<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: L2L VPN not coming up, or is it? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/l2l-vpn-not-coming-up-or-is-it/m-p/1248039#M970258</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;RFC 2408:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.faqs.org/rfcs/rfc2408.html" target="_blank"&gt;http://www.faqs.org/rfcs/rfc2408.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Section '3.14.1 Notify Message Types'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6.x code will not display the meaning of the notify message types, even at the highest debug levels. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;7.x and above code will display the meaning of the notify messages in the higher-level debug outputs.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's always best to troubleshoot the IKE negotiation by examining your debugs as the responder, however, knowing these message types will help you troubleshoot as the initiator.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Oct 2009 04:29:40 GMT</pubDate>
    <dc:creator>Patrick0711</dc:creator>
    <dc:date>2009-10-22T04:29:40Z</dc:date>
    <item>
      <title>L2L VPN not coming up, or is it?</title>
      <link>https://community.cisco.com/t5/network-security/l2l-vpn-not-coming-up-or-is-it/m-p/1248032#M970251</link>
      <description>&lt;P&gt;I've been banging my head against a wall trying to figure this one out and I'm stumped. I've been trying to setup a LAN to LAN VPN between our network (Pix515e) and AT&amp;amp;T (IOS Router). AT&amp;amp;T provided the following configuration information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ATT's peer address is 209.183.xxx.yyy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IKE Phase I settings:&lt;/P&gt;&lt;P&gt;3des&lt;/P&gt;&lt;P&gt;sha1 or md5&lt;/P&gt;&lt;P&gt;pre-shared key&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DH group 2&lt;/P&gt;&lt;P&gt;IPSec phase II settings:&lt;/P&gt;&lt;P&gt;3des&lt;/P&gt;&lt;P&gt;Sha&lt;/P&gt;&lt;P&gt;Pre-shared key:****&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ATT's ACL or Local/Remote Network List:&lt;/P&gt;&lt;P&gt; permit ip 192.168.80.0 0.0.0.255 192.168.3.0 0.0.0.15&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my config, which should match theirs. You can also see my hit counters are climbing for NoNat and Interesting traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**********************************************************************************************************************************&lt;/P&gt;&lt;P&gt;IPSEC Configuration&lt;/P&gt;&lt;P&gt;**********************************************************************************************************************************&lt;/P&gt;&lt;P&gt;access-list ATTIPSecACL permit ip 192.168.3.0 255.255.255.240 192.168.80.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set att esp-3des esp-sha-hmac&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto map SSVPN 9 ipsec-isakmp&lt;/P&gt;&lt;P&gt;crypto map SSVPN 9 match address ATTIPSecACL&lt;/P&gt;&lt;P&gt;crypto map SSVPN 9 set peer 209.183.xxx.yyy&lt;/P&gt;&lt;P&gt;crypto map SSVPN 9 set transform-set att&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;isakmp key ******** address 209.183.xxx.yyy netmask 255.255.255.255 no-xauth no-config-mode&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;isakmp policy 7 authentication pre-share&lt;/P&gt;&lt;P&gt;isakmp policy 7 encryption 3des&lt;/P&gt;&lt;P&gt;isakmp policy 7 hash md5&lt;/P&gt;&lt;P&gt;isakmp policy 7 group 2&lt;/P&gt;&lt;P&gt;isakmp policy 7 lifetime 28800&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;isakmp policy 9 authentication pre-share&lt;/P&gt;&lt;P&gt;isakmp policy 9 encryption 3des&lt;/P&gt;&lt;P&gt;isakmp policy 9 hash sha&lt;/P&gt;&lt;P&gt;isakmp policy 9 group 2&lt;/P&gt;&lt;P&gt;isakmp policy 9 lifetime 28800&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ATTIPSecACL line 1 permit ip 192.168.3.0 255.255.255.240 192.168.80.0 255.255.255.0 (hitcnt=161)&lt;/P&gt;&lt;P&gt;access-list nonat line 16 permit ip 192.168.3.0 255.255.255.240 192.168.80.0 255.255.255.0 (hitcnt=5312)&lt;/P&gt;&lt;P&gt;**********************************************************************************************************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Due to size limits, I will post the debug in a second post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:44:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2l-vpn-not-coming-up-or-is-it/m-p/1248032#M970251</guid>
      <dc:creator>dennylester</dc:creator>
      <dc:date>2020-02-21T11:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: L2L VPN not coming up, or is it?</title>
      <link>https://community.cisco.com/t5/network-security/l2l-vpn-not-coming-up-or-is-it/m-p/1248033#M970252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the output from debug crypto isakmp, ipsec, and engine&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): sending NAT-T vendor ID - rev 2 &amp;amp; 3&lt;/P&gt;&lt;P&gt;ISAKMP (0): beginning Main Mode exchange&lt;/P&gt;&lt;P&gt;crypto_isakmp_process_block:src:209.183.xxx.yyy, dest:63.167.xxx.yyy spt:500 dpt:500&lt;/P&gt;&lt;P&gt;OAK_MM exchange&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing SA payload. message ID = 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): Checking ISAKMP transform 1 against priority 7 policy&lt;/P&gt;&lt;P&gt;ISAKMP:      encryption 3DES-CBC&lt;/P&gt;&lt;P&gt;ISAKMP:      hash MD5&lt;/P&gt;&lt;P&gt;ISAKMP:      default group 2&lt;/P&gt;&lt;P&gt;ISAKMP:      auth pre-share&lt;/P&gt;&lt;P&gt;ISAKMP:      life type in seconds&lt;/P&gt;&lt;P&gt;ISAKMP:      life duration (basic) of 28800&lt;/P&gt;&lt;P&gt;ISAKMP (0): atts are acceptable. Next payload is 0&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing vendor id payload&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): vendor ID is NAT-T&lt;/P&gt;&lt;P&gt;ISAKMP (0): SA is doing pre-shared key authentication using id type ID_IPV4_ADDR&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): constructed HIS NAT-D&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): constructed MINE NAT-D&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): Detected port floating&lt;/P&gt;&lt;P&gt;return status is IKMP_NO_ERROR&lt;/P&gt;&lt;P&gt;crypto_isakmp_process_block:src:209.183.xxx.yyy, dest:63.167.xxx.yyy spt:500 dpt:500&lt;/P&gt;&lt;P&gt;OAK_MM exchange&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing KE payload. message ID = 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing NONCE payload. message ID = 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing vendor id payload&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing vendor id payload&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): remote peer supports dead peer detection&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing vendor id payload&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): speaking to another IOS box!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing vendor id payload&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): received xauth v6 vendor id&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): Detected NAT-D payload&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): NAT match MINE hash&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): Detected NAT-D payload&lt;/P&gt;&lt;P&gt;ISAKMP (0:0): NAT match HIS hash&lt;/P&gt;&lt;P&gt;ISAKMP (0): ID payload&lt;/P&gt;&lt;P&gt;        next-payload : 8&lt;/P&gt;&lt;P&gt;        type         : 1&lt;/P&gt;&lt;P&gt;        protocol     : 17&lt;/P&gt;&lt;P&gt;        port         : 500&lt;/P&gt;&lt;P&gt;        length       : 8&lt;/P&gt;&lt;P&gt;ISAKMP (0): Total payload length: 12&lt;/P&gt;&lt;P&gt;return status is IKMP_NO_ERROR&lt;/P&gt;&lt;P&gt;crypto_isakmp_process_block:src:209.183.xxx.yyy, dest:63.167.xxx.yyy spt:500 dpt:500&lt;/P&gt;&lt;P&gt;OAK_MM exchange&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing ID payload. message ID = 0&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing HASH payload. message ID = 0&lt;/P&gt;&lt;P&gt;ISAKMP (0): SA has been authenticated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): beginning Quick Mode exchange, M-ID of -1073275296:c0071e60IPSEC(key&lt;/P&gt;&lt;P&gt;_engine): got a queue event...&lt;/P&gt;&lt;P&gt;IPSEC(spi_response): getting spi 0x1ceb70cb(485191883) for SA&lt;/P&gt;&lt;P&gt;        from  209.183.xxx.yyy to  63.167.xxx.yyy for prot 3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;return status is IKMP_NO_ERROR&lt;/P&gt;&lt;P&gt;ISAKMP (0): sending INITIAL_CONTACT notify&lt;/P&gt;&lt;P&gt;ISAKMP (0): sending NOTIFY message 24578 protocol 1&lt;/P&gt;&lt;P&gt;VPN Peer: ISAKMP: Added new peer: ip:209.183.xxx.yyy/500 Total VPN Peers:5&lt;/P&gt;&lt;P&gt;VPN Peer: ISAKMP: Peer ip:209.183.xxx.yyy/500 Ref cnt incremented to:1 Total VPNPeers:5&lt;/P&gt;&lt;P&gt;crypto_isakmp_process_block:src:209.183.xxx.yyy, dest:63.167.xxx.yyy spt:500 dpt:500&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing NOTIFY payload 14 protocol 3&lt;/P&gt;&lt;P&gt;        spi 485191883, message ID = 8338705&lt;/P&gt;&lt;P&gt;ISAKMP (0): deleting spi 3413175068 message ID = 3221692000&lt;/P&gt;&lt;P&gt;return status is IKMP_NO_ERR_NO_TRANSIPSEC(key_engine): request timer fired: count = 1,&lt;/P&gt;&lt;P&gt;  (identity) local= 63.167.xxx.yyy, remote= 209.183.xxx.yyy,&lt;/P&gt;&lt;P&gt;    local_proxy= 192.168.3.0/255.255.255.240/0/0 (type=4),&lt;/P&gt;&lt;P&gt;    remote_proxy= 192.168.80.0/255.255.255.0/0/0 (type=4)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): beginning Quick Mode exchange, M-ID of -1084598074:bf5a58c6IPSEC(key_engine): got a queue event...&lt;/P&gt;&lt;P&gt;IPSEC(spi_response): getting spi 0x9f947e5(167331813) for SA&lt;/P&gt;&lt;P&gt;        from  209.183.xxx.yyy to  63.167.xxx.yyy for prot 3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto_isakmp_process_block:src:209.183.xxx.yyy, dest:63.167.xxx.yyy spt:500 dpt:500&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing NOTIFY payload 14 protocol 3&lt;/P&gt;&lt;P&gt;        spi 167331813, message ID = 689271268&lt;/P&gt;&lt;P&gt;ISAKMP (0): deleting spi 3846699273 message ID = 3210369222&lt;/P&gt;&lt;P&gt;return status is IKMP_NO_ERR_NO_TRANS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Oct 2009 15:53:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2l-vpn-not-coming-up-or-is-it/m-p/1248033#M970252</guid>
      <dc:creator>dennylester</dc:creator>
      <dc:date>2009-10-16T15:53:20Z</dc:date>
    </item>
    <item>
      <title>Re: L2L VPN not coming up, or is it?</title>
      <link>https://community.cisco.com/t5/network-security/l2l-vpn-not-coming-up-or-is-it/m-p/1248034#M970253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the show crypto isakmp sa and show crypto ipsec sa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the show crypto ipsec sa, you can see all the traffic increments the sent errors counter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**********************************************************************************************************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pixfirewall# show crypto isakmp sa&lt;/P&gt;&lt;P&gt;Total     : 5&lt;/P&gt;&lt;P&gt;Embryonic : 0&lt;/P&gt;&lt;P&gt;        dst               src        state     pending     created&lt;/P&gt;&lt;P&gt;  209.183.xxx.yyy   63.167.xxx.yyy    QM_IDLE         0           0&lt;/P&gt;&lt;P&gt;  *****************Others have been removed************************  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**********************************************************************************************************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pixfirewall# show crypto ipsec sa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; local  ident (addr/mask/prot/port): (192.168.3.0/255.255.255.240/0/0)&lt;/P&gt;&lt;P&gt; remote ident (addr/mask/prot/port): (192.168.80.0/255.255.255.0/0/0)&lt;/P&gt;&lt;P&gt; current_peer: 209.183.xxx.yyy:0&lt;/P&gt;&lt;P&gt;   PERMIT, flags={origin_is_acl,}&lt;/P&gt;&lt;P&gt;  #pkts encaps: 0, #pkts encrypt: 0, #pkts digest 0&lt;/P&gt;&lt;P&gt;  #pkts decaps: 0, #pkts decrypt: 0, #pkts verify 0&lt;/P&gt;&lt;P&gt;  #pkts compressed: 0, #pkts decompressed: 0&lt;/P&gt;&lt;P&gt;  #pkts not compressed: 0, #pkts compr. failed: 0, #pkts decompress failed: 0&lt;/P&gt;&lt;P&gt;  #send errors 111, #recv errors 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   local crypto endpt.: 63.167.xxx.yyy, remote crypto endpt.: 209.183.xxx.yyy&lt;/P&gt;&lt;P&gt;   path mtu 1500, ipsec overhead 0, media mtu 1500&lt;/P&gt;&lt;P&gt;   current outbound spi: 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   inbound esp sas:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   inbound ah sas:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   inbound pcp sas:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   outbound esp sas:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   outbound ah sas:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   outbound pcp sas:&lt;/P&gt;&lt;P&gt;**********************************************************************************************************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am completely stumped.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Oct 2009 15:54:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2l-vpn-not-coming-up-or-is-it/m-p/1248034#M970253</guid>
      <dc:creator>dennylester</dc:creator>
      <dc:date>2009-10-16T15:54:38Z</dc:date>
    </item>
    <item>
      <title>Re: L2L VPN not coming up, or is it?</title>
      <link>https://community.cisco.com/t5/network-security/l2l-vpn-not-coming-up-or-is-it/m-p/1248035#M970254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It appears AT&amp;amp;T provided me with incorrect information. I changed my transform-set to MD5 and it came right up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Oct 2009 18:53:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2l-vpn-not-coming-up-or-is-it/m-p/1248035#M970254</guid>
      <dc:creator>dennylester</dc:creator>
      <dc:date>2009-10-19T18:53:14Z</dc:date>
    </item>
    <item>
      <title>Re: L2L VPN not coming up, or is it?</title>
      <link>https://community.cisco.com/t5/network-security/l2l-vpn-not-coming-up-or-is-it/m-p/1248036#M970255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yup, you would have been able to determine this by the notify message sent back from the peer:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISAKMP (0): processing NOTIFY payload 14 protocol 3 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Notify message 14 is a "NO_PROPOSAL_CHOSEN" message which indicates an unsuccessful Phase 2 SA proposal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Oct 2009 18:07:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2l-vpn-not-coming-up-or-is-it/m-p/1248036#M970255</guid>
      <dc:creator>Patrick0711</dc:creator>
      <dc:date>2009-10-20T18:07:02Z</dc:date>
    </item>
    <item>
      <title>Re: L2L VPN not coming up, or is it?</title>
      <link>https://community.cisco.com/t5/network-security/l2l-vpn-not-coming-up-or-is-it/m-p/1248037#M970256</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Patrick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess I need to track down a list of the notify messages as I was looking for something a little clearer than a number.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At least I know what to look for the next time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for pointing this out as it really helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Denny&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Oct 2009 18:45:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2l-vpn-not-coming-up-or-is-it/m-p/1248037#M970256</guid>
      <dc:creator>dennylester</dc:creator>
      <dc:date>2009-10-20T18:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: L2L VPN not coming up, or is it?</title>
      <link>https://community.cisco.com/t5/network-security/l2l-vpn-not-coming-up-or-is-it/m-p/1248038#M970257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I searched Cisco and Google and couldn't readily find a list defining the Notify Message #'s. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea if such a list exists?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Oct 2009 19:08:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2l-vpn-not-coming-up-or-is-it/m-p/1248038#M970257</guid>
      <dc:creator>dennylester</dc:creator>
      <dc:date>2009-10-20T19:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: L2L VPN not coming up, or is it?</title>
      <link>https://community.cisco.com/t5/network-security/l2l-vpn-not-coming-up-or-is-it/m-p/1248039#M970258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;RFC 2408:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.faqs.org/rfcs/rfc2408.html" target="_blank"&gt;http://www.faqs.org/rfcs/rfc2408.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Section '3.14.1 Notify Message Types'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6.x code will not display the meaning of the notify message types, even at the highest debug levels. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;7.x and above code will display the meaning of the notify messages in the higher-level debug outputs.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's always best to troubleshoot the IKE negotiation by examining your debugs as the responder, however, knowing these message types will help you troubleshoot as the initiator.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Oct 2009 04:29:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2l-vpn-not-coming-up-or-is-it/m-p/1248039#M970258</guid>
      <dc:creator>Patrick0711</dc:creator>
      <dc:date>2009-10-22T04:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: L2L VPN not coming up, or is it?</title>
      <link>https://community.cisco.com/t5/network-security/l2l-vpn-not-coming-up-or-is-it/m-p/1248040#M970259</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you again. This has been very very helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Denny&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Oct 2009 17:02:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2l-vpn-not-coming-up-or-is-it/m-p/1248040#M970259</guid>
      <dc:creator>dennylester</dc:creator>
      <dc:date>2009-10-22T17:02:04Z</dc:date>
    </item>
  </channel>
</rss>

