vigor 3300 at HQ. All other sites but one works fine and has done for years, recently one branch was refurbished and the builders damaged the phone line which was replaced by BT OpenReach. After refurbishment all equipment has gone back in (all original) the LAN to LAN VPN which is IKE1 will not connect. The SysLog doesn't seem to indicate much. The ISP are being unhelpful - a speed test reveals poor down/up .4Mbps D and .25Mbps up
I've tried changing the Phase 1 mode to aggressive but still nothing. I had a backup of a working config which i've also restored but same issue, doesn't connect.
Just trying to work out if there is anything i'm missing or if the log's are showing me something I'm just not understanding!
2023-10-02 09:41:29 [IPSEC][L2L][1:HQQGoring][@xx.xx.xxx.x] IKE link timeout: state linking
2023-10-02 09:41:26 [IPSEC/IKE][L2L][1:HQQGoring][@xx.xx.xxx.x] state transition fail: STATE_AGGR_I1
2023-10-02 09:41:26 NAT-Traversal: Using RFC 3947, no NAT detected
2023-10-02 09:41:26 Accept Phase1 proposals : ENCR OAKLEY_DES_CBC, HASH OAKLEY_MD5
2023-10-02 09:41:26 IKE <==, Next Payload=ISAKMP_NEXT_SA, Exchange Type = 0x4, Message ID = 0x0
2023-10-02 09:41:16 [IPSEC/IKE][L2L][1:HQQGoring][@xx.xx.xxx.x] state transition fail: STATE_AGGR_I1
2023-10-02 09:41:16 NAT-Traversal: Using RFC 3947, no NAT detected
2023-10-02 09:41:16 Accept Phase1 proposals : ENCR OAKLEY_DES_CBC, HASH OAKLEY_MD5
2023-10-02 09:41:16 IKE <==, Next Payload=ISAKMP_NEXT_SA, Exchange Type = 0x4, Message ID = 0x0
2023-10-02 09:41:16 IKE ==>, Next Payload=ISAKMP_NEXT_SA, Exchange Type = 0x4, Message ID = 0x0
2023-10-02 09:41:16 Initiating IKE Aggressive Mode to xx.xx.xxx.x
2023-10-02 09:41:16 Dialing Node1 (HQQGoring) : xx.xx.xxx.x
Please Log in or Create an account to join the conversation.
- jamiedean83
- Topic Author
- Offline
- New Member
Less
More
- Posts: 2
- Thank you received: 0
02 Oct 2023 17:29 #102893
by jamiedean83
Replied by jamiedean83 on topic Re: Lan to Lan - IKE link timeout: state linking IKEV1
Just to add - ISP have fixed an issue by the looks causing slow up and down speeds and no sooner they've done that the VPN connected within a few minutes of the service being online. Is there a minimum up/down for the VPN to work?
Please Log in or Create an account to join the conversation.
Moderators: Sami
Copyright © 2024 DrayTek