cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3113
Views
0
Helpful
2
Replies

IPSec issue on ISR4221

mtmharison
Level 1
Level 1

Hi,

 

The IPSec sa on my ISR 4221 can't be established and I have the below repetitive log message :

%ACE-3-TRANSERR: IOSXE-ESP(9): IKEA trans 0x73E; opcode 0x60; param 0x39C; error 0x5; retry cnt 0

what does it mean?

 

Regards,

Harison

1 Accepted Solution

Accepted Solutions

it seems that I don't have the same encryption and hash algorithm in my new and the existing routers

View solution in original post

2 Replies 2

balaji.bandi
Hall of Fame
Hall of Fame

Suggestions are here :

 

1. what is the version of IOS code running. (post show version)

2. can you check both the side configuration are identical part of VPN config.

 

if all ok, i see some bug was reported here, not able to find the details full, but mentioned some version fixed, check with against your version.

 

https://community.cisco.com/t5/vpn-and-anyconnect/cisco-bug-csctc78745/td-p/1968089

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

it seems that I don't have the same encryption and hash algorithm in my new and the existing routers