This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Site-to-Site IPSec UTM-UTM "no suitable connection"

Hi all,

I have a pair of identical UTM devices (small form factor, fairly low power, boxes with quad nics) at two locations.

They are doing the 'right thing'(TM) when it comes to single site networking, one of them also acts as a road warrior VPN endpoint for my devices.

 

I'm struggling to get a site-site IPSec tunnel working though...

I have set both up with the other defined as a remote gateway with a pre-shared key, and I've tried with RSA keys (generated and then copied public keys between the UTM gateways), but I can't establish a connection (so the routing and firewall rules that will be generated are irrelevant at this stage I think).

 

I'm sure I'm doing something really daft, but can't quite work out what it is... There is clearly a connection attempt, both are reporting much the same, which includes replies from each other, but also:

Error message with PSK: "no suitable connection for peer"

Error message with RSA: "no public key known for"

 

My google-fu is turning up pages of older UTM/Astaro documentation/guides and some 'dealing with multilink paths' - but precious little about the simple setup scenario in the current UI (well, one of them is set to run some updates tonight).

 

Is there an idiots guide that I've missed, or do I need to just go digging in the logs to try and get more guidance...



This thread was automatically locked due to age.