This article provides a list of error messages related to the Netskope service and IPSec tunnel configuration, environment, or protocol and explains how to resolve them.
To view the IPSec tunnel status and error messages, go to Settings > Security Cloud Platform > IPSec Site and hover over
under Tunnel Status.

NS_ALERT_PEER_PSK_MISMATCH

This error occurs when there is a pre-shared key (PSK) mismatch on the peer side. To fix it, check if PSK configured on the peer side matches the one configured in the Netskope UI.
NS_ALERT_PROPOSAL_MISMATCH_CHILD

This error occurs when the ESP proposals configured for the tunnel on the peer side don’t match the ones configured in the Netskope UI. To update the ESP proposals:
- Check the ESP proposals you configured for your router/firewall:

- Check the ESP proposals configured for Encryption Cipher in the Netskope UI. To learn more: Creating an IPSec Site.

- If they don’t match, update them so they do. For your router/firewall, you can enter the following command to change the proposals:

NS_ALERT_DPD_FAILURE

This error occurs when the Netskope IPSec daemon can’t reach the peer-side IPSec daemon because of one of these reasons:
- There are DPD failures caused by network reachability issues.
- The IPSec daemon on the peer-side device is hung and not responding.
- The IPSec daemon on the peer-side device crashed and isn’t responding.
NS_ALERT_INSTALL_CHILD_SA_FAILED

This error occurs when the CHILD SA installation fails in the Netskope POP. Refresh in one minute. If the issue persists, contact Netskope Support for additional debugging.
NS_ALERT_UNKNOWN_IDENTITY

This error occurs when the IPSec tunnel is down due to generic reasons. To fix it:
- Check if the Source Identity of the tunnels match. To learn more: Creating an IPSec Site.
- Check if the IKE Phase 1 proposals of the tunnels match.

NS_ALERT_CHILD_SA_COUNT_EXCEEDED

This error is specific to the Netskope infrastructure and occurs when Netskope restricts the CHILD SA count to no more than 10. There isn’t an actual error and Netskope isn’t bringing the IPSec tunnel down but just showing the IPSec tunnel as temporarily down. Refresh in one minute to see if the issue persists.
NS_ALERT_TENANT_TUNNEL_RESTRICTED

This error occurs when your IPSec tunnel is not in service for this Netskope POP because your tenant might be under maintenance. If the issue persists, contact Netskope Support.
NS_ALERT_POP_UNDER_MAINTENANCE

This error occurs when the Netskope POP is not in service because it might be under maintenance. To check the Netskope POP status, see the Netskope Trust Portal. If the issue persists, contact Netskope Support for additional debugging.
NS_ALERT_DOWNSTREAM_SERVICES_HC_FAILURE

This error occurs when there is a failure in the health check from the tunnel gateway towards downstream services (e.g., proxy, Cloud Firewall, etc.).
NS_ALERT_TUNNEL_DOWN_INACTIVE

This error occurs when there are no events received for the IPSec tunnel in the last 60 minutes. If the issue persists, contact Netskope Support.
NS_ALERT_GENERIC_TUNNEL_DOWN

This error occurs when the IPSec tunnel is brought down by the peer gateway device (e.g., router or firewall) or because of re-authentication.
NS_ALERT_REAUTH_ON_TUNNEL

This error occurs when the IPSec tunnel goes down because reauthentication is initiated from Netskope IPSec gateway side.
NS_ALERT_IKE_DELETE_FROM_CLIENT

This error occurs when the IPSec tunnel goes down because of the IKE_DELETE request from the peer gateway device (e.g., router or firewall), or it went down due to re-authentication initiated from the peer gateway device.
NS_ALERT_DUPLICATE_TUNNEL_DETECTED

This error occurs when the IPSec tunnel goes down because of a duplicate IKE_SA, where you’ve initiated an IKE_SA for the same connection. Netskope brings down one of the IKE_SA with this tunnel reason.
NS_ALERT_AUTH_FAILED
This error occurs when the IPSec tunnel goes down because of the authentication failure from Netskope IPSec gateway side. Usually, this happens due to an incorrect tunnel configuration. Verify the configuration from Netskope gateway (e.g., PSK configuration, etc.).
NS_ALERT_KEEP_ON_CHILD_SA_FAILURE
This error occurs from strongSwan when the IPSec tunnel creation fails because the CHILD_SA creation continues to fail.
NS_ALERT_INVALID_PKT
This error occurs from strongSwan when strongSwan fails to process the IKE message. This might be due to the malformed payload formats or invalid payload lengths.

