<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RA-VPN error: Duplicate Phase 1 packet detected in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ra-vpn-error-duplicate-phase-1-packet-detected/m-p/978519#M939097</link>
    <description>&lt;P&gt;i've tried to set up a remote access vpn with both the wizard and then agian at the CLI, but to no avail. &lt;/P&gt;&lt;P&gt;Each time i get the same error,&lt;/P&gt;&lt;P&gt;Duplicate Phase 1 packet detected.  Retransmitting last packet&lt;/P&gt;&lt;P&gt;I've tried different clients and also checked that : &lt;/P&gt;&lt;P&gt;sysopt connection permit-ipsec &lt;/P&gt;&lt;P&gt;is enabled.&lt;/P&gt;&lt;P&gt;though i haven't been able to run the:&lt;/P&gt;&lt;P&gt;debug crypto isakmp&lt;/P&gt;&lt;P&gt;due to it being in production&lt;/P&gt;&lt;P&gt;many thanks&lt;/P&gt;&lt;P&gt;phil&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 12:32:54 GMT</pubDate>
    <dc:creator>philbe</dc:creator>
    <dc:date>2019-03-11T12:32:54Z</dc:date>
    <item>
      <title>RA-VPN error: Duplicate Phase 1 packet detected</title>
      <link>https://community.cisco.com/t5/network-security/ra-vpn-error-duplicate-phase-1-packet-detected/m-p/978519#M939097</link>
      <description>&lt;P&gt;i've tried to set up a remote access vpn with both the wizard and then agian at the CLI, but to no avail. &lt;/P&gt;&lt;P&gt;Each time i get the same error,&lt;/P&gt;&lt;P&gt;Duplicate Phase 1 packet detected.  Retransmitting last packet&lt;/P&gt;&lt;P&gt;I've tried different clients and also checked that : &lt;/P&gt;&lt;P&gt;sysopt connection permit-ipsec &lt;/P&gt;&lt;P&gt;is enabled.&lt;/P&gt;&lt;P&gt;though i haven't been able to run the:&lt;/P&gt;&lt;P&gt;debug crypto isakmp&lt;/P&gt;&lt;P&gt;due to it being in production&lt;/P&gt;&lt;P&gt;many thanks&lt;/P&gt;&lt;P&gt;phil&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:32:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ra-vpn-error-duplicate-phase-1-packet-detected/m-p/978519#M939097</guid>
      <dc:creator>philbe</dc:creator>
      <dc:date>2019-03-11T12:32:54Z</dc:date>
    </item>
    <item>
      <title>Re: RA-VPN error: Duplicate Phase 1 packet detected</title>
      <link>https://community.cisco.com/t5/network-security/ra-vpn-error-duplicate-phase-1-packet-detected/m-p/978520#M939100</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have checked the error log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I have found for you:&lt;/P&gt;&lt;P&gt;Error Message    %PIX|ASA-3-713902 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Recommended Action    It might be necessary to troubleshoot the configuration to determine the cause of the error. Check the ISAKMP and crypto map configuration on both peers. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also check if you can reach the peer. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wouter&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Apr 2008 17:33:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ra-vpn-error-duplicate-phase-1-packet-detected/m-p/978520#M939100</guid>
      <dc:creator>whjvdam1</dc:creator>
      <dc:date>2008-04-17T17:33:53Z</dc:date>
    </item>
    <item>
      <title>Re: RA-VPN error: Duplicate Phase 1 packet detected</title>
      <link>https://community.cisco.com/t5/network-security/ra-vpn-error-duplicate-phase-1-packet-detected/m-p/978521#M939102</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks Wouter &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is the config, there is also a bit for a site to site, that works, sorry for the delay.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt; description *** Ultra Site-2-Site ***&lt;/P&gt;&lt;P&gt; nameif Ultra_Site-2-Site&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address **********&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 172.16.9.0 255.255.255.0 10.1.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list Ultra_Site-2-Site_cryptomap_20 extended permit ip 172.16.9.0 255.255.255.0 10.1.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip local pool affinitipool 172.16.8.249-172.16.8.250 mask 255.255.255.252&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route Ultra_Site-2-Site 81.171.173.35 255.255.255.255 81.137.12.22 1&lt;/P&gt;&lt;P&gt;route Ultra_Site-2-Site 10.1.0.0 255.255.255.0 81.137.12.22 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;group-policy affinitivpn internal&lt;/P&gt;&lt;P&gt;group-policy affinitivpn attributes&lt;/P&gt;&lt;P&gt; dns-server value 10.201.10.10&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol IPSec&lt;/P&gt;&lt;P&gt; webvpn&lt;/P&gt;&lt;P&gt;username network password oAey6bUMeYJzmyZI encrypted privilege 15&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto dynamic-map affiniti_dyn_map 40 set transform-set ESP-3DES-SHA&lt;/P&gt;&lt;P&gt;crypto dynamic-map affiniti_dyn_map 40 set reverse-route&lt;/P&gt;&lt;P&gt;crypto map Ultra_Site-2-Site_map 20 match address Ultra_Site-2-Site_cryptomap_20&lt;/P&gt;&lt;P&gt;crypto map Ultra_Site-2-Site_map 20 set peer 81.171.173.35&lt;/P&gt;&lt;P&gt;crypto map Ultra_Site-2-Site_map 20 set transform-set ESP-3DES-SHA&lt;/P&gt;&lt;P&gt;crypto map Ultra_Site-2-Site_map 40 ipsec-isakmp dynamic affiniti_dyn_map&lt;/P&gt;&lt;P&gt;crypto map Ultra_Site-2-Site_map interface Ultra_Site-2-Site&lt;/P&gt;&lt;P&gt;isakmp enable Ultra_Site-2-Site&lt;/P&gt;&lt;P&gt;isakmp policy 10 authentication pre-share&lt;/P&gt;&lt;P&gt;isakmp policy 10 encryption 3des&lt;/P&gt;&lt;P&gt;isakmp policy 10 hash sha&lt;/P&gt;&lt;P&gt;isakmp policy 10 group 2&lt;/P&gt;&lt;P&gt;isakmp policy 10 lifetime 1800&lt;/P&gt;&lt;P&gt;isakmp nat-traversal  20&lt;/P&gt;&lt;P&gt;tunnel-group 81.171.173.35 type ipsec-l2l&lt;/P&gt;&lt;P&gt;tunnel-group 81.171.173.35 ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;tunnel-group affinitivpn type ipsec-ra&lt;/P&gt;&lt;P&gt;tunnel-group affinitivpn general-attributes&lt;/P&gt;&lt;P&gt; address-pool affinitipool&lt;/P&gt;&lt;P&gt; default-group-policy affinitivpn&lt;/P&gt;&lt;P&gt;tunnel-group affinitivpn ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2008 09:56:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ra-vpn-error-duplicate-phase-1-packet-detected/m-p/978521#M939102</guid>
      <dc:creator>philbe</dc:creator>
      <dc:date>2008-04-22T09:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: RA-VPN error: Duplicate Phase 1 packet detected</title>
      <link>https://community.cisco.com/t5/network-security/ra-vpn-error-duplicate-phase-1-packet-detected/m-p/978522#M939103</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;for others who get this error.&lt;/P&gt;&lt;P&gt;it was actually a routing problem.&lt;/P&gt;&lt;P&gt;this RA-VPN wasn't on the outside interface, but on e0/3 so there wasn't a default route.&lt;/P&gt;&lt;P&gt;we needed to add specific routes to REAL ip address to connect.&lt;/P&gt;&lt;P&gt;the asa log is just saying that it's recieving the phase1 (but can't respond in the right direction.)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Apr 2008 08:33:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ra-vpn-error-duplicate-phase-1-packet-detected/m-p/978522#M939103</guid>
      <dc:creator>philbe</dc:creator>
      <dc:date>2008-04-25T08:33:20Z</dc:date>
    </item>
  </channel>
</rss>

