Troubleshooting Tip: IPSEC VPN down due to Error INVALID_KE_PAYLOAD
| Description | This article describes the solution to solve the Error "INVALID_KE_PAYLOAD" received on the IKE debug. |
| Scope | |
| Solution | - From the IKE debug if you see the error "INVALID_KE_PAYLOAD" as below:
The above error is seen due the mismatch in the PFS setting in Phase2 of the IPSEC VPN.
Solution:
- Verify if the PFS is enabled on both peers. - Verify if the DH-Group is same on both end.
|
