cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1163
Views
0
Helpful
4
Replies

%CRYPTO-4-IKMP_NO_SA@message

d.beppu
Level 1
Level 1

Hello,

We are using two IOS routers ( Cisco 1720 and

Cisco 7206VXR, both IOS versions are 12.1(3) )

for peer-to-peer VPN communications.

Both routers are set the IKE authentication method

to RSA-encrypted nonces. (authentication rsa-encr)

For a few months, VPN connections between the both

routers were OK.

But few days ago, the VPN connection was diconnected

suddenly, and the one router (Cisco 7206VXR) generated

the log below.

Dec 23 20:06:20: %CRYPTO-4-IKMP_NO_SA:

IKE message from xxx.xxx.xxx.xxx has no SA

and is not an initialization offer

We did not work on the two routers just before

the accident.

Any reasons for this?

Thank you.

4 Replies 4

a-vazquez
Level 6
Level 6

Possibly a hack attempt? Strange. Did the tunnel come back up?

errol.simon
Level 1
Level 1

Did you get any joy resolving this problem?

pdentico
Level 1
Level 1

Check the clocks. I had a router that when it rebooted the NTP failed and it would not reconnect.

(Just a thought)

Yes, the tunnel came back up by reconfiguring

the whole VPN config manually as before.

I know that VPN settings of routers are

sensitive to the clocks, but the clocks

have been working correctly.

Strange.