hi.

one problem: we have 2 netware 6.5 sp1a servers with bm3.8 sp1a. one is
configured as s2s-master, the other as s2s-slave.if we start vpn at both
servers, no vpn-tunnel is created.
At the Audit Log i can see the following messages on both servers in circles:

"IKE SA NEGOTIATION - Peer lifetime is: 28800 My lifetime is: 28800"
"First IKE connection sending INITIAL_CONTACT notify to <ip-address>"
"PFS NOT ENABLED - DELETING ALL IPSEC SA"
"Notify Received:Deleting IKE SA and related QM SAS - Peer <ip-address>"

On the IKE-Message Screen i can see the message "Failed to create IKE-SA -
ACL Check failed"

any tips or ideas ?

Some important information: the ds of the two servers is not in sync
because i installed / configured the s2s-slave in our network (and in our
tree) and it was delivered to our remote office. but i can connect over
remote control to configure it.

thnx for any help.
erik
(sorry for my bad english)