XR60 IPsec Cisco ASA DH Error

I am trying to setup an IPsec VPN tunnel between a XR60 and Cisco ASA. I have this same setup working between AirLink MP70 routers and the same ASA. I am able to establish the VPN connection, but not all networks will connect. When I enable “Multiple SA’s for IKEv2” the VPN will connect and shows connected on router (with a single Child network) and the ASA shows the VPN is connected. The router VPN Tunnel has the Status “Partially Connected. Some Child SA’s failed”. The Cisco ASA log has an error “IKEv2 Negotiation aborted due to ERROR: The peer’s KE payload contained the wrong DH group” for the networks that fail to connect. The DH is set to dh14 on the router and ASA.

The XR60 has these entries in the log:
Jan 12 19:08:33 info charon: 09[IKE] peer didn’t accept DH group MODP_2048, it requested KE_NONE
Jan 12 19:08:33 info charon: 16[CFG] received proposals: ESP:AES_CBC_128/HMAC_SHA2_256_128/NO_EXT_SEQ
Jan 12 19:08:33 info charon: 16[CFG] configured proposals: ESP:AES_CBC_128/HMAC_SHA2_256_128/MODP_2048/NO_EXT_SEQ
Jan 12 19:08:33 info charon: 16[IKE] no acceptable proposal found
Jan 12 19:08:33 info charon: 16[IKE] failed to establish CHILD_SA, keeping IKE_SA

Hi @it15,

Welcome to our community!
Could you please answer the questions below to narrow down the issue?

  1. Could you share with me how you set up an IPsec VPN tunnel between XR60 and Cisco ASA? Please refer to the configuration of VPN on XR60 at the following link: Configuring VPN - XR60-5.3 - Sierra Wireless
  2. Could you please share the full log from XR60 with me so I can check further?

Thanks,

We have MP70 routers using the same VPN setup. This XR60 replaced a MP70 that was working with the same site to site IPsec VPN tunnel. I used the MP70 VPN config as a reference as much as possible.

I attached the log retrieved from the router via AirVantage and a PDF with screenshots of the VPN status and setup.

Thanks,

(attachments)

log_da2743f29f904fd99ee89e8cf8365b76_2026-01-14.txt (1.98 MB)
XR60 VPN Setup.pdf (145 KB)

Hi @it15,

Based on your description, I understand that setting up an IPsec VPN tunnel between MP70 and the Cisco ASA is working well. Could you please share the template log and full log of MP70 with me?

Thanks,