<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic MULTIPLE CRYPTO AUTHENTICATION ERROR in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/multiple-crypto-authentication-error/m-p/532602#M5735</link>
    <description>&lt;P&gt;I have two crypto map, one dynamic for my vpn clients and another for vpn site-to-site. The thing is that the vpn site-to-site works perfect until I put authentication for the dynamic vpn. After that, my vpn clients authenticate perfect but my vpn site-to-site won´t pass phase 2. The logs says "ISAKMP Phase 2 retransmission". If I remove the authentication line, in a couple of minutes vpn site-to-site is up again. Any ideas to solve this? Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problematic line&lt;/P&gt;&lt;P&gt;crypto map mymap client authentication ias (radius server)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the configuration of crypto map&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set myset esp-3des esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto dynamic-map dynmap 100 set transform-set myset&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set set_london esp-3des esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto map mymap 20 ipsec-isakmp&lt;/P&gt;&lt;P&gt;crypto map mymap 20 match address acl_aeiou&lt;/P&gt;&lt;P&gt;crypto map mymap 20 set pfs group2&lt;/P&gt;&lt;P&gt;crypto map mymap 20 set peer 11.22.33.44&lt;/P&gt;&lt;P&gt;crypto map mymap 20 set transform-set set_london&lt;/P&gt;&lt;P&gt;crypto map mymap 100 ipsec-isakmp dynamic dynmap&lt;/P&gt;&lt;P&gt;crypto map mymap interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;isakmp key netscreen address aa.bb.cc.dd netmask 255.255.aa.bb &lt;/P&gt;&lt;P&gt;isakmp identity address&lt;/P&gt;&lt;P&gt;isakmp policy 20 authentication pre-share&lt;/P&gt;&lt;P&gt;isakmp policy 20 encryption 3des&lt;/P&gt;&lt;P&gt;isakmp policy 20 hash sha&lt;/P&gt;&lt;P&gt;isakmp policy 20 group 2&lt;/P&gt;&lt;P&gt;isakmp policy 20 lifetime 28800&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:15:50 GMT</pubDate>
    <dc:creator>edimonte1980</dc:creator>
    <dc:date>2020-02-21T18:15:50Z</dc:date>
    <item>
      <title>MULTIPLE CRYPTO AUTHENTICATION ERROR</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-crypto-authentication-error/m-p/532602#M5735</link>
      <description>&lt;P&gt;I have two crypto map, one dynamic for my vpn clients and another for vpn site-to-site. The thing is that the vpn site-to-site works perfect until I put authentication for the dynamic vpn. After that, my vpn clients authenticate perfect but my vpn site-to-site won´t pass phase 2. The logs says "ISAKMP Phase 2 retransmission". If I remove the authentication line, in a couple of minutes vpn site-to-site is up again. Any ideas to solve this? Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problematic line&lt;/P&gt;&lt;P&gt;crypto map mymap client authentication ias (radius server)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the configuration of crypto map&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set myset esp-3des esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto dynamic-map dynmap 100 set transform-set myset&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set set_london esp-3des esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto map mymap 20 ipsec-isakmp&lt;/P&gt;&lt;P&gt;crypto map mymap 20 match address acl_aeiou&lt;/P&gt;&lt;P&gt;crypto map mymap 20 set pfs group2&lt;/P&gt;&lt;P&gt;crypto map mymap 20 set peer 11.22.33.44&lt;/P&gt;&lt;P&gt;crypto map mymap 20 set transform-set set_london&lt;/P&gt;&lt;P&gt;crypto map mymap 100 ipsec-isakmp dynamic dynmap&lt;/P&gt;&lt;P&gt;crypto map mymap interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;isakmp key netscreen address aa.bb.cc.dd netmask 255.255.aa.bb &lt;/P&gt;&lt;P&gt;isakmp identity address&lt;/P&gt;&lt;P&gt;isakmp policy 20 authentication pre-share&lt;/P&gt;&lt;P&gt;isakmp policy 20 encryption 3des&lt;/P&gt;&lt;P&gt;isakmp policy 20 hash sha&lt;/P&gt;&lt;P&gt;isakmp policy 20 group 2&lt;/P&gt;&lt;P&gt;isakmp policy 20 lifetime 28800&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:15:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-crypto-authentication-error/m-p/532602#M5735</guid>
      <dc:creator>edimonte1980</dc:creator>
      <dc:date>2020-02-21T18:15:50Z</dc:date>
    </item>
    <item>
      <title>Re: MULTIPLE CRYPTO AUTHENTICATION ERROR</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-crypto-authentication-error/m-p/532603#M5739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please find fully working configuration from my lab, hope this helps also as reference check the following document:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00800b6099.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00800b6099.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list nonat permit ip &lt;INSIDE_LAN_IP&gt; 255.255.255.0 &lt;REMOTE_LAN_IP&gt; 255.255.255.0&lt;/REMOTE_LAN_IP&gt;&lt;/INSIDE_LAN_IP&gt;&lt;/P&gt;&lt;P&gt;access-list nonat permit ip &lt;INSIDE_LAN_IP&gt; 255.255.255.0 &lt;VPN-RAS-POOL-IP&gt; 255.255.255.240&lt;/VPN-RAS-POOL-IP&gt;&lt;/INSIDE_LAN_IP&gt;&lt;/P&gt;&lt;P&gt;access-list 700 permit ip &lt;INSIDE_LAN_IP&gt; 255.255.255.0 &lt;REMOTE_LAN_IP&gt; 255.255.255.0&lt;/REMOTE_LAN_IP&gt;&lt;/INSIDE_LAN_IP&gt;&lt;/P&gt;&lt;P&gt;access-list 300 permit ip &lt;INSIDE_LAN_IP&gt; 255.255.255.0 &lt;VPN-RAS-POOL-IP&gt; 255.255.255.240&lt;/VPN-RAS-POOL-IP&gt;&lt;/INSIDE_LAN_IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip local pool vpn-ras-pool 172.x.x.1-172.x.x.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list nonat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server partnerauth (inside) host &lt;LAN_RADIUS_SERVER_IP&gt; &lt;RADIUS_KEY&gt; timeout 5&lt;/RADIUS_KEY&gt;&lt;/LAN_RADIUS_SERVER_IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sysopt connection permit-ipsec&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set LAB1 esp-3des esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto dynamic-map dynmap 100 set transform-set LAB1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto map labmap 1 ipsec-isakmp&lt;/P&gt;&lt;P&gt;crypto map labmap 1 match address 700&lt;/P&gt;&lt;P&gt;crypto map labmap 1 set peer &lt;PEER ip="" address=""&gt;&lt;/PEER&gt;&lt;/P&gt;&lt;P&gt;crypto map labmap 1 set transform-set LAB1&lt;/P&gt;&lt;P&gt;crypto map labmap 65535 ipsec-isakmp dynamic dynmap&lt;/P&gt;&lt;P&gt;crypto map labmap client authentication partnerauth&lt;/P&gt;&lt;P&gt;crypto map labmap interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;isakmp enable outside&lt;/P&gt;&lt;P&gt;isakmp key secretkey address &lt;PEER ip="" address=""&gt; netmask 255.255.255.255&lt;/PEER&gt;&lt;/P&gt;&lt;P&gt;isakmp identity address&lt;/P&gt;&lt;P&gt;isakmp nat-traversal &lt;/P&gt;&lt;P&gt;isakmp policy 1 authentication pre-share&lt;/P&gt;&lt;P&gt;isakmp policy 1 encryption 3des&lt;/P&gt;&lt;P&gt;isakmp policy 1 hash md5&lt;/P&gt;&lt;P&gt;isakmp policy 1 group 2&lt;/P&gt;&lt;P&gt;isakmp policy 1 lifetime 86400&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vpngroup labrasvpn address-pool vpn-ras-pool&lt;/P&gt;&lt;P&gt;vpngroup labrasvpn dns-server &lt;DNS1&gt; &lt;DNS2&gt;&lt;/DNS2&gt;&lt;/DNS1&gt;&lt;/P&gt;&lt;P&gt;vpngroup labrasvpn wins-server &lt;WINS_SERVER_IP&gt;&lt;/WINS_SERVER_IP&gt;&lt;/P&gt;&lt;P&gt;vpngroup labrasvpn default-domain &lt;DOMAIN_NAME&gt;&lt;/DOMAIN_NAME&gt;&lt;/P&gt;&lt;P&gt;vpngroup labrasvpn split-tunnel 300&lt;/P&gt;&lt;P&gt;vpngroup labrasvpn idle-time 1800&lt;/P&gt;&lt;P&gt;vpngroup labrasvpn password &lt;PASSWORD&gt;&lt;/PASSWORD&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate post if it helps you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jay&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 May 2006 09:17:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-crypto-authentication-error/m-p/532603#M5739</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2006-05-24T09:17:24Z</dc:date>
    </item>
    <item>
      <title>Re: MULTIPLE CRYPTO AUTHENTICATION ERROR</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-crypto-authentication-error/m-p/532604#M5742</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just wonder if you need to disable extended authentication &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;isakmp key netscreen address aa.bb.cc.dd netmask 255.255.aa.bb no-xauth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 May 2006 09:28:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-crypto-authentication-error/m-p/532604#M5742</guid>
      <dc:creator>attrgautam</dc:creator>
      <dc:date>2006-05-24T09:28:29Z</dc:date>
    </item>
  </channel>
</rss>

