Hello,
I configured a site-to-site VPN peering to a non-Meraki firewall device, with below parameters:
IKEv2
Phase 1 encryption: AES256
Phase 1 authentication: SHA256
Phase 1 Pseudo-random Function: SHA256
Diffie-Hellman group: 14
Lifetime (seconds): 28800
Phase 2 encryption: AES256
Phase 2 Authentication: SHA256
PFS group: 14
Lifetime (seconds): 28800
I also make sure the pre shared key is correctly entered at both ends.
However, the tunnel does not form up. I did packet capturing on the MX250 WAN1 side, which is my primary WAN, and do not see a single packet goes out to the remote peer's IP. I tried to change the parameters, re-configure everything, to trigger the VPN negotiation packets, but do not get a single packet out to the remote peer.
I do have another non-Meraki VPN peer configured on the same MX250 to compare, and I can capture packets destined to that peer..
So my question is why MX250 does not send any packets to the first non-Meraki peer at all? Any thoughts?
Thanks,
Fei.