<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: help deciphering IOS to PIX ISAKMP debug in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/help-deciphering-ios-to-pix-isakmp-debug/m-p/269235#M611619</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That sounds look a good plan.  Thanks for the tips!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Diego&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 01 Dec 2003 03:07:12 GMT</pubDate>
    <dc:creator>tato386</dc:creator>
    <dc:date>2003-12-01T03:07:12Z</dc:date>
    <item>
      <title>help deciphering IOS to PIX ISAKMP debug</title>
      <link>https://community.cisco.com/t5/network-security/help-deciphering-ios-to-pix-isakmp-debug/m-p/269233#M611602</link>
      <description>&lt;P&gt;I have several IOS routers that are successfully establishing IPSec tunnels to my PIX.  However there is one particular router that will not connect.  It is no different than all the rest, same IOS, same crypto config but it just doesn't work.  I have double and triple checked the configs and all looks OK.  I have some debugs here from both ends that show the failure but don't really say why its failing.  Maybe somebody can tell me what the debugs mean.  There is a debug from both ends.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Diego&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;** Debug of PIX with 68.44.33.90 IOS Router trying to establish ISAKMP  **&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto_isakmp_process_block: src 68.44.33.90, dest 64.3.180.226&lt;/P&gt;&lt;P&gt;VPN Peer: ISAKMP: Added new peer: ip:68.44.33.90 Total VPN Peers:6&lt;/P&gt;&lt;P&gt;VPN Peer: ISAKMP: Peer ip:68.44.33.90 Ref cnt incremented to:1 Total VPN Peers:6&lt;/P&gt;&lt;P&gt;OAK_MM exchange&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing SA payload. message ID = 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): Checking ISAKMP transform 1 against priority 1 policy&lt;/P&gt;&lt;P&gt;ISAKMP:      encryption DES-CBC&lt;/P&gt;&lt;P&gt;ISAKMP:      hash MD5&lt;/P&gt;&lt;P&gt;ISAKMP:      default group 1&lt;/P&gt;&lt;P&gt;ISAKMP:      auth pre-share&lt;/P&gt;&lt;P&gt;ISAKMP:      life type in seconds&lt;/P&gt;&lt;P&gt;ISAKMP:      life duration (basic) of 3600&lt;/P&gt;&lt;P&gt;ISAKMP (0): atts are acceptable. Next payload is 0&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing vendor id payload&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing vendor id payload&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): SA is doing pre-shared key authentication using id type ID_IPV4_ADDR&lt;/P&gt;&lt;P&gt;return status is IKMP_NO_ERROR&lt;/P&gt;&lt;P&gt;crypto_isakmp_process_block: src 68.44.33.90, dest 64.3.180.226&lt;/P&gt;&lt;P&gt;VPN Peer: ISAKMP: Peer ip:68.44.33.90 Ref cnt incremented to:2 Total VPN Peers:6&lt;/P&gt;&lt;P&gt;VPN Peer: ISAKMP: Peer ip:68.44.33.90 Ref cnt decremented to:1 Total VPN Peers:6&lt;/P&gt;&lt;P&gt;crypto_isakmp_process_block: src 64.221.60.74, dest 64.3.180.226&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing NOTIFY payload 36136 protocol 1&lt;/P&gt;&lt;P&gt;        spi 0, message ID = 494535626&lt;/P&gt;&lt;P&gt;ISAMKP (0): received DPD_R_U_THERE from peer 64.221.60.74&lt;/P&gt;&lt;P&gt;ISAKMP (0): sending NOTIFY message 36137 protocol 1&lt;/P&gt;&lt;P&gt;return status is IKMP_NO_ERR_NO_TRANS&lt;/P&gt;&lt;P&gt;ISAKMP (0): retransmitting phase 1...&lt;/P&gt;&lt;P&gt;crypto_isakmp_process_block: src 68.44.33.90, dest 64.3.180.226&lt;/P&gt;&lt;P&gt;VPN Peer: ISAKMP: Peer ip:68.44.33.90 Ref cnt incremented to:2 Total VPN Peers:6&lt;/P&gt;&lt;P&gt;VPN Peer: ISAKMP: Peer ip:68.44.33.90 Ref cnt decremented to:1 Total VPN Peers:6&lt;/P&gt;&lt;P&gt;crypto_isakmp_process_block: src 68.44.33.90, dest 64.3.180.226&lt;/P&gt;&lt;P&gt;VPN Peer: ISAKMP: Peer ip:68.44.33.90 Ref cnt incremented to:2 Total VPN Peers:6&lt;/P&gt;&lt;P&gt;VPN Peer: ISAKMP: Peer ip:68.44.33.90 Ref cnt decremented to:1 Total VPN Peers:6&lt;/P&gt;&lt;P&gt;ISAKMP (0): retransmitting phase 1...&lt;/P&gt;&lt;P&gt;crypto_isakmp_process_block: src 68.44.33.90, dest 64.3.180.226&lt;/P&gt;&lt;P&gt;VPN Peer: ISAKMP: Peer ip:68.44.33.90 Ref cnt incremented to:2 Total VPN Peers:6&lt;/P&gt;&lt;P&gt;VPN Peer: ISAKMP: Peer ip:68.44.33.90 Ref cnt decremented to:1 Total VPN Peers:6&lt;/P&gt;&lt;P&gt;ISAKMP (0): deleting SA: src 68.44.33.90, dst 64.3.180.226&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VPN Peer: ISAKMP: Peer ip:68.44.33.90 Ref cnt decremented to:0 Total VPN Peers:6&lt;/P&gt;&lt;P&gt;VPN Peer: ISAKMP: Deleted peer: ip:68.44.33.90 Total VPN peers:5&lt;/P&gt;&lt;P&gt;crypto_isakmp_process_block: src 68.44.33.90, dest 64.3.180.226&lt;/P&gt;&lt;P&gt;VPN Peer: ISAKMP: Added new peer: ip:68.44.33.90 Total VPN Peers:6&lt;/P&gt;&lt;P&gt;VPN Peer: ISAKMP: Peer ip:68.44.33.90 Ref cnt incremented to:1 Total VPN Peers:6&lt;/P&gt;&lt;P&gt;OAK_MM exchange&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing SA payload. message ID = 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): Checking ISAKMP transform 1 against priority 1 policy&lt;/P&gt;&lt;P&gt;ISAKMP:      encryption DES-CBC&lt;/P&gt;&lt;P&gt;ISAKMP:      hash MD5&lt;/P&gt;&lt;P&gt;ISAKMP:      default group 1&lt;/P&gt;&lt;P&gt;ISAKMP:      auth pre-share&lt;/P&gt;&lt;P&gt;ISAKMP:      life type in seconds&lt;/P&gt;&lt;P&gt;ISAKMP:      life duration (basic) of 3600&lt;/P&gt;&lt;P&gt;ISAKMP (0): atts are acceptable. Next payload is 0&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing vendor id payload&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing vendor id payload&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): SA is doing pre-shared key authentication using id type ID_IPV4_ADDR&lt;/P&gt;&lt;P&gt;return status is IKMP_NO_ERROR&lt;/P&gt;&lt;P&gt;ISAKMP (0): retransmitting phase 1...&lt;/P&gt;&lt;P&gt;crypto_isakmp_process_block: src 68.44.33.90, dest 64.3.180.226&lt;/P&gt;&lt;P&gt;VPN Peer: ISAKMP: Peer ip:68.44.33.90 Ref cnt incremented to:2 Total VPN Peers:6&lt;/P&gt;&lt;P&gt;OAK_MM exchange&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing SA payload. message ID = 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): Checking ISAKMP transform 1 against priority 1 policy&lt;/P&gt;&lt;P&gt;ISAKMP:      encryption DES-CBC&lt;/P&gt;&lt;P&gt;ISAKMP:      hash MD5&lt;/P&gt;&lt;P&gt;ISAKMP:      default group 1&lt;/P&gt;&lt;P&gt;ISAKMP:      auth pre-share&lt;/P&gt;&lt;P&gt;ISAKMP:      life type in seconds&lt;/P&gt;&lt;P&gt;ISAKMP:      life duration (basic) of 3600&lt;/P&gt;&lt;P&gt;ISAKMP (0): atts are acceptable. Next payload is 0&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing vendor id payload&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing vendor id payload&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): SA is doing pre-shared key authentication using id type ID_IPV4_ADDR&lt;/P&gt;&lt;P&gt;return status is IKMP_NO_ERROR&lt;/P&gt;&lt;P&gt;ISAKMP (0): sending NOTIFY message 36136 protocol 1&lt;/P&gt;&lt;P&gt;crypto_isakmp_process_block: src 141.150.175.18, dest 64.3.180.226&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing NOTIFY payload 36137 protocol 1&lt;/P&gt;&lt;P&gt;        spi 0, message ID = 1670884433&lt;/P&gt;&lt;P&gt;ISAMKP (0): received DPD_R_U_THERE_ACK from peer 141.150.175.18&lt;/P&gt;&lt;P&gt;return status is IKMP_NO_ERR_NO_TRANS&lt;/P&gt;&lt;P&gt;ISAKMP (0): retransmitting phase 1...&lt;/P&gt;&lt;P&gt;crypto_isakmp_process_block: src 68.44.33.90, dest 64.3.180.226&lt;/P&gt;&lt;P&gt;VPN Peer: ISAKMP: Peer ip:68.44.33.90 Ref cnt incremented to:3 Total VPN Peers:6&lt;/P&gt;&lt;P&gt;OAK_MM exchange&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing SA payload. message ID = 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): Checking ISAKMP transform 1 against priority 1 policy&lt;/P&gt;&lt;P&gt;ISAKMP:      encryption DES-CBC&lt;/P&gt;&lt;P&gt;ISAKMP:      hash MD5&lt;/P&gt;&lt;P&gt;ISAKMP:      default group 1&lt;/P&gt;&lt;P&gt;ISAKMP:      auth pre-share&lt;/P&gt;&lt;P&gt;ISAKMP:      life type in seconds&lt;/P&gt;&lt;P&gt;ISAKMP:      life duration (basic) of 3600&lt;/P&gt;&lt;P&gt;ISAKMP (0): atts are acceptable. Next payload is 0&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing vendor id payload&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing vendor id payload&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): SA is doing pre-shared key authentication using id type ID_IPV4_ADDR&lt;/P&gt;&lt;P&gt;return status is IKMP_NO_ERROR&lt;/P&gt;&lt;P&gt;ISAKMP (0): retransmitting phase 1...&lt;/P&gt;&lt;P&gt;crypto_isakmp_process_block: src 68.44.33.90, dest 64.3.180.226&lt;/P&gt;&lt;P&gt;VPN Peer: ISAKMP: Peer ip:68.44.33.90 Ref cnt incremented to:4 Total VPN Peers:6&lt;/P&gt;&lt;P&gt;OAK_MM exchange&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing SA payload. message ID = 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): Checking ISAKMP transform 1 against priority 1 policy&lt;/P&gt;&lt;P&gt;ISAKMP:      encryption DES-CBC&lt;/P&gt;&lt;P&gt;ISAKMP:      hash MD5&lt;/P&gt;&lt;P&gt;ISAKMP:      default group 1&lt;/P&gt;&lt;P&gt;ISAKMP:      auth pre-share&lt;/P&gt;&lt;P&gt;ISAKMP:      life type in seconds&lt;/P&gt;&lt;P&gt;ISAKMP:      life duration (basic) of 3600&lt;/P&gt;&lt;P&gt;ISAKMP (0): atts are acceptable. Next payload is 0&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing vendor id payload&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing vendor id payload&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): SA is doing pre-shared key authentication using id type ID_IPV4_ADDR&lt;/P&gt;&lt;P&gt;return status is IKMP_NO_ERROR&lt;/P&gt;&lt;P&gt;ISAKMP (0): deleting SA: src 68.44.33.90, dst 64.3.180.226&lt;/P&gt;&lt;P&gt;ISAKMP (0): retransmitting phase 1...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VPN Peer: ISAKMP: Peer ip:68.44.33.90 Ref cnt decremented to:3 Total VPN Peers:6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto_isakmp_process_block: src 68.44.33.90, dest 64.3.180.226&lt;/P&gt;&lt;P&gt;VPN Peer: ISAKMP: Peer ip:68.44.33.90 Ref cnt incremented to:4 Total VPN Peers:6&lt;/P&gt;&lt;P&gt;VPN Peer: ISAKMP: Peer ip:68.44.33.90 Ref cnt decremented to:3 Total VPN Peers:6&lt;/P&gt;&lt;P&gt;ISAKMP (0): retransmitting phase 1...no debug crypto isakmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;** Debug at IOS router trying to establish ISAKMP with PIX  **&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP: received ke message (1/1)&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): SA request profile is (NULL)&lt;/P&gt;&lt;P&gt;ISAKMP: local port 500, remote port 500&lt;/P&gt;&lt;P&gt;ISAKMP: set new node 0 to QM_IDLE&lt;/P&gt;&lt;P&gt;ISAKMP: insert sa successfully sa = 81C55628&lt;/P&gt;&lt;P&gt;ISAKMP (0:1): Can not start Aggressive mode, trying Main mode.&lt;/P&gt;&lt;P&gt;ISAKMP: Looking for a matching key for 64.3.180.226 in default : success&lt;/P&gt;&lt;P&gt;ISAKMP (0:1): found peer pre-shared key matching 64.3.180.226&lt;/P&gt;&lt;P&gt;ISAKMP (0:1): constructed NAT-T vendor-03 ID&lt;/P&gt;&lt;P&gt;ISAKMP (0:1): constructed NAT-T vendor-02 ID&lt;/P&gt;&lt;P&gt;ISAKMP (0:1): Input = IKE_MESG_FROM_IPSEC, IKE_SA_REQ_MM&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): Old State = IKE_READY  New State = IKE_I_MM1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): beginning Main Mode exchange&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): sending packet to 64.3.180.226 my_port 500 peer_port 500 (I) MM_NO_STATE.....&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): retransmitting phase 1 MM_NO_STATE.&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): incrementing error counter on sa: retransmit phase 1&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): retransmitting phase 1 MM_NO_STATE&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): sending packet to 64.3.180.226 my_port 500 peer_port 500 (I) MM_NO_STATE&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): retransmitting phase 1 MM_NO_STATE.&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): incrementing error counter on sa: retransmit phase 1&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): retransmitting phase 1 MM_NO_STATE&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): sending packet to 64.3.180.226 my_port 500 peer_port 500 (I) MM_NO_STATE&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP: received ke message (1/1)&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP: set new node 0 to QM_IDLE&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): SA is still budding. Attached new ipsec request to it. (local 68.44.33.90, remote 64.3.180.226)&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): retransmitting phase 1 MM_NO_STATE.&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): incrementing error counter on sa: retransmit phase 1&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): retransmitting phase 1 MM_NO_STATE&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): sending packet to 64.3.180.226 my_port 500 peer_port 500 (I) MM_NO_STATE&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): retransmitting phase 1 MM_NO_STATE.&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): incrementing error counter on sa: retransmit phase 1&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): retransmitting phase 1 MM_NO_STATE&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): sending packet to 64.3.180.226 my_port 500 peer_port 500 (I) MM_NO_STATE&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): retransmitting phase 1 MM_NO_STATE.&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): incrementing error counter on sa: retransmit phase 1&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): retransmitting phase 1 MM_NO_STATE&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): sending packet to 64.3.180.226 my_port 500 peer_port 500 (I) MM_NO_STATE&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP: received ke message (3/1)&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): peer does not do paranoid keepalives.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): deleting SA reason "gen_ipsec_isakmp_delete but doi isakmp" state (I) MM_NO_STATE (peer 64.3.180.226) input queue 0&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): deleting SA reason "gen_ipsec_isakmp_delete but doi isakmp" state (I) MM_NO_STATE (peer 64.3.180.226) input queue 0&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): deleting node 243979660 error TRUE reason "gen_ipsec_isakmp_delete but doi isakmp"&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): deleting node -1559624423 error TRUE reason "gen_ipsec_isakmp_delete but doi isakmp"&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): Input = IKE_MESG_INTERNAL, IKE_PHASE1_DEL&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): Old State = IKE_I_MM1  New State = IKE_DEST_SA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:07:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-deciphering-ios-to-pix-isakmp-debug/m-p/269233#M611602</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2020-02-21T07:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: help deciphering IOS to PIX ISAKMP debug</title>
      <link>https://community.cisco.com/t5/network-security/help-deciphering-ios-to-pix-isakmp-debug/m-p/269234#M611613</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The router debug here:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): beginning Main Mode exchange&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): sending packet to 64.3.180.226 my_port 500 peer_port 500 (I) MM_NO_STATE.....&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): retransmitting phase 1 MM_NO_STATE.&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): incrementing error counter on sa: retransmit phase 1&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): retransmitting phase 1 MM_NO_STATE&lt;/P&gt;&lt;P&gt;2w0d: ISAKMP (0:1): sending packet to 64.3.180.226 my_port 500 peer_port 500 (I) MM_NO_STATE &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;shows that it's sending IKE packets to the PIX.  The PIX debug shows it's comparing the attributes and they're OK, it replies to the router, but the router never sees that.  It retransmits, again it gets no answer, and eventually gives up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you have to see why the router isn't seeing the ISAKMP packets from the PIX.  Check that the ISP isn't blocking them, they do sometimes cause they want to charge extra for having VPN's run across their network.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Failing that, try bringing up the tunnel from behind the PIX (rather from behind the router) and check the debugs again, you'll get more information on the router debug this way and it may give more information as to the cause.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Dec 2003 01:17:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-deciphering-ios-to-pix-isakmp-debug/m-p/269234#M611613</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2003-12-01T01:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: help deciphering IOS to PIX ISAKMP debug</title>
      <link>https://community.cisco.com/t5/network-security/help-deciphering-ios-to-pix-isakmp-debug/m-p/269235#M611619</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That sounds look a good plan.  Thanks for the tips!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Diego&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Dec 2003 03:07:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-deciphering-ios-to-pix-isakmp-debug/m-p/269235#M611619</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2003-12-01T03:07:12Z</dc:date>
    </item>
  </channel>
</rss>

