# IPSec - Negotiation Failure

**URL:** https://forums.digi.com/t/ipsec-negotiation-failure/22263
**Category:** Digi TransPort WR (Series)
**Tags:** vpn, wr21, ipsec
**Created:** [March 9, 2021, 9:15am UTC](https://forums.digi.com/t/ipsec-negotiation-failure/22263 "2021-03-09T09:15:13Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![backnew](https://avatars.discourse-cdn.com/v4/letter/b/a8b319/32.png) [@backnew](https://forums.digi.com/u/backnew)
#### Post date: [March 9, 2021, 9:15am UTC](https://forums.digi.com/t/ipsec-negotiation-failure/22263/1 "2021-03-09T09:15:13Z")

</div>

Hi all,

I have two WR21 and try to setup a IPSec vpn tunnel.  
The configurations between two WR21 are match to each other and the IPSec tunnel was setting successfully.  
Then, I sent one of the WR21 to other country and insert sim card from the country.  
The log of WR21 from my side shows the dog as following:

16:23:15, 09 Mar 2021,(31) IKE SA Removed. Peer: WR21\_TEST,Negotiation Failure  
16:23:15, 09 Mar 2021,(31) IKE Negotiation Failed. Peer: ,Inactivity  
16:22:46, 09 Mar 2021,(31) IKE Keys Negotiated. Peer: WR21\_TEST  
16:22:45, 09 Mar 2021,(31) New Phase 1 IKE Session 45.115.73.50,Responder  
16:20:05, 09 Mar 2021,(28) IKE SA Removed. Peer: WR21\_TEST,Negotiation Failure  
16:20:05, 09 Mar 2021,(28) IKE Negotiation Failed. Peer: ,Inactivity  
16:19:53, 09 Mar 2021,(27) IKE SA Removed. Peer: WR21\_TEST,Negotiation Failure  
16:19:53, 09 Mar 2021,(27) IKE Negotiation Failed. Peer: ,Inactivity  
16:19:35, 09 Mar 2021,(28) IKE Keys Negotiated. Peer: WR21\_TEST  
16:19:35, 09 Mar 2021,(28) New Phase 1 IKE Session 45.115.73.58,Responder  
16:19:23, 09 Mar 2021,(27) IKE Keys Negotiated. Peer: WR21\_TEST  
16:19:23, 09 Mar 2021,(27) New Phase 1 IKE Session 45.115.73.26,Responder  
16:16:53, 09 Mar 2021,(25) IKE SA Removed. Peer: WR21\_TEST,Negotiation Failure  
16:16:53, 09 Mar 2021,(25) IKE Negotiation Failed. Peer: ,Inactivity  
16:16:23, 09 Mar 2021,(25) IKE Keys Negotiated. Peer: WR21\_TEST  
16:16:23, 09 Mar 2021,(25) New Phase 1 IKE Session 45.115.73.26,Responder  
16:13:43, 09 Mar 2021,(23) IKE SA Removed. Peer: WR21\_TEST,Negotiation Failure  
16:13:43, 09 Mar 2021,(23) IKE Negotiation Failed. Peer: ,Inactivity  
16:13:13, 09 Mar 2021,(23) IKE Keys Negotiated. Peer: WR21\_TEST  
16:13:13, 09 Mar 2021,(23) New Phase 1 IKE Session 45.115.73.52,Responder

There is only New Phase 1 IKE Session but no Phase 2.  
Any idea for this? Thanks.

Best,  
CS

---

<div class="post-metadata">

### Author: ![NicholasYourIoT](https://sea2.discourse-cdn.com/flex016/user_avatar/forums.digi.com/nicholasyouriot/32/27_2.png) [@NicholasYourIoT](https://forums.digi.com/u/NicholasYourIoT)
#### Post date: [March 9, 2021, 8:05pm UTC](https://forums.digi.com/t/ipsec-negotiation-failure/22263/2 "2021-03-09T20:05:07Z")

</div>

You can see from the logs IP addresses that they keep changing:

New Phase 1 IKE Session 45.115.73.52,Responder  
New Phase 1 IKE Session 45.115.73.26,Responder  
New Phase 1 IKE Session 45.115.73.50,Responder

This most likely means that the WR21 does not have a public IP address but is behind a NAT system.

If you have setup an IPsec VPN using IKE v1 and Main mode (default mode) then this will fail. You will need to use aggressive mode to allow IKE v1 to negotiate behind a NATted IP address.

You could also request a public IP from the carrier on the SIM but I highly doubt Telkomcel (in Timor-Liste?) can provide that.

You will need remote hands/SMS control/Digi Remote Manager to change the initiator for aggressive mode.

[https://ftp1.digi.com/support/documentation/AN\_010\_IPSec\_Over\_Cellular\_using\_Digi\_Tport\_Routers.pdf](https://ftp1.digi.com/support/documentation/AN_010_IPSec_Over_Cellular_using_Digi_Tport_Routers.pdf)

Nicholas Wilson  
Your IoT

---

<div class="post-metadata">

### Author: ![backnew](https://avatars.discourse-cdn.com/v4/letter/b/a8b319/32.png) [@backnew](https://forums.digi.com/u/backnew)
#### Post date: [March 10, 2021, 9:32am UTC](https://forums.digi.com/t/ipsec-negotiation-failure/22263/3 "2021-03-10T09:32:42Z")

</div>

Hi Nicholas,

Thanks for your reply.  
I did set the aggressive mode for the initiator before I sent it to Timor-Leste.  
But it didn’t work.  
Any other idea?  
Thanks.

Best regards,  
CS

---

<div class="post-metadata">

### Author: ![NicholasYourIoT](https://sea2.discourse-cdn.com/flex016/user_avatar/forums.digi.com/nicholasyouriot/32/27_2.png) [@NicholasYourIoT](https://forums.digi.com/u/NicholasYourIoT)
#### Post date: [March 16, 2021, 1:27am UTC](https://forums.digi.com/t/ipsec-negotiation-failure/22263/4 "2021-03-16T01:27:34Z")

</div>

Turn on the analyser and monitor the IPsec and IKE ports to see where it is failing.
