"ike authentication credentials are unacceptable"
We switched firewall from M470 to M590 with Backup file , after migaration SSL VPN working fine but IKE2 not working as expect .
Comments
-
You probably used the Firebox default self-signed certificate in the IKEv2 configuration on the M470.
You need to download the new self-signed root certificate from the new M590 device and import this certificate to all IKEv2 client machines “Trusted Root Certification Authorities” store.
Easiest way is to download the IKEv2 client profile *.tgz file from the new M590 device and from this file copy the rootca certificate to all the IKEv2 client machines manually or AD GPO….
1 -
It's working as expect , thanks for information .
0 -
@Sandbox Games, kimmo.pohjoisaho hit the nail on the head regarding the most common cause of this error after a hardware migration. When you restore a backup image onto a new box (M470 to M590), the Firebox generates a new local self-signed Root CA certificate for IKEv2 authentication. Since your client machines are still holding onto the old Root CA from the M470, Windows/macOS will reject the handshake with "ike authentication credentials are unacceptable".
If updating/re-deploying the new Root CA certificate via GPO doesn't completely resolve it for all users, here are a couple of other practical things to double-check based on past migrations:
- Re-generate and Re-download the .tgz Mobile VPN Profile
Go to VPN > Mobile VPN > IKEv2 on the M590, save the settings (even without changing anything), and download the new Client Profile (.tgz).
Run the updated install.bat on a test machine to automatically import the new Root CA and update the connection profile settings.
- Shared Secret / Preshared Key (PSK) Mismatch
Sometimes during a cross-model backup restore, the encrypted Pre-Shared Key under Phase 1 settings doesn't decrypt properly or gets corrupted if the Firebox system keys differ.
Re-enter the Shared Secret manually on the M590 and save the configuration to force the system to write it fresh.
- RADIUS / Active Directory Secret (If using NPS/Authpoint)
If your IKEv2 setup uses RADIUS authentication instead of local Firebox users, make sure the new M590 IP address is updated in your RADIUS Server / NPS Clients list. If the RADIUS secret or client IP doesn't match, the authentication phase will fail with a generic credential error.
Try re-deploying the certificate first, as that solves ~90% of these post-migration IKEv2 issues. Let us know how it goes!ưu giữa các game thủ trở nên dễ dàng hơn bao giờ hết.
0
