<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX ENCRYPTION ISSUE? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-encryption-issue/m-p/396588#M554643</link>
    <description>&lt;P&gt;I have 2 pix's that are set up to connect to each other via vpn. but the pix's only setup as per below&lt;/P&gt;&lt;P&gt;the SA seems to be fine but nothing created:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Total     : 2&lt;/P&gt;&lt;P&gt;Embryonic : 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dst      src       state     pending    created&lt;/P&gt;&lt;P&gt;xxx      xxxx      QM_IDLE     0          0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also the remote pix does not seem to encrypt the traffic:&lt;/P&gt;&lt;P&gt; PERMIT, flags={origin_is_acl,}&lt;/P&gt;&lt;P&gt;#pkts encaps: 0, #pkts encrypt: 0, #pkts digest 0&lt;/P&gt;&lt;P&gt;#pkts decaps: 0, #pkts decrypt: 0, #pkts verify 0&lt;/P&gt;&lt;P&gt;#pkts compressed: 0, #pkts decompressed: 0&lt;/P&gt;&lt;P&gt;#pkts not compressed: 0, #pkts compr. failed: 0, #pkts decompress failed: 0&lt;/P&gt;&lt;P&gt;#send errors 1379, #recv errors 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am unable to find any info on this anywhere on cisco.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so i do not understand why the pix establishes the SA but does not encrypt the traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any help much appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 07:45:39 GMT</pubDate>
    <dc:creator>ciscoacs</dc:creator>
    <dc:date>2020-02-21T07:45:39Z</dc:date>
    <item>
      <title>PIX ENCRYPTION ISSUE?</title>
      <link>https://community.cisco.com/t5/network-security/pix-encryption-issue/m-p/396588#M554643</link>
      <description>&lt;P&gt;I have 2 pix's that are set up to connect to each other via vpn. but the pix's only setup as per below&lt;/P&gt;&lt;P&gt;the SA seems to be fine but nothing created:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Total     : 2&lt;/P&gt;&lt;P&gt;Embryonic : 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dst      src       state     pending    created&lt;/P&gt;&lt;P&gt;xxx      xxxx      QM_IDLE     0          0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also the remote pix does not seem to encrypt the traffic:&lt;/P&gt;&lt;P&gt; PERMIT, flags={origin_is_acl,}&lt;/P&gt;&lt;P&gt;#pkts encaps: 0, #pkts encrypt: 0, #pkts digest 0&lt;/P&gt;&lt;P&gt;#pkts decaps: 0, #pkts decrypt: 0, #pkts verify 0&lt;/P&gt;&lt;P&gt;#pkts compressed: 0, #pkts decompressed: 0&lt;/P&gt;&lt;P&gt;#pkts not compressed: 0, #pkts compr. failed: 0, #pkts decompress failed: 0&lt;/P&gt;&lt;P&gt;#send errors 1379, #recv errors 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am unable to find any info on this anywhere on cisco.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so i do not understand why the pix establishes the SA but does not encrypt the traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any help much appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:45:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-encryption-issue/m-p/396588#M554643</guid>
      <dc:creator>ciscoacs</dc:creator>
      <dc:date>2020-02-21T07:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: PIX ENCRYPTION ISSUE?</title>
      <link>https://community.cisco.com/t5/network-security/pix-encryption-issue/m-p/396589#M554644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please post the relevant ike and crypto config statements from both pix units.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You menetioned about an SA being created, would that be the phase 1 (ISAKMP) sa?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With regards to ipsec (phase 2) sa setup, you want to insure that the crypto acls on both pix units are mirror images of each other, and that the crypto map configs contain the same lifetime, DH group, encrypt and hash values.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will review the config statements and let you know what I find.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A handy troubleshooting tool are the debug cry isa, debug cry ipsec, and the debug cry engine commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If possible, run all 3 commands on both pix units, try to get the tunnel working, and post the debug output from both units here as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Nov 2004 02:54:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-encryption-issue/m-p/396589#M554644</guid>
      <dc:creator>ehirsel</dc:creator>
      <dc:date>2004-11-22T02:54:33Z</dc:date>
    </item>
  </channel>
</rss>

