IPsec VPN Failure After ER8411 Firmware Upgrade to 1.3.1
Hello,
I manage a large Omada deployment across various networks. My primary network uses an ER8411 gateway, and several remote sites connect to it via IPsec VPN.
Yesterday, I upgraded the ER8411 to firmware version 1.3.1, and since then, the IPsec VPN connection to one of my remote sites — which uses an ER707-M2 v1.0 — has stopped working.
I've confirmed that the VPN settings on both ends remain unchanged from before the upgrade, and I’ve also tried creating a new VPN configuration and testing various setting combinations. Despite this, the VPN tunnel still fails to establish.
The following error appears in the event log on the ER8411:
WAN/LAN4: Phase 1 of IKE negotiation failed. (Peers=xxx.xxx.xxx.xxx<->xxx.xxx.xxx.xxx, Error=NO_PROPOSAL_CHOSEN[14])
On the ER707-M2, a similar error is logged:
2.5G WAN1: Phase 1 of IKE negotiation failed. (Peers=xxx.xxx.xxx.xxx<->xxx.xxx.xxx.xxx, Error=14)
(Note: IP addresses have been obfuscated for privacy.)
This issue only began after upgrading to firmware 1.3.1 on the ER8411. Is there anything else I can try or logs to look at to inform what might be happening? Could this be a regression or compatibility issue introduced in the latest firmware? If so, is it possible to downgrade the ER8411 to the previous firmware version?
Thanks!