cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
847
Views
0
Helpful
3
Replies

Site to Site IPSec VPN unable to establish tunnel, below is the debug

mahendarec@123
Level 1
Level 1

Site to Site IPSec VPN unable to establish tunnel, below is the debug report.

 

Steps as of now i done.

cleared crypto

reconfigured

 

047900: *Feb 22 20:55:06.351 PCTime: IPSEC:(SESSION ID = 2) (key_engine) request timer fired: count = 2,
(identity) local= 192.168.18.21:0, remote= 40.65.189.27:0,
local_proxy= 10.152.10.0/255.255.255.0/256/0,
remote_proxy= 10.7.125.64/255.255.255.192/256/0
047901: *Feb 22 20:55:09.199 PCTime: IPSEC:(SESSION ID = 24370) still in use sa: 0x23DC8DD4
047902: *Feb 22 20:55:09.203 PCTime: IPSEC(send_delete_notify_kmi): not sending KEY_ENGINE_DELETE_SAS
047903: *Feb 22 20:55:11.651 PCTime: IPSEC(sa_request): ,
(key eng. msg.) OUTBOUND local= 192.168.18.21:500, remote= 40.65.189.27:500,
local_proxy= 10.152.10.0/255.255.255.0/256/0,
remote_proxy= 10.7.125.64/255.255.255.192/256/0,
protocol= ESP, transform= esp-aes 256 esp-sha256-hmac (Tunnel),
lifedur= 28800s and 4608000kb,
spi= 0x0(0), conn_id= 0, keysize= 256, flags= 0x0
047904: *Feb 22 20:55:41.651 PCTime: IPSEC:(SESSION ID = 2) (key_engine) request timer fired: count = 1,
(identity) local= 192.168.18.21:0, remote= 40.65.189.27:0,
local_proxy= 10.152.10.0/255.255.255.0/256/0,
remote_proxy= 10.7.125.64/255.255.255.192/256/0
047905: *Feb 22 20:55:41.651 PCTime: IPSEC(sa_request): ,
(key eng. msg.) OUTBOUND local= 192.168.18.21:500, remote= 40.65.189.27:500,
local_proxy= 10.152.10.0/255.255.255.0/256/0,
remote_proxy= 10.7.125.64/255.255.255.192/256/0,
protocol= ESP, transform= esp-aes 256 esp-sha256-hmac (Tunnel),
lifedur= 28800s and 4608000kb,
spi= 0x0(0), conn_id= 0, keysize= 256, flags= 0x0

3 Replies 3

mahendarec@123
Level 1
Level 1

Also cisco2911 router how to configure the NAT-traversal.Please help me with config steps.

Hello,

 

post the full running configurations of both VPN tunnel ends...

balaji.bandi
Hall of Fame
Hall of Fame

what is this device ? what code running, how about other side ?

 

Do you have config to look ?

 

run both the debug :

 

debug crypto isakmp 120

debug crypto ipsec 120

 

some example :

 

https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/119425-configure-ipsec-00.html

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Review Cisco Networking for a $25 gift card