Sunday, February 16, 2020

Invalid cert when forming IPSEC?

Hi, I'm currently setting up IPsec with pki authentication and I'm having below logs. when setting up a local pki server should it match the fqdn and other parameters to other CA server? Thanks

Diagram & Config:

https://imgur.com/l3oOeaO

Remote Device Logs:

Feb 16 20:05:35.677: %CRYPTO-5-IKMP_INVAL_CERT: Certificate received from 136.18.100.1 is bad: unknown error returned in certificate validation Feb 16 20:05:58.142: %CRYPTO-5-IKMP_INVAL_CERT: Certificate received from 136.18.100.1 is bad: unknown error returned in certificate validation Feb 16 20:05:59.645: %CRYPTO-5-IKMP_INVAL_CERT: Certificate received from 136.18.100.1 is bad: unknown error returned in certificate validation Feb 16 20:06:01.148: %CRYPTO-5-IKMP_INVAL_CERT: Certificate received from 136.18.100.1 is bad: unknown error returned in certificate validation 


No comments:

Post a Comment