Enabling two sites with the same local ID/IP and peer as "any" to respond with different ikeVersion
search cancel

Enabling two sites with the same local ID/IP and peer as "any" to respond with different ikeVersion

book

Article ID: 321252

calendar_today

Updated On:

Products

VMware NSX Data Center for vSphere

Issue/Introduction

Symptoms:
Two sites with same peer and local ID/IP cannot be configured with two different ikeVersion.

Environment

VMware NSX Data Center for vSphere 6.4.x

Cause

This issue occurs because currently, two sites with same peer and local ID/IP cannot be with two different ikeVersion.
But when the local site is a responder and the peer is configured as any, local site should be able to respond with different ikeVersion as per the intiator's ikeVersion.

Resolution

This is a known issue affecting VMware NSX Data Center for vSphere 6.4.2.

Currently, there is no resolution.

Workaround:
To work around this issue:
  1. Configure the sites with same local ID/IP and peer as "any" using "ike-flex".
  2. When the peer initiates the communication using ikeV1, then the site will respond with ikeV1 and if the peer initiates the communication using ikeV2, then the site will respond with ikeV2.