cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4797
Views
0
Helpful
1
Replies

AnyConnect Error: The Peer's KE payload contained the wrong DH group

aalsul
Level 1
Level 1

I recently zeroized my keys and generated new ones. I've been looking at where to delete the old, cached key in AnyConnect, but I can't find it anywhere. I uninstalled the application and deleted remnant folders. I stopped and restarted the service. It still gives me an error whenever I connect:

 

Unknown IKEv2 Negotiation abored due to ERROR: The Peer's KE payload contained the wrong DH group

Unknown IKEv2 Negotiation abored due to ERROR: Failed to locate an item in the database

 

Log file from ASDM is attached, but it's formatted weirdly.

 

Thanks.

1 Accepted Solution

Accepted Solutions

aalsul
Level 1
Level 1

Found the issue: I didn't have a certificate on the ASA.

 

Resolution via ASDM is to navigate to: Device Management > Certificate Management > Identity certificate. I added one through there and was able to log in through AnyConnect again.

View solution in original post

1 Reply 1

aalsul
Level 1
Level 1

Found the issue: I didn't have a certificate on the ASA.

 

Resolution via ASDM is to navigate to: Device Management > Certificate Management > Identity certificate. I added one through there and was able to log in through AnyConnect again.