Frequent brief IPsec VPN tunnel interruptions between a VMware NSX Edge and a third-party peer gateway (e.g., Vyatta)
search cancel

Frequent brief IPsec VPN tunnel interruptions between a VMware NSX Edge and a third-party peer gateway (e.g., Vyatta)

book

Article ID: 450514

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • IPsec VPN tunnel status intermittently changes to DOWN.
  • NSX Edge shows following log messages:

NSX 1788239 VPN [nsx@6876 comp="nsx-edge" subcomp="iked" s2comp="nestdb-iked" level="INFO"] Successfully updated IKE session 4843b80b-###-4703-####-65361fb994ef, for rule ID: 197883175, with status: IPSEC_STATUS_DOWN, reason
NSX 1788239 VPN [nsx@6876 comp="nsx-edge" subcomp="iked" s2comp="iked-sync-handler" level="INFO"] Processing IKESA delete message SPI: 0xc4087b082b####_i 0x6ee548d0c06####_r
NSX 1788239 VPN [nsx@6876 comp="nsx-edge" subcomp="iked" s2comp="iked-sync-handler" level="INFO"] Skipping processing for delete, SPI does not match
NSX 1788239 VPN [nsx@6876 comp="nsx-edge" subcomp="iked" s2comp="iked-event" level="INFO"] Request for IKE session status update for session: 1, local_ip: 10.##.##.140, peer_ip: 10.##.##.230 status: IKE_STATUS_DOWN, error: Peer sent delete

  • Outages occur despite the IKE negotiation appearing successful just milliseconds prior.

Environment

VMware NSX

Cause

Peer sent delete indicates that the peer gateway initiated a delete case. A DELETE payload is received for IKE SA. Please refer to following document for information on IPSec alarm types and reasons. Refer to Alarms When an IPsec VPN Session or Tunnel Is Down for alarm definitions.

Resolution

Review configuration parameters on the peer router to verify it matches NSX.
Check peer router logs to understand why it is deleting IKE session.

Additional Information

For further diagnostic steps, refer to Troubleshooting IPsec VPN in VMware NSX.

To speak with a customer representative or a Support Engineer, see contact support.