Short question: Does anyone have any idea what causes SRX 1400 to only log this with ike debug enabled, not bringing up a VPN tunnel?
[Oct 6 13:22:29 PIC 1/1/0 KMD2][188.8.131.52 <-> 184.108.40.206] Reached max initiated negotiations in progress. Ignoring the request to trigger new negotiation[Oct 6 13:22:33 PIC 1/1/0 KMD2][220.127.116.11 <-> 18.104.22.168] Received IKE Trigger message with local_gw_addr = 22.214.171.124 remote_gw_addr = 126.96.36.199
Looks like I have this problem with one particular routed VPN tunnel with three network pairs, doesn't matter if the tunnel is configured with traffic-selectors or as three different tunnels. Other tunnels on the same device seem to work just fine, even newer ones than this problematic one.
The devices are an SRX 1400 cluster, with some 50-100 active routed tunnels. The configuration maximums shouldn't be even close, as far as I know the limit should be like 5000 tunnels for SRX 1400?
It looks you are hitting know issue PR1085657. More details on below URL
Fix available on versions above 12.1X46-D40 12.1X47-D25 12.3X48-D20 15.1X49-D20
Looks correct. Great, thanks. 🙂