<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec VPN Issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ipsec-vpn-issue/m-p/1896193#M458845</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It was phase2 problem and after changing the transformset it worked fine &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 28 Feb 2012 13:31:08 GMT</pubDate>
    <dc:creator>Haris P</dc:creator>
    <dc:date>2012-02-28T13:31:08Z</dc:date>
    <item>
      <title>IPSec VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-issue/m-p/1896187#M458832</link>
      <description>&lt;P&gt;Dears ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm just configuring an IPsec siste to site VPN . I have many sites in the same router and all is working except one &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For all IPSec tunnel my ISAKMP encription , hash are as given in policy 1 . But for this particular site it is as mentioned in policy 2 . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The branch not working is using&amp;nbsp; paremeters used in policy 2 . How can ensure that specific branch is using policy 2 ? The below is the debug for my VPN Tunnel . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto isakmp policy 1&lt;/P&gt;&lt;P&gt; encr 3des&lt;/P&gt;&lt;P&gt; hash md5&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto isakmp policy 2&lt;/P&gt;&lt;P&gt; encr aes 512&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;:07:43.101: ISAKMP:(0:11:SW:1):SA has been authenticated with 56.5.4.6&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.101: ISAKMP: Trying to insert a peer 152.86.90.129/56.5.4.6&lt;/P&gt;&lt;P&gt;/500/,&amp;nbsp; and inserted successfully 63CE2DE4.&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.101: ISAKMP:(0:11:SW:1):Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.101: ISAKMP:(0:11:SW:1):Old State = IKE_I_MM5&amp;nbsp; New State = IKE_I_MM6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.101: ISAKMP:(0:11:SW:1):Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.101: ISAKMP:(0:11:SW:1):Old State = IKE_I_MM6&amp;nbsp; New State = IKE_I_MM6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.105: ISAKMP:(0:11:SW:1):Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.105: ISAKMP:(0:11:SW:1):Old State = IKE_I_MM6&amp;nbsp; New State = IKE_P1_COMPLETE&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.105: ISAKMP:(0:11:SW:1):beginning Quick Mode exchange, M-ID of -1841673445&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.105: ISAKMP:(0:11:SW:1): sending packet to 56.5.4.6 my_port 500 peer_port 500 (I) QM_IDLE&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.105: ISAKMP:(0:11:SW:1):Node -1841673445, Input = IKE_MESG_INTERNAL, IKE_INIT_QM&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.105: ISAKMP:(0:11:SW:1):Old State = IKE_QM_READY&amp;nbsp; New State = IKE_QM_I_QM1&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.105: ISAKMP:(0:11:SW:1):Input = IKE_MESG_INTERNAL, IKE_PHASE1_COMPLETE&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.105: ISAKMP:(0:11:SW:1):Old State = IKE_P1_COMPLETE&amp;nbsp; New State = IKE_P1_COMPLETE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.121: ISAKMP (0:134217739): received packet from 56.5.4.6 dport 500 sport 500 Global (I) QM_IDLE&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.121: ISAKMP: set new node -1459554599 to QM_IDLE&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.121: ISAKMP:(0:11:SW:1): processing HASH payload. message ID = -1459554599&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.121: ISAKMP:(0:11:SW:1): processing NOTIFY PROPOSAL_NOT_CHOSEN protocol 3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; spi 0, message ID = -1459554599, sa = 63C68AF8&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.121: ISAKMP:(0:11:SW:1):deleting node -1459554599 error FALSE reason "Informational (in) state 1"&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.121: ISAKMP:(0:11:SW:1):Input = IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.121: ISAKMP:(0:11:SW:1):Old State = IKE_P1_COMPLETE&amp;nbsp; New State = IKE_P1_COMPLETE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.121: ISAKMP (0:134217739): received packet from 56.5.4.6 dport 500 sport 500 Global (I) QM_IDLE&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.125: ISAKMP: set new node -235856768 to QM_IDLE&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.125: ISAKMP:(0:11:SW:1): processing HASH payload. message ID = 235856768&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.125: ISAKMP:(0:11:SW:1): processing DELETE payload. message ID = -235856768&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.125: ISAKMP:(0:11:SW:1):peer does not do paranoid keepalives.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.125: ISAKMP:(0:11:SW:1):deleting SA reason "No reason" state (I) QM_IDLE&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (peer 56.5.4.6)&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.125: ISAKMP:(0:11:SW:1):deleting node -235856768 error FALSE reason "Informational (in) state 1"&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.125: ISAKMP: set new node -212410468 to QM_IDLE&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.125: ISAKMP:(0:11:SW:1): sending packet to 56.5.4.6 my_port 500 peer_port 500 (I) QM_IDLE&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.125: ISAKMP:(0:11:SW:1):purging node -212410468&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.129: ISAKMP:(0:11:SW:1):Input = IKE_MESG_INTERNAL, IKE_PHASE1_DEL&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.129: ISAKMP:(0:11:SW:1):Old State = IKE_P1_COMPLETE&amp;nbsp; New State = IKE_DEST_SA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.129: ISAKMP:(0:11:SW:1):deleting SA reason "No reason" state (I) QM_IDLE&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (peer 56.5.4.6)&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.129: ISAKMP: Unlocking IKE struct 0x63CE2DE4 for isadb_mark_sa_deleted(), count 0&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.129: ISAKMP: Deleting peer node by peer_reap for 56.5.4.6:63CE2DE4&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.129: ISAKMP:(0:11:SW:1):deleting node -1841673445 error FALSE reason "IKE deleted"&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.129: ISAKMP:(0:11:SW:1):deleting node -1459554599 error FALSE reason "IKE deleted"&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.129: ISAKMP:(0:11:SW:1):deleting node -235856768 error FALSE reason "IKE deleted"&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.129: ISAKMP:(0:11:SW:1):Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH&lt;/P&gt;&lt;P&gt;Feb 25 06:07:43.129: ISAKMP:(0:11:SW:1):Old State = IKE_DEST_SA&amp;nbsp; New State = IKE_DEST_SA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feb 25 06:08:02.735: ISAKMP:(0:10:SW:1):purging node -39846581&lt;/P&gt;&lt;P&gt;Feb 25 06:08:02.739: ISAKMP:(0:10:SW:1):purging node 324814776&lt;/P&gt;&lt;P&gt;Feb 25 06:08:02.739: ISAKMP:(0:10:SW:1):purging node 958416367&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:34:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-issue/m-p/1896187#M458832</guid>
      <dc:creator>Haris P</dc:creator>
      <dc:date>2019-03-11T22:34:57Z</dc:date>
    </item>
    <item>
      <title>IPSec VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-issue/m-p/1896188#M458835</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like you got notify message 14 "PROPOSAL_NOT_CHOSEN" during phase 2.&amp;nbsp; Compare your phase 2 attributes with the peer. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Feb 2012 16:45:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-issue/m-p/1896188#M458835</guid>
      <dc:creator>Patrick0711</dc:creator>
      <dc:date>2012-02-25T16:45:37Z</dc:date>
    </item>
    <item>
      <title>IPSec VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-issue/m-p/1896189#M458838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Haris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;The branch not working is using&amp;nbsp; paremeters used in policy 2 . How can ensure that specific branch is using policy 2 ? The below is the debug for my VPN Tunnel .&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif; min-height: 8pt; height: 8pt;"&gt;Each VPN endpoint innitiating the connection will send all of his isakmp's policies until a match happens, so if branch two also has isakmp policie one, that would be a match and they will use that one. as the first match is the one used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif; min-height: 8pt; height: 8pt;"&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif; min-height: 8pt; height: 8pt;"&gt;Do rate all the helpful posts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif; min-height: 8pt; height: 8pt;"&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Feb 2012 18:44:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-issue/m-p/1896189#M458838</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-26T18:44:33Z</dc:date>
    </item>
    <item>
      <title>IPSec VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-issue/m-p/1896190#M458839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's not a phase 1 issue.&amp;nbsp; Notify message 14 "NO_PROPOSAL_CHOSEN" can be used in both phase 1 and phase 2.&amp;nbsp; In this case you can see that phase 1 has completed and the notify message was received during quick mode.&amp;nbsp; I would first check the the phase 2 transform set and then the proxy ID (subnet) info as the INVALID_ID_INFO notify message isn't always used for host/subnet incompaibilities.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Feb 2012 23:01:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-issue/m-p/1896190#M458839</guid>
      <dc:creator>Patrick0711</dc:creator>
      <dc:date>2012-02-26T23:01:54Z</dc:date>
    </item>
    <item>
      <title>IPSec VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-issue/m-p/1896191#M458840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Patrick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When did I said it was a phase one issue?????????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just answered one of his questions!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Feb 2012 01:35:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-issue/m-p/1896191#M458840</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-27T01:35:40Z</dc:date>
    </item>
    <item>
      <title>IPSec VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-issue/m-p/1896192#M458842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wasn't trying argue with you, just trying to emphasize to the issue is not with phase 1.&amp;nbsp; Your response was correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Patrick &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Feb 2012 03:30:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-issue/m-p/1896192#M458842</guid>
      <dc:creator>Patrick0711</dc:creator>
      <dc:date>2012-02-27T03:30:15Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-issue/m-p/1896193#M458845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It was phase2 problem and after changing the transformset it worked fine &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Feb 2012 13:31:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-issue/m-p/1896193#M458845</guid>
      <dc:creator>Haris P</dc:creator>
      <dc:date>2012-02-28T13:31:08Z</dc:date>
    </item>
  </channel>
</rss>

