DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Vigor3900 IPSEC to AWS VPC/VPN/CGW

  • ukandrewtaylor
  • Topic Author
  • User
  • User
More
13 Jun 2018 09:58 #1 by ukandrewtaylor
Vigor3900 IPSEC to AWS VPC/VPN/CGW was created by ukandrewtaylor
Hi All,

We've got two offices, each with a Vigor 3900. Office 1 is connected to our Amazon AWS VPC via a VPN Gateway using IPSEC no problem at all.

Our second office, we're trying to re-create the setup. I have a new setup of everything in AWS and I've configured the VPN on Vigor with the new settings.

I'm failing at phase 1 with

<141>Jun 13 08:53:09 Vigor: pluto[11655]: "aws_s2" #94: deleting state (STATE_MAIN_I1)
<141>Jun 13 08:53:09 Vigor: pluto[11655]: "aws_s2" #94: Deleting state #94 of aws_s2
<141>Jun 13 08:53:09 Vigor: pluto[11655]: "aws_s2": Deleting state #0 of aws_s2
<141>Jun 13 08:53:09 Vigor: pluto[11655]: "aws_s2" #95: initiating Main Mode
<13>Jun 13 08:53:09 Vigor: [IPsec] Re-initiate always on tunnel: aws_s2
<141>Jun 13 08:53:10 Vigor: pluto[11655]: "aws_s2": Don't init aws_s2 PHASE2/CHILD SA because PHASE1/PARENT #95 state STATE_MAIN_I1 is not established}
<14>Jun 13 08:53:10 Vigor: : 002 "aws_s2": Don't init aws_s2 PHASE2/CHILD SA because PHASE1/PARENT #95 state STATE_MAIN_I1 is not established}

As I understand IPSEC the "STATE_MAIN_I1 is not established" is telling me that I'm failing at the first hurdle; any ideas how I can get more information out of the Vigor? I assume my proposal settings aren't really relevant here as I'm not getting to that phase?

Many thanks

Andrew

Please Log in or Create an account to join the conversation.