Support Support Downloads Knowledge Base Juniper Support Portal Community

Knowledge Base

Search our Knowledge Base sites to find answers to your questions.

Ask All Knowledge Base Sites All Knowledge Base Sites JunosE Defect (KA)Knowledge BaseSecurity AdvisoriesTechnical BulletinsTechnotes Sign in to display secure content and recently viewed articles

Troubleshooting a LAN to LAN VPN Using Preshared Secrets



Article ID: KB6340 KB Last Updated: 28 Jun 2010Version: 6.0

Troubleshooting a LAN to LAN VPN Using Preshared Secrets


Symptoms & Errors:

  • Cannot pass VPN traffic from NetScreen gateway to a NetScreen gateway

Note: This article applies to ScreenOS 4.0 and higher.

To troubleshoot a LAN to LAN VPN using preshared secrets, perform the following steps:

Open the Command Line Interface. For more information on accessing the Command Line Interface (CLI), go to Accessing the Command Line Interface Using Telnet.

From the CLI, enter the following command, and then copy the result into a text file.

get tech-support [Enter]

Note: This output file can be used when you contact technical support.

At this point, we recommend determining how IKE negotiations are taking place by running some debug commands within the CLI.

From the CLI, enter the following command:

debug ike detail [Enter]

From the remote side of the LAN to LAN VPN, initiate traffic through the VPN tunnel.

After approximately ten seconds, disable debugging by entering the following command:

undebug ike detail [Enter]

To view the contents of the debug, enter the following command:

get dbuf stream [Enter]

Note:  If the IKE negotiations are succeeding, but traffic is still not passing through the tunnels, on your NetScreen device verify the following information:

  • Any VPN policies should be at the top of the Policy list
  • The VPN route information is correct

note: For assistance with deciphering the debug data, or further help in troubleshooting, Contact Juniper Networks Technical Assistance Center (JTAC).

Comment on this article > Affected Products Browse the Knowledge Base for more articles related to these product categories. Select a category to begin.

Getting Up and Running with Junos

Getting Up and Running with Junos Security Alerts and Vulnerabilities Product Alerts and Software Release Notices Problem Report (PR) Search Tool EOL Notices and Bulletins JTAC User Guide Customer Care User Guide Pathfinder SRX High Availability Configurator SRX VPN Configurator Training Courses and Videos End User Licence Agreement Global Search