cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
675
Views
0
Helpful
2
Replies

871 easy vpn to 3005

rkazmierczak
Level 1
Level 1

I setup cisco 871 as a vpn client connecting to 3005 concentrator. (the client has a private address). The connection is successful. Right after the tunnel is up I can ping a host on a remote network (behind 871). But when I stop the ping for about 20 seconds I cannot resume it, although the ISAKMP and IPsec SAs are still there (on both router and concentrator).

The log from the concentrator:

PHASE 2 COMPLETED (msgid=8dc50042)

6710 05/19/2006 14:44:09.630 SEV=6 IKE/145 RPT=221 xxx.xxx.xxx.xxx

..............

Detected Hardware Client in network extension mode,

adding static route for address: 192.168.127.0, mask: 255.255.255.0

6713 05/19/2006 14:44:10.130 SEV=4 IKE/0 RPT=3250

Group ........ User .......

Inconsistent PSK hash size

What does the the last line mean? The authentication has definately been successful and phase 2 is complete.

What can be the problem?

2 Replies 2

rkazmierczak
Level 1
Level 1

I solved the problem with isakmp keepalive 10 periodic command on the router, although I am not happy with the solution. It is normally used for DPD when backup servers are configured. Why do I have to use it in this case?

ZAHI ZEINEDDINE
Level 1
Level 1

Hi,

Do you know what was the solution for your problem about "inconsitent PSK hash size".

I have exact the same issue.

Would you please email me at

zzeineddine@yahoo.com if you can help me with this.

Thanks

Zahi Zeineddie

tel:781-363-0865