<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to debug ipsec phase 2 on ASA 5520? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-debug-ipsec-phase-2-on-asa-5520/m-p/1326366#M785538</link>
    <description>&lt;P&gt;I have a problem related to ipsec on a Cisco ASA 5520. Briefly told the problem is when the remote site is initiating traffic againt my site. Traffic initiated from my site is working perfect. When the remote site is initiating traffic sometimes it works and somestimes it is not working. When it is NOT working the log shows the output that I have included in the attached file. So my question is: How can I set up logging on the ASA so that I can see exactly WAHT is causing the problem? The attached file is the result from logging with debug level, but how to see the exact cause of the failure? How to see what proposals the remote gateway is suggesting and so on...?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The really strange thing is that it sometimes work, sometimes not. Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 16:40:31 GMT</pubDate>
    <dc:creator>cisco</dc:creator>
    <dc:date>2019-03-11T16:40:31Z</dc:date>
    <item>
      <title>How to debug ipsec phase 2 on ASA 5520?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-debug-ipsec-phase-2-on-asa-5520/m-p/1326366#M785538</link>
      <description>&lt;P&gt;I have a problem related to ipsec on a Cisco ASA 5520. Briefly told the problem is when the remote site is initiating traffic againt my site. Traffic initiated from my site is working perfect. When the remote site is initiating traffic sometimes it works and somestimes it is not working. When it is NOT working the log shows the output that I have included in the attached file. So my question is: How can I set up logging on the ASA so that I can see exactly WAHT is causing the problem? The attached file is the result from logging with debug level, but how to see the exact cause of the failure? How to see what proposals the remote gateway is suggesting and so on...?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The really strange thing is that it sometimes work, sometimes not. Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:40:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-debug-ipsec-phase-2-on-asa-5520/m-p/1326366#M785538</guid>
      <dc:creator>cisco</dc:creator>
      <dc:date>2019-03-11T16:40:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to debug ipsec phase 2 on ASA 5520?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-debug-ipsec-phase-2-on-asa-5520/m-p/1326367#M785539</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You're failing at the negotiation of IPSec. You have a log entry of &lt;B&gt;All IPSec SA proposals found unacceptable&lt;/B&gt;. Make sure everything matches verbatim in ISAKMP and IPSec. Also here's an excellent troubleshooting guide.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807e0aca.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807e0aca.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Nov 2009 14:22:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-debug-ipsec-phase-2-on-asa-5520/m-p/1326367#M785539</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2009-11-17T14:22:21Z</dc:date>
    </item>
  </channel>
</rss>

