<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ikev2 Tunnel status &amp;quot; Ready &amp;quot; in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998954#M1108102</link>
    <description>&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;#sh monitor event-trace crypto ikev2 error latest&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;*Jan 17 23:38:29.355: SA ID:120 SESSION ID:4080 Remote: X.X.X.132/500 Local: X.X.X.219/500 Negotiation aborted due to ERROR: Create child exchange failed&lt;/P&gt;&lt;P&gt;*Jan 17 23:38:36.896: SA ID:273 SESSION ID:4084 Remote: X.X.X.132/500 Local: X.X.X.219/500 Negotiation aborted due to ERROR: Create child exchange failed&lt;/P&gt;&lt;P&gt;*Jan 17 23:38:40.300: SA ID:316 SESSION ID:4087 Remote: X.X.X.132/500 Local: X.X.X.219/500 Negotiation aborted due to ERROR: Create child exchange failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jan 2024 22:50:12 GMT</pubDate>
    <dc:creator>Yahya</dc:creator>
    <dc:date>2024-01-17T22:50:12Z</dc:date>
    <item>
      <title>Ikev2 Tunnel status " Ready "</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998862#M1108083</link>
      <description>&lt;P&gt;Dear Experts!&lt;/P&gt;&lt;P&gt;I am beginner with vpn configs. I am trying to make tunnel up and ive done all configuration required from my side. After all, it showing many tunnels with status "ready".&amp;nbsp; I dont know what is the issue!&amp;nbsp;&lt;/P&gt;&lt;P&gt;My device is cisco ISR4321/K9 ,, peer side is none cisco device.&lt;/P&gt;&lt;P&gt;below resulte of # sh cry ikev2 sa&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screenshot 2024-01-17 233417.png" style="width: 966px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/207689iFDB4051962504692/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-01-17 233417.png" alt="Screenshot 2024-01-17 233417.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 20:41:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998862#M1108083</guid>
      <dc:creator>Yahya</dc:creator>
      <dc:date>2024-01-17T20:41:44Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Tunnel status " Ready "</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998864#M1108085</link>
      <description>&lt;P&gt;Is this route based vpn?&lt;/P&gt;
&lt;P&gt;Can you share crypto session details&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;
&lt;P&gt;Show&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 20:49:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998864#M1108085</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-17T20:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Tunnel status " Ready "</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998874#M1108086</link>
      <description>&lt;P&gt;&lt;SPAN&gt;1- Is this route based vpn?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;DID not get your question.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2-&amp;nbsp;Can you share crypto session details?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;Sure&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 20:59:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998874#M1108086</guid>
      <dc:creator>Yahya</dc:creator>
      <dc:date>2024-01-17T20:59:10Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Tunnel status " Ready "</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998877#M1108087</link>
      <description>&lt;P&gt;dont see anything wrong except the lifetime one side use 300 other use more longest&amp;nbsp;&lt;BR /&gt;can you match it&amp;nbsp;&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 21:07:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998877#M1108087</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-17T21:07:16Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Tunnel status " Ready "</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998883#M1108088</link>
      <description>&lt;P&gt;I have changed it many times, but still same status!&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 21:16:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998883#M1108088</guid>
      <dc:creator>Yahya</dc:creator>
      <dc:date>2024-01-17T21:16:10Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Tunnel status " Ready "</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998896#M1108090</link>
      <description>&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;deb crypto ikev2 internal&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;deb crypto ikev2 packet&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*Jan 17 22:33:03.406: IKEv2-INTERNAL:(SESSION ID = 922,SA ID = 221):Process NAT discovery notify&lt;BR /&gt;*Jan 17 22:33:03.406: IKEv2-INTERNAL:(SESSION ID = 922,SA ID = 221):No NAT found&lt;BR /&gt;*Jan 17 22:33:03.406: IKEv2-INTERNAL:(SESSION ID = 922,SA ID = 221):SM Trace-&amp;gt; SA: I_SPI=C3D15E494526DB9C R_SPI=22096482C48E801B (R) MsgID = 0 CurState: R_INIT Event: EV_CHK_CONFIG_MODE&lt;BR /&gt;*Jan 17 22:33:03.406: IKEv2-INTERNAL:(SESSION ID = 922,SA ID = 221):SM Trace-&amp;gt; SA: I_SPI=C3D15E494526DB9C R_SPI=22096482C48E801B (R) MsgID = 0 CurState: R_BLD_INIT Event: EV_SET_POLICY&lt;BR /&gt;*Jan 17 22:33:03.406: IKEv2-INTERNAL:(SESSION ID = 922,SA ID = 221):Setting configured policies&lt;BR /&gt;*Jan 17 22:33:03.406: IKEv2-INTERNAL:(SESSION ID = 922,SA ID = 221):SM Trace-&amp;gt; SA: I_SPI=C3D15E494526DB9C R_SPI=22096482C48E801B (R) MsgID = 0 CurState: R_BLD_INIT Event: EV_CHK_AUTH4PKI&lt;BR /&gt;*Jan 17 22:33:03.406: IKEv2-INTERNAL:(SESSION ID = 922,SA ID = 221):SM Trace-&amp;gt; SA: I_SPI=C3D15E494526DB9C R_SPI=22096482C48E801B (R) MsgID = 0 CurState: R_BLD_INIT Event: EV_PKI_SESH_OPEN&lt;BR /&gt;*Jan 17 22:33:03.407: IKEv2-INTERNAL:(SESSION ID = 922,SA ID = 221):Opening a PKI session&lt;BR /&gt;*Jan 17 22:33:03.407: IKEv2-INTERNAL:(SESSION ID = 922,SA ID = 221):SM Trace-&amp;gt; SA: I_SPI=C3D15E494526DB9C R_SPI=22096482C48E801B (R) MsgID = 0 CurState: R_BLD_INIT Event: EV_GEN_DH_KEY&lt;BR /&gt;*Jan 17 22:33:03.407: IKEv2-INTERNAL:(SESSION ID = 922,SA ID = 221):SM Trace-&amp;gt; SA: I_SPI=C3D15E494526DB9C R_SPI=22096482C48E801B (R) MsgID = 0 CurState: R_BLD_INIT Event: EV_NO_EVENT&lt;BR /&gt;*Jan 17 22:33:03.407: IKEv2-INTERNAL:(SESSION ID = 922,SA ID = 221):SM Trace-&amp;gt; SA: I_SPI=C3D15E494526DB9C R_SPI=22096482C48E801B (R) MsgID = 0 CurState: R_BLD_INIT Event: EV_OK_RECD_DH_PUBKEY_RESP&lt;BR /&gt;*Jan 17 22:33:03.407: IKEv2-INTERNAL:(SESSION ID = 922,SA ID = 221):Action: Action_Null&lt;BR /&gt;*Jan 17 22:33:03.407: IKEv2-INTERNAL:(SESSION ID = 922,SA ID = 221):SM Trace-&amp;gt; SA: I_SPI=C3D15E494526DB9C R_SPI=22096482C48E801B (R) MsgID = 0 CurState: R_BLD_INIT Event: EV_GEN_DH_SECRET&lt;BR /&gt;*Jan 17 22:33:03.484: IKEv2-INTERNAL:(SESSION ID = 922,SA ID = 221):SM Trace-&amp;gt; SA: I_SPI=C3D15E494526DB9C R_SPI=22096482C48E801B (R) MsgID = 0 CurState: R_BLD_INIT Event: EV_NO_EVENT&lt;BR /&gt;*Jan 17 22:33:03.485: IKEv2-INTERNAL:(SESSION ID = 648,SA ID = 217):SM Trace-&amp;gt; SA: I_SPI=6CE6E3808F2D75AD R_SPI=4E54FC53C25AEFEF (I) MsgID = 1 CurState: INFO_I_WAIT Event: EV_RE_XMT&lt;BR /&gt;*Jan 17 22:33:03.485: IKEv2-INTERNAL:(SESSION ID = 648,SA ID = 217):SM Trace-&amp;gt; SA: I_SPI=6CE6E3808F2D75AD R_SPI=4E54FC53C25AEFEF (I) MsgID = 1 CurState: INFO_I_WAIT Event: unknown event&lt;BR /&gt;*Jan 17 22:33:03.485: IKEv2-PAK:(SESSION ID = 648,SA ID = 217):Next payload: ENCR, version: 2.0 Exchange type: INFORMATIONAL, flags: RESPONDER Message id: 1, length: 72&lt;BR /&gt;Payload contents:&lt;BR /&gt;ENCR Next payload: DELETE, reserved: 0x0, length: 44&lt;/P&gt;&lt;P&gt;*Jan 17 22:33:03.486: IKEv2-INTERNAL:(SESSION ID = 648,SA ID = 217):SM Trace-&amp;gt; SA: I_SPI=6CE6E3808F2D75AD R_SPI=4E54FC53C25AEFEF (I) MsgID = 1 CurState: INFO_I_WAIT Event: EV_NO_EVENT&lt;BR /&gt;*Jan 17 22:33:03.486: IKEv2-INTERNAL:(SESSION ID = 922,SA ID = 221):SM Trace-&amp;gt; SA: I_SPI=C3D15E494526DB9C R_SPI=22096482C48E801B (R) MsgID = 0 CurState: R_BLD_INIT Event: EV_OK_RECD_DH_SECRET_RESP&lt;BR /&gt;*Jan 17 22:33:03.486: IKEv2-INTERNAL:(SESSION ID = 922,SA ID = 221):Action: Action_Null&lt;BR /&gt;*Jan 17 22:33:03.486: IKEv2-INTERNAL:(SESSION ID = 922,SA ID = 221):SM Trace-&amp;gt; SA: I_SPI=C3D15E494526DB9C R_SPI=22096482C48E801B (R) MsgID = 0 CurState: R_BLD_INIT Event: EV_GEN_SKEYID&lt;BR /&gt;*Jan 17 22:33:03.486: IKEv2-INTERNAL:(SESSION ID = 922,SA ID = 221):Generate skeyid&lt;BR /&gt;*Jan 17 22:33:03.486: IKEv2-INTERNAL:(SESSION ID = 922,SA ID = 221):SM Trace-&amp;gt; SA: I_SPI=C3D15E494526DB9C R_SPI=22096482C48E801B (R) MsgID = 0 CurState: R_BLD_INIT Event: EV_GET_CONFIG_MODE&lt;BR /&gt;*Jan 17 22:33:03.487: IKEv2-INTERNAL:(SESSION ID = 922,SA ID = 221):No config data to send to toolkit:&lt;BR /&gt;*Jan 17 22:33:03.487: IKEv2-INTERNAL:(SESSION ID = 922,SA ID = 221):SM Trace-&amp;gt; SA: I_SPI=C3D15E494526DB9C R_SPI=22096482C48E801B (R) MsgID = 0 CurState: R_BLD_INIT Event: EV_BLD_MSG&lt;BR /&gt;*Jan 17 22:33:03.487: IKEv2-INTERNAL:Construct Vendor Specific Payload: DELETE-REASON&lt;BR /&gt;*Jan 17 22:33:03.487: IKEv2-INTERNAL:Construct Vendor Specific Payload: CISCOVPN-REV-02&lt;BR /&gt;*Jan 17 22:33:03.487: IKEv2-INTERNAL:Sending DRU Handshake&lt;BR /&gt;*Jan 17 22:33:03.487: IKEv2-INTERNAL:(221): Sending custom vendor id : CISCO-DYNAMIC-ROUTE&lt;BR /&gt;*Jan 17 22:33:03.487: IKEv2-INTERNAL:Construct Vendor Specific Payload: (CUSTOM)&lt;BR /&gt;*Jan 17 22:33:03.487: IKEv2-IN&lt;BR /&gt;Gtel_test#TERNAL:Construct Vendor Specific Payload: (CUSTOM)&lt;BR /&gt;*Jan 17 22:33:03.968: IKEv2-PAK:(SESSION ID = 572,SA ID = 182):Next payload: ENCR, version: 2.0 Exchange type: INFORMATIONAL, flags: RESPONDER Message id: 1, length: 72&lt;BR /&gt;Payload contents:&lt;BR /&gt;ENCR Next payload: DELETE, reserved: 0x0, length: 44&lt;/P&gt;&lt;P&gt;*Jan 17 22:33:03.968: IKEv2-INTERNAL:(SESSION ID = 572,SA ID = 182):SM Trace-&amp;gt; SA: I_SPI=9FAAF7B9595D4F3E R_SPI=E0AFC2801BC02625 (I) MsgID = 1 CurState: INFO_I_WAIT Event: EV_NO_EVENT&lt;BR /&gt;*Jan 17 22:33:04.016: IKEv2-INTERNAL:(SESSION ID = 689,SA ID = 184):SM Trace-&amp;gt; SA: I_SPI=5A88EADE3E38EA79 R_SPI=4D6C7C5BC46F6C8D (I) MsgID = 1 CurState: READY Event: EV_CHK_IKE_REKEY&lt;BR /&gt;*Jan 17 22:33:04.016: IKEv2-INTERNAL:(SESSION ID = 689,SA ID = 184):SM Trace-&amp;gt; SA: I_SPI=5A88EADE3E38EA79 R_SPI=4D6C7C5BC46F6C8D (I) MsgID = 1 CurState: READY Event: EV_REKEY_IKESA&lt;BR /&gt;*Jan 17 22:33:04.016: IKEv2-INTERNAL:(SESSION ID = 689,SA ID = 184):Action: Action_Null&lt;BR /&gt;*Jan 17 22:33:04.016: IKEv2-INTERNAL:(SESSION ID = 689,SA ID = 184):SM Trace-&amp;gt; SA: I_SPI=5A88EADE3E38EA79 R_SPI=4D6C7C5BC46F6C8D (I) MsgID = 1 CurState: CHILD_I_INIT Event: EV_REKEY_IKESA&lt;BR /&gt;*Jan 17 22:33:04.017: IKEv2-INTERNAL:(SESSION ID = 689,SA ID = 184):SM Trace-&amp;gt; SA: I_SPI=5A88EADE3E38EA79 R_SPI=4D6C7C5BC46F6C8D (I) MsgID = 1 CurState: CHILD_I_IKE Event: EV_REKEY_IKESA&lt;BR /&gt;*Jan 17 22:33:04.017: IKEv2-INTERNAL:(SESSION ID = 689,SA ID = 232): Child SA: I_SPI=3707C011A2A2117C R_SPI=0000000000000000&lt;BR /&gt;*Jan 17 22:33:04.017: IKEv2-INTERNAL:(SESSION ID = 689,SA ID = 184):SM Trace-&amp;gt; SA: I_SPI=5A88EADE3E38EA79 R_SPI=4D6C7C5BC46F6C8D (I) MsgID = 1 CurState: CHILD_I_IKE Event: EV_GET_IKE_POLICY&lt;BR /&gt;*Jan 17 22:33:04.017: IKEv2-INTERNAL:(SESSION ID = 689,SA ID = 232): Child SA: I_SPI=3707C011A2A2117C R_SPI=0000000000000000&lt;BR /&gt;*Jan 17 22:33:04.017: IKEv2-INTERNAL:Adding Proposal PROP2 to toolkit policy&lt;BR /&gt;*Jan 17 22:33:04.017: IKEv2-INTERNAL:(SA ID = 184):Using IKEv2 profile 'IKEv2PROF2'&lt;BR /&gt;*Jan 17 22:33:04.017: IKEv2-INTERNAL:(SESSION ID = 689,SA ID = 184):SM Trace-&amp;gt; SA: I_SPI=5A88EADE3E38EA79 R_SPI=4D6C7C5BC46F6C8D (I) MsgID = 1 CurState: CHILD_I_IKE Event: EV_SET_POLICY&lt;BR /&gt;*Jan 17 22:33:04.018: IKEv2-INTERNAL:(SESSION ID = 689,SA ID = 232): Child SA: I_SPI=3707C011A2A2117C R_SPI=0000000000000000&lt;BR /&gt;*Jan 17 22:33:04.018: IKEv2-INTERNAL:(SESSION ID = 689,SA ID = 184):Setting configured policies&lt;BR /&gt;*Jan 17 22:33:04.018: IKEv2-INTERNAL:(SESSION ID = 689,SA ID = 184):SM Trace-&amp;gt; SA: I_SPI=5A88EADE3E38EA79 R_SPI=4D6C7C5BC46F6C8D (I) MsgID = 1 CurState: CHILD_I_IKE Event: EV_GEN_DH_KEY&lt;BR /&gt;*Jan 17 22:33:04.018: IKEv2-INTERNAL:(SESSION ID = 689,SA ID = 232): Child SA: I_SPI=3707C011A2A2117C R_SPI=0000000000000000&lt;BR /&gt;*Jan 17 22:33:04.018: IKEv2-INTERNAL:(SESSION ID = 689,SA ID = 184):SM Trace-&amp;gt; SA: I_SPI=5A88EADE3E38EA79 R_SPI=4D6C7C5BC46F6C8D (I) MsgID = 1 CurState: CHILD_I_IKE Event: EV_NO_EVENT&lt;BR /&gt;*Jan 17 22:33:04.018: IKEv2-INTERNAL:(SESSION ID = 689,SA ID = 232): Child SA: I_SPI=3707C011A2A2117C R_SPI=0000000000000000&lt;BR /&gt;*Jan 17 22:33:04.018: IKEv2-INTERNAL:(SESSION ID = 689,SA ID = 184):SM Trace-&amp;gt; SA: I_SPI=5A88EADE3E38EA79 R_SPI=4D6C7C5BC46F6C8D (I) MsgID = 1 CurState: CHILD_I_IKE Event: EV_OK_RECD_DH_PUBKEY_RESP&lt;BR /&gt;*Jan 17 22:33:04.019: IKEv2-INTERNAL:(SESSION ID = 689,SA ID = 232): Child SA: I_SPI=3707C011A2A2117C R_SPI=0000000000000000&lt;BR /&gt;*Jan 17 22:33:04.019: IKEv2-INTERNAL:(SESSION ID = 689,SA ID = 184):Action: Action_Null&lt;BR /&gt;*Jan 17 22:33:04.019: IKEv2-INTERNAL:(SESSION ID = 689,SA ID = 184):SM Trace-&amp;gt; SA: I_SPI=5A88EADE3E38EA79 R_SPI=4D6C7C5BC46F6C8D (I) MsgID = 1 CurState: CHILD_I_IKE Event: EV_BLD_MSG&lt;BR /&gt;*Jan 17 22:33:04.019: IKEv2-INTERNAL:(SESSION ID = 689,SA ID = 232): Child SA: I_SPI=3707C011A2A2117C R_SPI=0000000000000000&lt;BR /&gt;*Jan 17 22:33:04.019: IKEv2-INTERNAL:Construct Notify Payload: SET_WINDOW_SIZE&lt;BR /&gt;Payload contents:&lt;BR /&gt;SA Next payload: N, reserved: 0x0, length: 52&lt;BR /&gt;last proposal: 0x0, reserved: 0x0, length: 48&lt;BR /&gt;Proposal: 1, Protocol id: IKE, SPI size: 8, #trans: 4 last transform: 0x3, reserved: 0x0: length: 8&lt;BR /&gt;type: 1, reserved: 0x0, id: 3DES&lt;BR /&gt;last transform: 0x3, reserved: 0x0: length: 8&lt;BR /&gt;type: 2, reserved: 0x0, id: SHA256&lt;BR /&gt;last transform: 0x3, reserved: 0x0: length: 8&lt;BR /&gt;type: 3, reserved: 0x0, id: SHA256&lt;BR /&gt;last transform: 0x0, reserved: 0x0: length: 8&lt;BR /&gt;type: 4, reserved: 0x0, id: DH_GROUP_521_ECP/Group 21&lt;BR /&gt;N Next payload: KE, reserved: 0x0, length: 36&lt;BR /&gt;KE Next payload: NOTIFY, reserved: 0x0, length: 140&lt;BR /&gt;DH group: 21, Reserved: 0x0&lt;BR /&gt;NOTIFY(SET_WINDOW_SIZE) Next payload: NONE, reserved: 0x0, length: 12&lt;BR /&gt;Security protocol id: Unknown - 0, spi size: 0, type: SET_WINDOW_SIZE&lt;/P&gt;&lt;P&gt;*Jan 17 22:33:04.020: IKEv2-PAK:(SESSION ID = 689,SA ID = 184):Next payload: ENCR, version: 2.0 Exchange type: CREATE_CHILD_SA, flags: RESPONDER Message id: 0, length: 304&lt;BR /&gt;Payload contents:&lt;BR /&gt;ENCR Next payload: SA, reserved: 0x0, length: 276&lt;/P&gt;&lt;P&gt;*Jan 17 22:33:04.021: IKEv2-INTERNAL:(SESSION ID = 689,SA ID = 184):SM Trace-&amp;gt; SA: I_SPI=5A88EADE3E38EA79 R_SPI=4D6C7C5BC46F6C8D (I) MsgID = 0 CurState: CHILD_I_IKE Event: EV_INSERT_SA&lt;BR /&gt;*Jan 17 22:33:04.021: IKEv2-INTERNAL:(SESSION ID = 689,SA ID = 232): Child SA: I_SPI=3707C011A2A2117C R_SPI=0000000000000000&lt;BR /&gt;*Jan 17 22:33:04.021: IKEv2-INTERNAL:(SESSION ID = 689,SA ID = 184):SM Trace-&amp;gt; SA: I_SPI=5A88EADE3E38EA79 R_SPI=4D6C7C5BC46F6C8D (I) MsgID = 0 CurState: CHILD_I_WAIT Event: EV_NO_EVENT&lt;BR /&gt;*Jan 17 22:33:04.021: IKEv2-INTERNAL:(SESSION ID = 689,SA ID = 232): Child SA: I_SPI=3707C011A2A2117C R_SPI=0000000000000000&lt;BR /&gt;Gtel_test#und&lt;BR /&gt;Gtel_test#undebug a&lt;BR /&gt;Gtel_test#undebug all&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 21:41:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998896#M1108090</guid>
      <dc:creator>Yahya</dc:creator>
      <dc:date>2024-01-17T21:41:06Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Tunnel status " Ready "</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998912#M1108096</link>
      <description>&lt;PRE id="GUID-A01CCEB5-BB30-49BD-A3CD-76E0094856B4__GUID-92EE1A00-90E7-407B-B03D-14E6376D8347" class="pre codeblock"&gt;&lt;CODE&gt;device# debug ikev2 error
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;can you share this&amp;nbsp;&lt;BR /&gt;thanks&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 22:06:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998912#M1108096</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-17T22:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Tunnel status " Ready "</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998932#M1108099</link>
      <description>&lt;P&gt;&lt;BR /&gt;*Jan 17 23:14:14.712: IKEv2-ERROR:(SESSION ID = 2947,SA ID = 32):: Maximum number of retransmissions reached&lt;BR /&gt;*Jan 17 23:14:20.394: IKEv2-ERROR:(SESSION ID = 2952,SA ID = 37):: Maximum number of retransmissions reached&lt;BR /&gt;&lt;BR /&gt;*Jan 17 23:14:25.845: IKEv2-ERROR:(SESSION ID = 2953,SA ID = 38):: Maximum number of retransmissions reached&lt;BR /&gt;&lt;BR /&gt;*Jan 17 23:14:28.455: IKEv2-ERROR:(SESSION ID = 2958,SA ID = 44):: Maximum number of retransmissions reached&lt;BR /&gt;&lt;BR /&gt;*Jan 17 23:14:32.425: IKEv2-ERROR:(SESSION ID = 2964,SA ID = 50):: Maximum number of retransmissions reached&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 22:21:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998932#M1108099</guid>
      <dc:creator>Yahya</dc:creator>
      <dc:date>2024-01-17T22:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Tunnel status " Ready "</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998935#M1108101</link>
      <description>&lt;P&gt;&lt;A href="https://community.cisco.com/t5/vpn/crypto-ikev2-stuck-in-neg-state-maximum-number-of/td-p/4697594" target="_blank"&gt;https://community.cisco.com/t5/vpn/crypto-ikev2-stuck-in-neg-state-maximum-number-of/td-p/4697594&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;check this&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 22:25:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998935#M1108101</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-17T22:25:49Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Tunnel status " Ready "</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998954#M1108102</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;#sh monitor event-trace crypto ikev2 error latest&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;*Jan 17 23:38:29.355: SA ID:120 SESSION ID:4080 Remote: X.X.X.132/500 Local: X.X.X.219/500 Negotiation aborted due to ERROR: Create child exchange failed&lt;/P&gt;&lt;P&gt;*Jan 17 23:38:36.896: SA ID:273 SESSION ID:4084 Remote: X.X.X.132/500 Local: X.X.X.219/500 Negotiation aborted due to ERROR: Create child exchange failed&lt;/P&gt;&lt;P&gt;*Jan 17 23:38:40.300: SA ID:316 SESSION ID:4087 Remote: X.X.X.132/500 Local: X.X.X.219/500 Negotiation aborted due to ERROR: Create child exchange failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 22:50:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998954#M1108102</guid>
      <dc:creator>Yahya</dc:creator>
      <dc:date>2024-01-17T22:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Tunnel status " Ready "</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998963#M1108103</link>
      <description>&lt;P&gt;so we solve this first error message ?&lt;BR /&gt;if Yes&amp;nbsp;&lt;BR /&gt;can you share the phaseII config and transform set,&amp;nbsp; I think there is mismatch NOW&amp;nbsp;&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 22:58:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998963#M1108103</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-17T22:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Tunnel status " Ready "</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998970#M1108105</link>
      <description>&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;#sh run | sec crypto&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set XXX esp-3des esp-sha256-hmac&lt;BR /&gt;mode tunnel&lt;/P&gt;&lt;P&gt;# interested traffic #&lt;/P&gt;&lt;P&gt;1312 permit ip host X.X.X.219 host { peer server ip ] &amp;gt; behind X.X.1.132&lt;BR /&gt;1313 permit ip host X.X.X.219 host { peer server ip ] &amp;gt;&amp;nbsp;behind X.X.1.132&lt;/P&gt;&lt;P&gt;no crypto ipsec nat-transparency udp-encapsulation&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;crypto map CMAP 20 ipsec-isakmp&lt;BR /&gt;set peer X.X.1.132&lt;BR /&gt;set transform-set XXX&lt;BR /&gt;set pfs group21&lt;BR /&gt;set ikev2-profile IKEv2PROF2&lt;/P&gt;&lt;P&gt;interface g0/0/1&lt;BR /&gt;match address 102&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 23:09:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998970#M1108105</guid>
      <dc:creator>Yahya</dc:creator>
      <dc:date>2024-01-17T23:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Tunnel status " Ready "</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998980#M1108106</link>
      <description>&lt;P&gt;&lt;SPAN&gt;set pfs group21 &amp;lt;&amp;lt;- mustly PFS is issue here, can you change the group&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1312 permit ip host X.X.X.219 host { &lt;FONT color="#00FF00"&gt;&lt;STRONG&gt;peer server ip&lt;/STRONG&gt; &lt;/FONT&gt;] &amp;gt; behind X.X.1.132&lt;BR /&gt;1313 permit ip host X.X.X.219 host { &lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;peer server ip&lt;/FONT&gt;&lt;/STRONG&gt; ] &amp;gt;&amp;nbsp;behind X.X.1.132&lt;BR /&gt;I will assume that peer server IP is different&amp;nbsp;&lt;BR /&gt;MHM&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 23:30:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998980#M1108106</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-17T23:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Tunnel status " Ready "</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998983#M1108107</link>
      <description>&lt;P&gt;lets say we need my server in my company to reach at the two servers inside ISP company for some reason. However, peer ip is the gateway and I can ping it, but server ips are inside company that they are behind the peer X.X.1.132&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 23:36:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4998983#M1108107</guid>
      <dc:creator>Yahya</dc:creator>
      <dc:date>2024-01-17T23:36:25Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Tunnel status " Ready "</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4999137#M1108109</link>
      <description>&lt;P&gt;Sorry I dont get your last reply&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you more elaborate&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 06:03:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4999137#M1108109</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-18T06:03:44Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Tunnel status " Ready "</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4999160#M1108110</link>
      <description>&lt;P&gt;Hi MHM,&lt;/P&gt;&lt;P&gt;Please see diagram for more details.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 06:28:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/4999160#M1108110</guid>
      <dc:creator>Yahya</dc:creator>
      <dc:date>2024-01-18T06:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Tunnel status " Ready "</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/5000086#M1108155</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-01-18 092644.png" style="width: 696px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/207821iA335A06F0BF8E852/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-01-18 092644.png" alt="Screenshot 2024-01-18 092644.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 18:17:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/5000086#M1108155</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-18T18:17:26Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Tunnel status " Ready "</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/5000106#M1108157</link>
      <description>&lt;P&gt;I changed acl by using remote access to router, but lost connectivity immediatley .&lt;/P&gt;&lt;P&gt;I will check through console soon.&lt;/P&gt;&lt;P&gt;Thank you..&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 18:48:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/5000106#M1108157</guid>
      <dc:creator>Yahya</dc:creator>
      <dc:date>2024-01-18T18:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Tunnel status " Ready "</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/5001120#M1108206</link>
      <description>&lt;P&gt;Hi MHM!&lt;/P&gt;&lt;H5&gt;thank you for your kind support, I would say we still in same issue not solved yet. But let me share you configuration of my side to be clear.&lt;/H5&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;## Phase1 ##&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;crypto ikev2 proposal Q50&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;encryption 3des&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;integrity sha256&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;group 21&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;***&lt;/P&gt;&lt;P&gt;crypto ikev2 policy P50&lt;BR /&gt;proposal &lt;FONT size="3"&gt;Q50&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;crypto ikev2 keyring Keyring&lt;/P&gt;&lt;P&gt;peer ISP&lt;/P&gt;&lt;P&gt;&amp;nbsp; address &lt;STRONG&gt;X.X.1.132&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; pre-shared-key local XXXXXX&lt;/P&gt;&lt;P&gt;&amp;nbsp; pre-shared-key remote XXXXXX&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;***&lt;/P&gt;&lt;P&gt;crypto ikev2 profile IKEv2PROFILE&lt;/P&gt;&lt;P&gt;match identity remote address &lt;STRONG&gt;X.X.1.132&lt;/STRONG&gt; 255.255.255.255&lt;/P&gt;&lt;P&gt;authentication remote pre-share&lt;/P&gt;&lt;P&gt;authentication local pre-share&lt;/P&gt;&lt;P&gt;keyring local Keyring&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ***&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;## Phase 2 ##&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set SETSET esp-3des esp-sha256-hmac&lt;/P&gt;&lt;P&gt;mode tunnel&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;***&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;## Interesting Traffic ##&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;ip access-list extended 102&lt;BR /&gt;1 permit ip host X.X.150.2 host X.X.129.59&lt;BR /&gt;2 permit ip host X.X.150.2 host X.X.129.200&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;***&lt;/P&gt;&lt;P&gt;no crypto ipsec nat-transparency udp-encapsulation&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;***&amp;nbsp;&lt;/P&gt;&lt;P&gt;crypto map CCCC ipsec-isakmp&lt;BR /&gt;set peer X.X.1.132&lt;BR /&gt;set transform-set SETSET&lt;BR /&gt;set pfs group21&lt;BR /&gt;set ikev2-profile IKEv2PROFILE&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; ***&lt;/P&gt;&lt;P&gt;interface gx/x/x&amp;nbsp;&lt;/P&gt;&lt;P&gt;match address 102&lt;BR /&gt;crypto map CCCC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 15:19:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/5001120#M1108206</guid>
      <dc:creator>Yahya</dc:creator>
      <dc:date>2024-01-19T15:19:38Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 Tunnel status " Ready "</title>
      <link>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/5001175#M1108213</link>
      <description>&lt;P&gt;&lt;SPAN&gt;match address 102 &amp;lt;&amp;lt;- this must be under the crypto map not under the interface&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 16:16:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ikev2-tunnel-status-quot-ready-quot/m-p/5001175#M1108213</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-19T16:16:02Z</dc:date>
    </item>
  </channel>
</rss>

