05-19-2006 06:01 AM - edited 02-21-2020 02:25 PM
I setup cisco 871 as a vpn client connecting to 3005 concentrator. (the client has a private address). The connection is successful. Right after the tunnel is up I can ping a host on a remote network (behind 871). But when I stop the ping for about 20 seconds I cannot resume it, although the ISAKMP and IPsec SAs are still there (on both router and concentrator).
The log from the concentrator:
PHASE 2 COMPLETED (msgid=8dc50042)
6710 05/19/2006 14:44:09.630 SEV=6 IKE/145 RPT=221 xxx.xxx.xxx.xxx
..............
Detected Hardware Client in network extension mode,
adding static route for address: 192.168.127.0, mask: 255.255.255.0
6713 05/19/2006 14:44:10.130 SEV=4 IKE/0 RPT=3250
Group ........ User .......
Inconsistent PSK hash size
What does the the last line mean? The authentication has definately been successful and phase 2 is complete.
What can be the problem?
05-19-2006 07:16 AM
I solved the problem with isakmp keepalive 10 periodic command on the router, although I am not happy with the solution. It is normally used for DPD when backup servers are configured. Why do I have to use it in this case?
02-09-2007 07:42 AM
Hi,
Do you know what was the solution for your problem about "inconsitent PSK hash size".
I have exact the same issue.
Would you please email me at
zzeineddine@yahoo.com if you can help me with this.
Thanks
Zahi Zeineddie
tel:781-363-0865
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide