<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: one remote site can't VPN in, getting SA errors (ASA5505) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/one-remote-site-can-t-vpn-in-getting-sa-errors-asa5505/m-p/1158531#M960438</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Huw&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DES instead of 3DES would certainly explain the error messages in your original post. If you are able to bring up the tunnel but not to route anything over it, my first suggestion would be to check the access list that identifies traffic for the VPN tunnel for possible omissions/mismatches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 08 Jan 2009 18:10:41 GMT</pubDate>
    <dc:creator>Richard Burts</dc:creator>
    <dc:date>2009-01-08T18:10:41Z</dc:date>
    <item>
      <title>one remote site can't VPN in, getting SA errors (ASA5505)</title>
      <link>https://community.cisco.com/t5/network-security/one-remote-site-can-t-vpn-in-getting-sa-errors-asa5505/m-p/1158529#M960434</link>
      <description>&lt;P&gt;Hi all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of our customers has an asa 5505. We have 4 remote sites working fine (the remote sites have 1841's with the security pack, and have all formed tunnels in OK)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We'ev visited our last site to be configured, set the router up exactly as the others, but we're now getting the below errors, taken from the head office ASA debug log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The engineer assures me the shared key is correct. What else could be the issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5	Jan 08 2009	04:58:41	713904			 IP = 81.179.5.13, Received encrypted packet with no matching SA, dropping&lt;/P&gt;&lt;P&gt;4	Jan 08 2009	04:58:41	113019			 Group = 81.179.5.13, Username = 81.179.5.13, IP = 81.179.5.13, Session disconnected. Session Type: IPSecLAN2LAN, Duration: 0h:00m:00s, Bytes xmt: 0, Bytes rcv: 0, Reason: Phase 2 Mismatch&lt;/P&gt;&lt;P&gt;3	Jan 08 2009	04:58:41	713902			 Group = 81.179.5.13, IP = 81.179.5.13, Removing peer from correlator table failed, no match!&lt;/P&gt;&lt;P&gt;3	Jan 08 2009	04:58:41	713902			 Group = 81.179.5.13, IP = 81.179.5.13, QM FSM error (P2 struct &amp;amp;0x3d584f8, mess id 0x40198ae4)!&lt;/P&gt;&lt;P&gt;5	Jan 08 2009	04:58:41	713904			 Group = 81.179.5.13, IP = 81.179.5.13, All IPSec SA proposals found unacceptable!&lt;/P&gt;&lt;P&gt;3	Jan 08 2009	04:58:41	713119			 Group = 81.179.5.13, IP = 81.179.5.13, PHASE 1 COMPLETED&lt;/P&gt;&lt;P&gt;6	Jan 08 2009	04:58:41	113009			 AAA retrieved default group policy (DfltGrpPolicy) for user = 81.179.5.13&lt;/P&gt;&lt;P&gt;4	Jan 08 2009	04:58:41	713903			 Group = 81.179.5.13, IP = 81.179.5.13, Freeing previously allocated memory for authorization-dn-attributes&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:12:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-remote-site-can-t-vpn-in-getting-sa-errors-asa5505/m-p/1158529#M960434</guid>
      <dc:creator>davieshuw</dc:creator>
      <dc:date>2020-02-21T11:12:14Z</dc:date>
    </item>
    <item>
      <title>Re: one remote site can't VPN in, getting SA errors (ASA5505)</title>
      <link>https://community.cisco.com/t5/network-security/one-remote-site-can-t-vpn-in-getting-sa-errors-asa5505/m-p/1158530#M960437</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok fixed this. The tunnel for this particular site had des configured on the ASA, we're actually using 3des. Rectified now the tunnels formed OK. Can't route anything over it mind.. but thats another story..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Jan 2009 13:59:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-remote-site-can-t-vpn-in-getting-sa-errors-asa5505/m-p/1158530#M960437</guid>
      <dc:creator>davieshuw</dc:creator>
      <dc:date>2009-01-08T13:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: one remote site can't VPN in, getting SA errors (ASA5505)</title>
      <link>https://community.cisco.com/t5/network-security/one-remote-site-can-t-vpn-in-getting-sa-errors-asa5505/m-p/1158531#M960438</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Huw&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DES instead of 3DES would certainly explain the error messages in your original post. If you are able to bring up the tunnel but not to route anything over it, my first suggestion would be to check the access list that identifies traffic for the VPN tunnel for possible omissions/mismatches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Jan 2009 18:10:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-remote-site-can-t-vpn-in-getting-sa-errors-asa5505/m-p/1158531#M960438</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2009-01-08T18:10:41Z</dc:date>
    </item>
  </channel>
</rss>

