08-13-2005 02:06 AM - edited 02-21-2020 12:19 AM
I have a 501 device. I have configured a site 2 site tunnel. It worked for a while (2 days) and then stopped. The problem now is that I'm blocked in Phase 1. My pix send a packet ISAKMP to the other side, the second respond and my pix does nothing when receiving it, strange.
attached is the config and the debug, any help please?
Thanx
08-13-2005 10:39 AM
I presume that you have a pix-to-pix vpn tunnel, if so can you issue the following command on both pix's :
(in config mode)
clear isakmp sa
clear cry ipsec sa
now ping from an internal client to an internal peer client to bring up the vpn tunnel.
Also, why do you have two transform-set statements on your 501?
Let me know how you get on.
Jay
08-14-2005 11:32 PM
The second transform set is unused and I have removed it and applied clear isakmp sa & clear cty ipsec sa but no changes. When I make difference between the two peers, I received "NO PROPOSAL CHOOSEN", it's ok. the problem is when the two configs are the same, I receives a response from the distant vpn gateway and then my pix ignore it and restarts phase negociation again. Stange !!! I'm blocked :(
08-14-2005 11:38 PM
Use the following document to compare and troubleshoot :
Let me know how you get on.
Jay
08-15-2005 01:05 AM
Thank you. I used this document but no changes. I have changed from 3des to des with the other side and still the same problem. I don't understand why is my pix don't continue phase 1 negociation :(
Any help please?
08-15-2005 01:49 AM
08-16-2005 03:15 AM
Thank you for your help during last days. Finaly, It worked :) I reset to factory default and reconfigured the vpn Tunnel. Until now, I don't understand the real problem. I'm going to restore my config (access-list, ...) and see where is the problem.
Thank you again
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide