Incorrect IPsec VPN status report - Balance One


#1

I have a Balance One (FW 7.0.0) connected to a Balance 20 (FW 6.3.3) via an aggressive IPsec VPN.

As I write this the Balance One shows the connections as “connecting” and the B20 shows the connection as “established”.

The connection is up - pings from the Balance One LAN devices succeed (as does logging into the B20 management web page from a Balance One LAN device).

The log entries from the B20:
Mar 06 21:12:00 IPsec: claremont2yttri/1x1 - Connected
Mar 06 21:11:59 IPsec: claremont2yttri/1x1 - Initiating Aggressive Mode connection…
Mar 06 21:11:59 IPsec: claremont2yttri/1x1 - Disconnected

And the Balance One:
Mar 06 21:12:10 IPsec: claremont2yttri/1x1 - Disconnected
Mar 06 21:12:00 IPsec: claremont2yttri/1x1 - Connected
Mar 06 21:11:59 IPsec: claremont2yttri/1x1 - Disconnected
Mar 06 21:11:59 IPsec: claremont2yttri/1x1 - Initiating Aggressive Mode connection to 89.11.191.75

I am mystified. (But happy that the connection is up.)


#2

Make sure you don’t have any conflicting routes between the two sites. Only one can use the NAT address space 192.168.1.0/24, etc. route conflicts can yield weirdness.