HASH N(AUTH_FAILED) when trying to establish an IPsec tunnel to Cloud Secure Web Gateway
search cancel

HASH N(AUTH_FAILED) when trying to establish an IPsec tunnel to Cloud Secure Web Gateway

book

Article ID: 217343

calendar_today

Updated On:

Products

Cloud Secure Web Gateway - Cloud SWG

Issue/Introduction

Unable to establish a Firewall/VPN IPsec tunnel to the Cloud Secure Web Gateway, the firewall IPSEC log showed an error.

Environment

  • Any Firewall Vendor
  • Cloud Secure Web Gateway

Cause

The firewall IPsec verbose logs showed the following error:

[ENC] parsed INFORMATIONAL_V1 request <Request ID>[ HASH N(AUTH_FAILED) ]
[IKE] received AUTHENTICATION_FAILED error notify

The error message indicates Phase 1 Identifier Mismatch.

Resolution

Review the firewall's VPN IPsec phase 1 configuration profile, and set the local ID to the given public egress IP.

The IP should be the same as added in the Cloud SWG portal under Connectivity > Location > Access Method Firewall VPN.