<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Phase 2 Mismatch Error in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/phase-2-mismatch-error/m-p/4583542#M1088840</link>
    <description>&lt;P&gt;post the real Log message - we are aware of this ASA log 106023 with an explanation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tell what ASA device model, what code running here ? what is other side of the device :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;there is also given recommendation - have you taken any action :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG class="ph b"&gt;Recommended Action&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;If messages persist from the same source address, footprinting or port scanning attempt might be occurring. Contact the remote host administrator.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 01 Apr 2022 04:23:05 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2022-04-01T04:23:05Z</dc:date>
    <item>
      <title>Phase 2 Mismatch Error</title>
      <link>https://community.cisco.com/t5/network-security/phase-2-mismatch-error/m-p/4583265#M1088834</link>
      <description>&lt;P&gt;Getting this error on a production site to site VPN&amp;nbsp; when it comes with a Phase 2 mismatch (see attached config):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN class=""&gt;%ASA-4-106023: Deny protocol src 
[&lt;EM&gt;interface_name&lt;/EM&gt;:&lt;EM&gt;source_address&lt;/EM&gt;/&lt;EM&gt;source_port&lt;/EM&gt;] [([&lt;EM&gt;idfw_user&lt;/EM&gt;|&lt;EM&gt;FQDN_string&lt;/EM&gt;], &lt;EM&gt;sg_info&lt;/EM&gt;)] 
dst &lt;EM&gt;interface_name&lt;/EM&gt;:&lt;EM&gt;dest_address&lt;/EM&gt;/&lt;EM&gt;dest_port&lt;/EM&gt; [([&lt;EM&gt;idfw_user&lt;/EM&gt;|&lt;EM&gt;FQDN_string&lt;/EM&gt;], &lt;EM&gt;sg_info&lt;/EM&gt;)] 
[type {&lt;EM&gt;string&lt;/EM&gt;}, code {&lt;EM&gt;code&lt;/EM&gt;}] by &lt;EM&gt;access_group acl_ID&lt;/EM&gt; [0x8ed66b60, 0xf8852875]&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P class=""&gt;A real IP packet was denied by the ACL. This message appears even if you do not have the &lt;STRONG&gt;log&lt;/STRONG&gt; option enabled for an ACL. The IP address is the real IP address instead of the values that display through NAT. Both user identity information and FQDN information is provided for the IP addresses if a matched one is found. The ASA logs either identity information (domain\user) or FQDN (if the username is not available). If the identity information or FQDN is available, the ASA logs this information for both the source and destination.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 18:10:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/phase-2-mismatch-error/m-p/4583265#M1088834</guid>
      <dc:creator>chris.bias</dc:creator>
      <dc:date>2022-03-31T18:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: Phase 2 Mismatch Error</title>
      <link>https://community.cisco.com/t5/network-security/phase-2-mismatch-error/m-p/4583542#M1088840</link>
      <description>&lt;P&gt;post the real Log message - we are aware of this ASA log 106023 with an explanation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tell what ASA device model, what code running here ? what is other side of the device :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;there is also given recommendation - have you taken any action :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG class="ph b"&gt;Recommended Action&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;If messages persist from the same source address, footprinting or port scanning attempt might be occurring. Contact the remote host administrator.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 04:23:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/phase-2-mismatch-error/m-p/4583542#M1088840</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-04-01T04:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: Phase 2 Mismatch Error</title>
      <link>https://community.cisco.com/t5/network-security/phase-2-mismatch-error/m-p/4583889#M1088857</link>
      <description>&lt;P&gt;Please see the log that is attached. The IP address in question is 69.167.161.53 so you have to do a search on the word document. The device is an ASA 5506 PowerSeries.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 14:13:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/phase-2-mismatch-error/m-p/4583889#M1088857</guid>
      <dc:creator>chris.bias</dc:creator>
      <dc:date>2022-04-01T14:13:38Z</dc:date>
    </item>
    <item>
      <title>Re: Phase 2 Mismatch Error</title>
      <link>https://community.cisco.com/t5/network-security/phase-2-mismatch-error/m-p/4587274#M1088988</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp; were you able to look at the config and prior message.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 13:15:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/phase-2-mismatch-error/m-p/4587274#M1088988</guid>
      <dc:creator>chris.bias</dc:creator>
      <dc:date>2022-04-06T13:15:20Z</dc:date>
    </item>
    <item>
      <title>Re: Phase 2 Mismatch Error</title>
      <link>https://community.cisco.com/t5/network-security/phase-2-mismatch-error/m-p/4587504#M1089001</link>
      <description>&lt;P&gt;Is this a question about the VPN not being established or the ACL deny log?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The VPN is not being established because there is a mismatch in the crypto ACL (most likely).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 17:45:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/phase-2-mismatch-error/m-p/4587504#M1089001</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-04-06T17:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: Phase 2 Mismatch Error</title>
      <link>https://community.cisco.com/t5/network-security/phase-2-mismatch-error/m-p/4587522#M1089004</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;&amp;nbsp; Correct the VPN lost it's connection during phase 2 as phase 1 connects. Would me configuring a RAVPN have anything to do with this? I was told it wouldn't as all other site to site VPNs are working.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 18:10:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/phase-2-mismatch-error/m-p/4587522#M1089004</guid>
      <dc:creator>chris.bias</dc:creator>
      <dc:date>2022-04-06T18:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: Phase 2 Mismatch Error</title>
      <link>https://community.cisco.com/t5/network-security/phase-2-mismatch-error/m-p/4590266#M1089110</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;and &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;&amp;nbsp; any thoughts on this?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 15:30:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/phase-2-mismatch-error/m-p/4590266#M1089110</guid>
      <dc:creator>chris.bias</dc:creator>
      <dc:date>2022-04-11T15:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: Phase 2 Mismatch Error</title>
      <link>https://community.cisco.com/t5/network-security/phase-2-mismatch-error/m-p/4590722#M1089129</link>
      <description>&lt;P&gt;No RAVPN and S2S VPN can co-exist on the same device and configuring one does not affect the other (unless you have inadvertently changed the S2S VPN configuration during RAVPN configuration).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As I mentioned in my last post, check that your crypto domain (crypto ACL) is correct on both sides of the VPN tunnel.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 07:17:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/phase-2-mismatch-error/m-p/4590722#M1089129</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-04-12T07:17:24Z</dc:date>
    </item>
    <item>
      <title>Re: Phase 2 Mismatch Error</title>
      <link>https://community.cisco.com/t5/network-security/phase-2-mismatch-error/m-p/4591141#M1089170</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;and &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt; even if I used a different port for the RAVPN?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 18:24:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/phase-2-mismatch-error/m-p/4591141#M1089170</guid>
      <dc:creator>chris.bias</dc:creator>
      <dc:date>2022-04-12T18:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: Phase 2 Mismatch Error</title>
      <link>https://community.cisco.com/t5/network-security/phase-2-mismatch-error/m-p/4591168#M1089173</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As already pointed out there is no matching entry in the crypto map and that is why it is not coming up.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check your crypto map acl.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 18:58:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/phase-2-mismatch-error/m-p/4591168#M1089173</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2022-04-12T18:58:28Z</dc:date>
    </item>
    <item>
      <title>Re: Phase 2 Mismatch Error</title>
      <link>https://community.cisco.com/t5/network-security/phase-2-mismatch-error/m-p/4594679#M1089308</link>
      <description>&lt;P&gt;Issue was on the vendor's side issue was corrected.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 17:23:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/phase-2-mismatch-error/m-p/4594679#M1089308</guid>
      <dc:creator>chris.bias</dc:creator>
      <dc:date>2022-04-18T17:23:42Z</dc:date>
    </item>
  </channel>
</rss>

