<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN 3000 Concentrator in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-3000-concentrator/m-p/1059462#M973022</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;QM FSM Error&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The IPsec L2L VPN tunnel does not come up on the PIX firewall or ASA, and the QM FSM error message appears.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One possible reason is the proxy identities, such as interesting traffic, Access Control List (ACL) or crypto ACL, do not match on both the ends. Check the configuration on both the devices, and make sure that the crypto ACLs match.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/tech/tk583/tk372/technologies_tech_note09186a00800949c5.shtml#qms" target="_blank"&gt;http://www.cisco.com/en/US/tech/tk583/tk372/technologies_tech_note09186a00800949c5.shtml#qms&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Arul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Pls rate if it helps*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 28 Oct 2008 15:35:42 GMT</pubDate>
    <dc:creator>ajagadee</dc:creator>
    <dc:date>2008-10-28T15:35:42Z</dc:date>
    <item>
      <title>VPN 3000 Concentrator</title>
      <link>https://community.cisco.com/t5/network-security/vpn-3000-concentrator/m-p/1059461#M973021</link>
      <description>&lt;P&gt;Does anyone know where I can find the meaning of this message?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;465 10/28/2008 14:48:06.640 SEV=4 IKEDBG/97 RPT=410 208.96.196.242 &lt;/P&gt;&lt;P&gt;Group [208.96.196.242]&lt;/P&gt;&lt;P&gt;QM FSM error (P2 struct &amp;amp;0x6810ef4, mess id 0xeb16b91f)!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;466 10/28/2008 14:48:06.640 SEV=7 IKEDBG/65 RPT=39116 208.96.196.242 &lt;/P&gt;&lt;P&gt;Group [208.96.196.242]&lt;/P&gt;&lt;P&gt;IKE QM Initiator FSM error history (struct &amp;amp;0x6810ef4)&lt;/P&gt;&lt;P&gt;&amp;lt;state&amp;gt;, &amp;lt;event&amp;gt;:&lt;/P&gt;&lt;P&gt;QM_DONE, EV_ERROR&lt;/P&gt;&lt;P&gt;QM_WAIT_MSG2, EV_TIMEOUT&lt;/P&gt;&lt;P&gt;QM_WAIT_MSG2, NullEvent&lt;/P&gt;&lt;P&gt;QM_SND_MSG1, EV_SND_MSG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:04:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-3000-concentrator/m-p/1059461#M973021</guid>
      <dc:creator>wgranada1</dc:creator>
      <dc:date>2020-02-21T11:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: VPN 3000 Concentrator</title>
      <link>https://community.cisco.com/t5/network-security/vpn-3000-concentrator/m-p/1059462#M973022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;QM FSM Error&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The IPsec L2L VPN tunnel does not come up on the PIX firewall or ASA, and the QM FSM error message appears.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One possible reason is the proxy identities, such as interesting traffic, Access Control List (ACL) or crypto ACL, do not match on both the ends. Check the configuration on both the devices, and make sure that the crypto ACLs match.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/tech/tk583/tk372/technologies_tech_note09186a00800949c5.shtml#qms" target="_blank"&gt;http://www.cisco.com/en/US/tech/tk583/tk372/technologies_tech_note09186a00800949c5.shtml#qms&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Arul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Pls rate if it helps*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2008 15:35:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-3000-concentrator/m-p/1059462#M973022</guid>
      <dc:creator>ajagadee</dc:creator>
      <dc:date>2008-10-28T15:35:42Z</dc:date>
    </item>
    <item>
      <title>Re: VPN 3000 Concentrator</title>
      <link>https://community.cisco.com/t5/network-security/vpn-3000-concentrator/m-p/1059463#M973023</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes this makes it clearer, just a fyi found out the the distant end didn't have a route back.  Thanks for your help!!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Oct 2008 13:54:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-3000-concentrator/m-p/1059463#M973023</guid>
      <dc:creator>wgranada1</dc:creator>
      <dc:date>2008-10-29T13:54:25Z</dc:date>
    </item>
  </channel>
</rss>

