06-27-2003 08:32 PM - edited 03-09-2019 03:50 AM
the debug below says the pre-shared keys don't match. i believe they do. my group is vpnuser and key is cisco123 on the vpn client and on the router they are also the same. suggestions?
2d09h: ISAKMP (0:9): Checking ISAKMP transform 8 against priority 100 policy
2d09h: ISAKMP: encryption AES-CBC
2d09h: ISAKMP: hash MD5
2d09h: ISAKMP: default group 2
2d09h: ISAKMP: auth pre-share
2d09h: ISAKMP: life type in seconds
2d09h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d09h: ISAKMP: keylength of 128
2d09h: ISAKMP (0:9): Encryption algorithm offered does not match policy!
2d09h: ISAKMP (0:9): atts are not acceptable. Next payload is 3
2d09h: ISAKMP (0:9): Checking ISAKMP transform 9 against priority 100 policy
2d09h: ISAKMP: encryption 3DES-CBC
2d09h: ISAKMP: hash SHA
2d09h: ISAKMP: default group 2
2d09h: ISAKMP: auth XAUTHInitPreShared
2d09h: ISAKMP: life type in seconds
2d09h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d09h: ISAKMP (0:9): Hash algorithm offered does not match policy!
2d09h: ISAKMP (0:9): atts are not acceptable. Next payload is 3
2d09h: ISAKMP (0:9): Checking ISAKMP transform 10 against priority 100 policy
2d09h: ISAKMP: encryption 3DES-CBC
2d09h: ISAKMP: hash MD5
2d09h: ISAKMP: default group 2
2d09h: ISAKMP: auth XAUTHInitPreShared
2d09h: ISAKMP: life type in seconds
2d09h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d09h: ISAKMP (0:9): Xauth authentication by pre-shared key offered but does not
match policy!
06-28-2003 12:30 AM
Hi,
Could you please post the complete debugs? The messages you are seeing just indicate that the router and the vpn client have not agreed on the phase 1 proposal which they are going to use.
Thanks
Ranjana
06-28-2003 08:23 AM
2d21h: ISAKMP (0:0): received packet from 172.16.1.107 dport 500 sport 500 Globa
l (N) NEW SA
2d21h: ISAKMP: local port 500, remote port 500
2d21h: ISAKMP: Find a dup sa in the avl tree during calling isadb_insert sa = 82
EBF27C
2d21h: ISAKMP (0:12): processing SA payload. message ID = 0
2d21h: ISAKMP (0:12): processing ID payload. message ID = 0
2d21h: ISAKMP (0:12): peer matches *none* of the profiles
2d21h: ISAKMP (0:12): processing vendor id payload
2d21h: ISAKMP (0:12): vendor ID seems Unity/DPD but major 215 mismatch
2d21h: ISAKMP (0:12): vendor ID is XAUTH
2d21h: ISAKMP (0:12): processing vendor id payload
2d21h: ISAKMP (0:12): vendor ID is DPD
2d21h: ISAKMP (0:12): processing vendor id payload
2d21h: ISAKMP (0:12): vendor ID is Unity
2d21h: ISAKMP : Scanning profiles for xauth ...
2d21h: ISAKMP (0:12): Checking ISAKMP transform 1 against priority 100 policy
2d21h: ISAKMP: encryption AES-CBC
2d21h: ISAKMP: hash SHA
2d21h: ISAKMP: default group 2exe-router#
2d21h: ISAKMP: auth XAUTHInitPreShared
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP: keylength of 256
2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 2 against priority 100 policy
2d21h: ISAKMP: encryption AES-CBC
2d21h: ISAKMP: hash MD5
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth XAUTHInitPreShared
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP: keylength of 256
2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 3 against priority 100 policy
2d21h: ISAKMP: encryption AES-CBC
2d21h: ISAKMP: hash SHA
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth pre-share
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP: keylength of 256
2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 4 against priority 100 policy
2d21h: ISAKMP: encryption AES-CBC
2d21h: ISAKMP: hash MD5
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth pre-share
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP: keylength of 256
2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 5 against priority 100 policy
2d21h: ISAKMP: encryption AES-CBC
2d21h: ISAKMP: hash SHA
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth XAUTHInitPreShared
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP: keylength of 128
2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 6 against priority 100 policy
2d21h: ISAKMP: encryption AES-CBC
2d21h: ISAKMP: hash MD5
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth XAUTHInitPreShared
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP: keylength of 128
2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 7 against priority 100 policy
2d21h: ISAKMP: encryption AES-CBC
2d21h: ISAKMP: hash SHA
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth pre-share
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP: keylength of 128
2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 8 against priority 100 policy
2d21h: ISAKMP: encryption AES-CBC
2d21h: ISAKMP: hash MD5
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth pre-share
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP: keylength of 128
2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 9 against priority 100 policy
2d21h: ISAKMP: encryption 3DES-CBC
2d21h: ISAKMP: hash SHA
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth XAUTHInitPreShared
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP (0:12): Hash algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 10 against priority 100 policy
2d21h: ISAKMP: encryption 3DES-CBC
2d21h: ISAKMP: hash MD5
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth XAUTHInitPreShared
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP (0:12): Xauth authentication by pre-shared key offered but does no
t match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 11 against priority 100 policy
2d21h: ISAKMP: encryption 3DES-CBC
2d21h: ISAKMP: hash SHA
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth pre-share
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP (0:12): Hash algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 12 against priority 100 policy
2d21h: ISAKMP: encryption 3DES-CBC
2d21h: ISAKMP: hash MD5
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth pre-share
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP (0:12): Preshared authentication offered but does not match policy
!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 13 against priority 100 policy
2d21h: ISAKMP: encryption DES-CBC
2d21h: ISAKMP: hash MD5
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth XAUTHInitPreShared
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 14 against priority 100 policy
2d21h: ISAKMP: encryption DES-CBC
2d21h: ISAKMP: hash MD5
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth pre-share
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 0
2d21h: ISAKMP (0:12): Checking ISAKMP transform 1 against priority 65535 policy
2d21h: ISAKMP: encryption AES-CBC
2d21h: ISAKMP: hash SHA
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth XAUTHInitPreShared
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP: keylength of 256
2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 2 against priority 65535 policy
2d21h: ISAKMP: encryption AES-CBC
2d21h: ISAKMP: hash MD5
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth XAUTHInitPreShared
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP: keylength of 256
2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 3 against priority 65535 policy
06-28-2003 08:24 AM
2d21h: ISAKMP: encryption AES-CBC
2d21h: ISAKMP: hash SHA
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth pre-share
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP: keylength of 256
2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 4 against priority 65535 policy
2d21h: ISAKMP: encryption AES-CBC
2d21h: ISAKMP: hash MD5
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth pre-share
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP: keylength of 256
2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 5 against priority 65535 policy
2d21h: ISAKMP: encryption AES-CBC
2d21h: ISAKMP: hash SHA
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth XAUTHInitPreShared
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP: keylength of 128
2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 6 against priority 65535 policy
2d21h: ISAKMP: encryption AES-CBC
2d21h: ISAKMP: hash MD5
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth XAUTHInitPreShared
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP: keylength of 128
2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 7 against priority 65535 policy
2d21h: ISAKMP: encryption AES-CBC
2d21h: ISAKMP: hash SHA
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth pre-share
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP: keylength of 128
2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 8 against priority 65535 policy
2d21h: ISAKMP: encryption AES-CBC
2d21h: ISAKMP: hash MD5
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth pre-share
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP: keylength of 128
2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 9 against priority 65535 policy
2d21h: ISAKMP: encryption 3DES-CBC
2d21h: ISAKMP: hash SHA
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth XAUTHInitPreShared
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 10 against priority 65535 policy
2d21h: ISAKMP: encryption 3DES-CBC
2d21h: ISAKMP: hash MD5
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth XAUTHInitPreShared
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 11 against priority 65535 policy
2d21h: ISAKMP: encryption 3DES-CBC
2d21h: ISAKMP: hash SHA
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth pre-share
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 12 against priority 65535 policy
2d21h: ISAKMP: encryption 3DES-CBC
2d21h: ISAKMP: hash MD5
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth pre-share
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 13 against priority 65535 policy
2d21h: ISAKMP: encryption DES-CBC
2d21h: ISAKMP: hash MD5
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth XAUTHInitPreShared
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP (0:12): Hash algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3
2d21h: ISAKMP (0:12): Checking ISAKMP transform 14 against priority 65535 policy
2d21h: ISAKMP: encryption DES-CBC
2d21h: ISAKMP: hash MD5
2d21h: ISAKMP: default group 2
2d21h: ISAKMP: auth pre-share
2d21h: ISAKMP: life type in seconds
2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B
2d21h: ISAKMP (0:12): Hash algorithm offered does not match policy!
2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 0
2d21h: ISAKMP (0:12): no offers accepted!
2d21h: ISAKMP (0:12): phase 1 SA policy not acceptable! (local 68.9.201.218 remo
te 172.16.1.107)
2d21h: ISAKMP (0:12): incrementing error counter on sa: construct_fail_ag_init
2d21h: ISAKMP (0:12): Unknown Input: state = IKE_READY, major, minor = IKE_MESG_
FROM_PEER, IKE_AM_EXCH
2d21h: ISAKMP (0:12): received packet from 172.16.1.107 dport 500 sport 500 Glob
al (R) AG_NO_STATE
2d21h: ISAKMP (0:12): phase 1 packet is a duplicate of a previous packet.
2d21h: ISAKMP (0:12): retransmitting due to retransmit phase 1
2d21h: ISAKMP (0:12): retransmitting phase 1 AG_NO_STATE...
2d21h: ISAKMP (0:12): retransmitting phase 1 AG_NO_STATE...
2d21h: ISAKMP (0:12): incrementing error counter on sa: retransmit phase 1
2d21h: ISAKMP (0:12): retransmitting phase 1 AG_NO_STATE
2d21h: ISAKMP (0:12): sending packet to 172.16.1.107 my_port 500 peer_port 500 (
R) AG_NO_STATE
2d21h: ISAKMP (0:12): received packet from 172.16.1.107 dport 500 sport 500 Glob
al (R) AG_NO_STATE
2d21h: ISAKMP (0:12): phase 1 packet is a duplicate of a previous packet.
2d21h: ISAKMP (0:12): retransmitting due to retransmit phase 1
2d21h: ISAKMP (0:12): retransmitting phase 1 AG_NO_STATE...
2d21h: ISAKMP (0:12): retransmitting phase 1 AG_NO_STATE...
2d21h: ISAKMP (0:12): incrementing error counter on sa: retransmit phase 1
2d21h: ISAKMP (0:12): no outgoing phase 1 packet to retransmit. AG_NO_STATE
2d21h: ISAKMP (0:12): received packet from 172.16.1.107 dport 500 sport 500 Glob
al (R) AG_NO_STATE
2d21h: ISAKMP (0:12): phase 1 packet is a duplicate of a previous packet.
2d21h: ISAKMP (0:12): retransmitting due to retransmit phase 1
2d21h: ISAKMP (0:12): retransmitting phase 1 AG_NO_STATE...
2d21h: ISAKMP (0:12): retransmitting phase 1 AG_NO_STATE...
2d21h: ISAKMP (0:12): incrementing error counter on sa: retransmit phase 1
2d21h: ISAKMP (0:12): no outgoing phase 1 packet to retransmit. AG_NO_STATE
exe-router#
exe-router#
06-30-2003 10:48 PM
From the details of the logs, it is very clear that the only transform set that is agreed is "Encryption=3DES and Hash=MD5". (See transform 10 and 12) but it is saying that the policy didn't allow to establish the IKE SA. So you can just configure this basic transform set and try creating the IKE tunnel.
06-30-2003 10:51 PM
thanks i'll give it a try
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide