由于公司Netscreen SSG140升级为SSG520,根据以下文章

http://viong.blog.51cto.com/blog/844766/247995

配置SSG140与SSG520对等端×××无报错,配置SSG5与SSG520对等端×××报以下错误:

2012-11-01 21:14:47 info Rejected an IKE packet on ethernet0/3 from 60.12.*.*500 to 111.161. .*.* :500 with cookies 655c4e8fc4c582d6 and bf9899ec79c8db4a because The peer sent a proxy ID that did not match the one in the SA config.

2012-11-01 21:14:47 info IKE 60.12. .*.*  Phase 2: No policy exists for the proxy ID received: local ID (0.0.0.0/255.255.255.255, 0, 0) remote ID (192.168.31.0/255.255.255.0, 0, 0).

2012-11-01 21:14:47 info IKE 60.12. .*.*  Phase 2 msg ID 9f57a3ae: Responded to the peer's first message.

2012-11-01 21:14:43 info IKE 60.12. .*.*  Phase 2 msg ID 9f57a3ae: Negotiations have failed.

 

解决方式:

SSG520端添加以下信息,SSG端无需改变:

 

netscreen SSG520M 与SSG5 配置点对点基于路由策略×××报错_第1张图片

 

 

                                                                                                              viong     2012.11.7